Independent guide. login.com is an independent educational resource. We are not affiliated with, endorsed by, or connected to the services described. Always sign in only on the service's own official website.
Fair-comparison note: login.com has no affiliate relationship with the products discussed, accepts no placement payment, and makes no universal winner claim.
Last reviewed: 2026-08-20 · Report a change
Short answer
What to know before you start
Before suspending or deleting a departing employee, move company-owned items out of personal or employee-only vaults, transfer vault ownership, and identify every shared password, passkey, TOTP secret, token, and recovery role they could use. Revoke access quickly, then rotate high-impact credentials. Preserve logs and verify sessions; deleting a manager account alone does not invalidate copied secrets.
01 · decision point
Establish credential ownership before access is removed
The critical distinction is not who created a vault item but who must control it after departure. Inventory company domains, cloud consoles, finance, payroll, customer systems, social accounts, code repositories, API keys, recovery mailboxes, hardware-token assignments, passkeys, and TOTP entries. Place business-owned records in organization-controlled vaults or collections with at least two authorized owners. Keep personal credentials outside the company vault according to policy and applicable law.
1Password's current offboarding guidance warns not to delete a member before transferring the contents of the Employee vault because deletion permanently removes those items. Bitwarden documents organization ownership, individual-vault boundaries, and controls that can centralize organization data. Proton documents vault ownership transfer and member access removal. Product models differ, so the runbook must name the exact vault and role affected by each step.
02 · decision point
Use suspension or revocation as a controlled first state
When policy and risk permit, suspend or revoke access before permanent deletion. That blocks or narrows access while administrators verify ownership, exports, and recovery. 1Password recommends suspending before removal and describes deprovisioning through an identity provider. Bitwarden says a revoked member cannot access organization vault items or the organization's SSO, and can later be restored. These reversible states can protect evidence and reduce irreversible data loss.
The identity provider, password manager, email, endpoint management, and application sessions should be coordinated. A SCIM deprovisioning event can suspend an account, but local or offline caches and already copied secrets may persist. Bitwarden explicitly notes that some offline clients can retain read-only organization data briefly, which is why credentials the member accessed may need rotation. Revocation is an access-control event, not a claim that knowledge has been erased.
03 · decision point
Rotate by exposure and consequence
Prioritize credentials the departing person viewed or could export: identity-provider owners, password-manager owners, domain and DNS, primary email, cloud root or billing roles, signing keys, production secrets, shared recovery codes, and financial systems. Then rotate team, vendor, and routine shared accounts. Use access or usage reports when the provider supplies them, but do not treat a missing event as proof that a credential was never copied.
Passkeys and TOTP seeds need explicit handling. Remove the employee's registered passkey or hardware key at each relying party, rotate a shared TOTP secret where possible, and issue new recovery codes. Removing a vault membership can stop future sync but cannot invalidate a credential copied to another authenticator. API tokens and SSH keys may live outside the password manager entirely; search the service's own access list and deployment systems.
04 · decision point
Transfer administrator and recovery authority
Before removing an owner, assign another qualified owner and verify that person can reach billing, audit, export, recovery, SSO, SCIM, and policy controls. Check family-plan benefits or linked personal accounts so the departure does not surprise the employee or expose personal data. Separate company recovery authority from an individual's private vault. If account recovery is used to retrieve business items, document the authorization and minimize exposure to unrelated personal records.
Review emergency contacts, manager recovery permissions, break-glass accounts, verified domains, and notification email addresses. A former employee should not remain the only recipient of recovery or security alerts. At least two current administrators should be able to recover one another through an approved process. Store the offboarding runbook and break-glass instructions outside the everyday administrator's personal vault so the process survives that person's departure.
05 · decision point
Close with evidence, deletion decisions, and follow-up
Record who approved the departure, when identity and manager access were revoked, which vault items were transferred, which high-impact credentials were rotated, and which sessions or devices were removed. Preserve provider event logs according to the organization's retention policy. Never place exported secrets in the ticket. Use item labels, service identifiers, and completion status, with a separate protected channel for any temporary credential that must be communicated.
Permanent deletion should occur only after retention, legal, ownership, and recovery checks are complete. Provider documentation can make deletion irreversible. Schedule a follow-up to find stale group memberships, tokens, shared links, automation accounts, and vendor portals. A successful offboarding is not a single delete action; it is a verified transition of ownership plus revocation of every credential path the person could still exercise.
Practical sequence
Run the business password-manager offboarding sequence
- 01
Inventory company-owned passwords, passkeys, TOTP seeds, tokens, recovery roles, and vault ownership.
- 02
Transfer employee-only business items and assign at least two current administrators or owners.
- 03
Suspend or revoke the identity-provider and manager account through the documented process.
- 04
Remove active sessions, devices, group memberships, shared links, passkeys, and hardware assignments.
- 05
Rotate high-impact and viewed credentials, then regenerate shared recovery material.
- 06
Preserve a no-secrets audit record and delay irreversible deletion until every ownership check passes.
Original research element
Map each offboarding action to the risk it actually closes
This original control ledger prevents account deletion from being mistaken for credential invalidation.
| Action | Closes | Does not close | Required evidence |
|---|---|---|---|
| Transfer vault ownership | Future company access | Employee's existing knowledge | New owner verifies items |
| Suspend or revoke member | Current organization access | Copied secrets or offline cache | Timestamp and session review |
| Rotate credential | Old password, token, or TOTP utility | Other unreviewed systems | Service-side change confirmed |
| Delete account | Provider account after final checks | Independent relying-party sessions | Retention and ownership approval |
Common questions
Password-manager employee offboarding FAQ
Should we delete the employee's password-manager account immediately?
Not before business-owned items, vault ownership, recovery roles, retention needs, and provider-specific consequences are checked. Use suspension or revocation first when the risk model permits.
Does revoking vault access invalidate copied passwords?
No. It stops authorized vault access, but a person may remember, export, cache, or copy a credential. Rotate exposed and high-impact secrets at the relying services.
What happens to passkeys and TOTP seeds?
Remove registered passkeys at each service, rotate shared TOTP enrollment where possible, and issue new recovery codes. Vault removal alone may not invalidate another copy.
How many password-manager owners should a business have?
Maintain at least two trained, current administrators or owners so billing, recovery, export, and policy functions do not depend on a departing individual.
Continue on login.com
Related independent guidance
Primary-source ledger
Official documentation reviewed
Features, plan packaging, interfaces, and recovery controls can change. Every factual product claim on this page is bounded by the official source and checked date below. Recheck the provider documentation before a migration, purchase, administrator change, or high-impact recovery.
- 1Password: offboard a team member ↗Checked 2026-08-20
- 1Password: automated provisioning best practices ↗Checked 2026-08-20
- Bitwarden: onboarding and succession ↗Checked 2026-08-20
- Bitwarden: temporarily revoke access ↗Checked 2026-08-20
- Proton Pass: transfer vault ownership ↗Checked 2026-08-20
- Proton Pass: remove shared-vault access ↗Checked 2026-08-20