ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Offboarding Checklist: Closing Access When Attorneys and Staff Leave

When someone leaves a firm, their access should end the same day. Use this offboarding checklist to cover email, devices, cloud apps and client files.

3 min readBy Counsel Cyber Team

Departures are routine in law firms: associates move on, paralegals retire, contract attorneys finish a project. Each one leaves behind accounts, devices, shared links and sometimes personal copies of files. If access is not closed promptly and completely, the firm carries risk long after the farewell lunch, from lingering logins to former employees who still receive client email on their phones.

A written offboarding checklist, triggered the moment a departure is known, is one of the least expensive security controls a firm can adopt.

Before the last day

Start the process early

HR or the firm administrator should notify IT as soon as a departure is scheduled, not on the final afternoon. For involuntary departures, coordinate timing so access is removed at the moment of notice.

Identify what the person holds

List the systems and data the person touches: email, calendar, practice management, document management, billing, e-filing credentials, shared mailboxes, mobile devices, remote access, firm credit cards, vendor portals and any personal devices with firm data.

Plan for continuity

Decide who will take over matters, who will monitor the mailbox and who will tell clients and courts about the change in responsible attorney. Client communication duties under Model Rule 1.4 may apply, so ask ethics counsel how your state handles departing lawyer notices.

On the last day

  1. Disable the account in your identity system, which should cut off email and any application using single sign-on. Disable rather than delete, to preserve records.
  2. Revoke active sessions and tokens so existing logins on phones and browsers end.
  3. Remove multi-factor methods and registered devices.
  4. Reset passwords for any shared accounts the person knew.
  5. Wipe or remove firm data from mobile devices. For personal phones, use a managed approach that removes only firm data. Retrieve firm laptops, phones and security keys.
  6. Change building and alarm codes where applicable.
  7. Cancel physical access such as key cards and parking.
  8. Remove from remote access, VPN and cloud storage.

After the last day

Handle the mailbox thoughtfully

Convert it to a shared mailbox, set an automatic reply that directs senders to a current contact, and grant access to the person taking over. Do not simply delete it, since retention obligations may apply. Check for forwarding rules and remove any external forwarding.

Reassign ownership

Documents, shared folders, calendars, Teams or SharePoint sites and automated workflows may be owned by the departing user. Reassign them before the account disappears so nothing breaks or becomes inaccessible.

Review connected apps

Check whether the user authorized third-party applications or created API tokens, and revoke any no longer needed.

Update vendors and courts

Remove the person from vendor portals, court e-filing registrations, bar association mailing lists tied to firm accounts and signing authority on bank accounts.

Preserve records

Keep the account data, mailbox contents and activity logs per your retention policy. If any dispute is possible, preserve more rather than less and ask counsel.

Special situations

  • Departing attorneys who take clients. Clients decide who represents them, and the rules on notice and file transfer are matters of ethics and state law. Coordinate technical access with counsel so files move properly and no unauthorized copying occurs.
  • Contractors and temps. Set end dates when accounts are created, so access expires automatically.
  • Unfriendly exits. Remove access first, then conduct the conversation. Review logs for unusual downloads in the weeks before departure.

Documenting the process

Record each step with the date and who completed it. A signed checklist per departure gives you evidence for clients, insurers and auditors that former personnel lose access promptly. It also helps you spot recurring misses.

Common mistakes

  • Waiting for HR paperwork to reach IT
  • Forgetting cloud apps outside single sign-on
  • Leaving external forwarding in place
  • Not retrieving MFA devices or security keys
  • Keeping stale accounts "just in case"

Why this matters

ABA Model Rule 1.6(c) addresses reasonable efforts to prevent unauthorized access to client information, and Rules 5.1 and 5.3 address supervision. Prompt deprovisioning is a straightforward way to show that effort. Confirm specifics with your state bar.

How we can help

Counsel Cyber builds offboarding procedures into managed IT for law firms, including same-day account shutdown and quarterly audits for leftover access. If you would like us to check for stale accounts right now, we can run a quick review.