Employee Offboarding: The Digital Assets You Must Take Down
When someone leaves, the digital assets you need to take down fall into three groups: accounts you hold the keys to (email, Slack, CRM, shared logins), public-facing assets built under your brand (their profile page, directory and review listings, WhatsApp Business, the QR code printed on their card), and anything living in an account the person owns personally, which you cannot take down at all — you can only ask. A practical offboarding checklist handles the first two the same week and, more importantly, stops creating the third by issuing the public-facing pages from a company account where revoking them is a single action.
The resignation email lands on a Tuesday. HR sends you the offboarding checklist, you work through it, and by Friday the laptop is back, the mailbox is on a forward, Slack is deactivated, the CRM licence is reassigned and the badge is deactivated. On paper the person is offboarded.
Three weeks later a customer forwards you a screenshot. They scanned the QR code on the business card your former rep handed them at a trade show in March. It still works. It opens a page with your logo on it, and the phone number now goes somewhere you don't control.
Nothing was done wrong. The checklist covered internal systems, because internal systems are what IT can see. The public-facing footprint the person built under your brand — the part customers actually touch — sits outside it. What follows is a takedown checklist for that footprint, and an honest account of the one category you can't take down at all.
Where the standard checklist stops
A typical offboarding checklist is built from an IT asset register. Everything on it has an owner, a licence and an admin console. That's why it works: for each item there is a button somewhere that ends access.
The public footprint has none of those properties. Nobody provisioned the rep's entry in an industry directory, licensed the WhatsApp Business account on their work phone, or logged the bio page they made because the team needed one before a conference. These things were created by a person doing their job, quickly, with whatever was to hand — and they outlive the employment because nothing in your stack knows they exist.
The useful way to sort them is not by tool but by who holds the keys, because that determines whether you take an asset down, request it, or write it off.
| Asset class | Who holds the keys | How it comes down | Realistic time |
|---|---|---|---|
| Internal systems (email, Slack, CRM, VPN) | You | Deactivate in admin console | Same day |
| Brand-owned public assets (website profile, company-issued page, Google Business Profile user) | You | Remove or revoke | Same day, if you know they exist |
| Third-party listings created under your brand (directories, review profiles, marketplaces) | Split — the platform, sometimes the person | Support ticket or claim process | Days to weeks |
| Assets in the person's own account (personal social, personal bio page, personal number) | Them | Request only — no technical route | Never guaranteed |
| Printed material already in circulation (cards, signage, brochures) | Nobody | You can't recall it; you can only control what it points to | Permanent |
The public-facing takedown checklist
Work it in three passes. The first pass is same-day and mechanical. The second takes a week and needs someone to actually look. The third never fully closes, so plan for it instead of chasing it.
Pass one: things you can end yourself, on the last day
- Email signature and auto-reply — set the forward, and check the signature block on any shared or role mailboxes they had send-as rights on.
- Shared logins — rotate every credential in the shared vault they had access to, not just the ones assigned to them. If a password was in a spreadsheet, treat it as compromised.
- Scheduling and meeting links — calendar booking pages, webinar host accounts, recurring meeting ownership.
- Company-issued public page — their staff bio on your website, and any company-issued profile or link page. If it was provisioned centrally, this is one action.
- Phone, extension and voicemail — including the recorded greeting, which usually names them.
- WhatsApp Business — if it runs on a company SIM, retrieve the SIM before the last day. If the company number was ported to their personal handset, sort that out before you announce the departure, not after.
- Google Business Profile and ad accounts — remove them as a user, and check whether they were the primary owner. Primary ownership walking out the door is a painful recovery.
- E-signature, invoicing and quoting tools — anything that can send a document with your name on it.
Pass two: the footprint someone has to go and find
Search for the person's name together with your company name and see what comes back. Then check, in order:
- Industry directories and association listings — professional bodies, chambers, trade associations, franchise or dealer locators.
- Review and marketplace profiles — agent profiles on property portals, adviser profiles on comparison sites, individual reviewer profiles that carry your brand.
- Partner and vendor directories — "find a certified partner" pages on suppliers' sites, which are often maintained by a person, not a process.
- Event and content bylines — speaker bios on conference sites, podcast guest pages, webinar landing pages, co-authored posts. These usually can't be removed, but the link in the bio can often be updated, and that's the part that matters.
- Anything still pointing at a page you control — a link you can repoint is better than a listing you have to chase. This is the whole argument for putting one updatable link on every employee page rather than hard-coding destinations everywhere.
Pass three: print, and everything already in someone's hand
Business cards, brochures, vehicle branding, trade-show banners, sponsor boards, the laminated sheet at reception. You cannot recall any of it. What you can do is make sure the destination those materials point to is one you still control — which is a design decision made months before the resignation, not an offboarding task.
The category you cannot take down
Here is the part most checklists skip, because there's no satisfying answer to it.
If an asset lives in an account the person opened in their own name, with their own email address, you have no technical route to it. Not a slow route or an escalation path — none. That includes their personal social profiles with your branding in the header, the personal mobile number four hundred customers have saved under your company name, and the link-in-bio page they set up themselves because they needed one for a campaign and nobody had issued them anything.
Your options are limited to asking. A well-drafted employment agreement helps — it can require the removal of brand identifiers on separation, and it gives you something to point at. A specific request in the last week also works more often than people expect, because most leavers aren't trying to cause a problem, they're just busy: a vague "take down anything with our logo" doesn't get actioned, while "please remove the header image and the company name from your bio by Friday" usually does.
But you're negotiating, not administering. If the relationship ended badly, you're negotiating from a weak position over an asset that carries your brand to your customers. That asymmetry is the real argument for deciding upfront who controls the asset, and it's why what happens to a rep's page when they leave should be settled before you ever hand one out.
Issued pages make revocation one action
The structural fix is to move the public-facing page out of the third row of that table and into the second: make it something the organization provisions, so it's something the organization can withdraw.
That's the model behind Biotree for Organizations. The company creates a managed page for each person, on their work email, through a single Partner API call. That one call creates the account, the page, the handle (which becomes handle.biotree.bio), the profile photo, bio, links, social icons, background and style. The page is live immediately. Nobody signs up, nobody picks a template, nobody is left holding the login.
When the person leaves, you revoke. The page is unpublished, the URL stops serving, and the content is preserved so that if the person returns — or the page belonged to a role you're rehiring into — re-granting restores it. It's one call, and it doesn't depend on the leaver's cooperation or their mood.
Two details matter for offboarding specifically:
- Shared destinations are indirection, not copies. The media kit or events button on every member page points at a fixed
biotree.bio/go/{org}/{slug}address. You repoint that destination once and every page follows. So when a departure means a resource should move or disappear, you're editing one record, not auditing forty pages. - Tenant isolation is real, and it cuts both ways. An organization can only touch pages it created. If your former rep also has a personal Biotree page, that's a separate asset — it is never converted, absorbed or taken down by the company, and it shouldn't be. Company pages are provisioned on work email precisely so the line between the two stays clean.
ProLend, a private lending business in South Africa, runs this way: every independent consultant gets a branded page issued from prolend.biotree.bio. Consultants come and go, as they do in any independent network, and the offboarding step for the public page is one API call on the day.
QR codes, cards, and what you actually control
Be clear-eyed about QR codes, because they're the item that generates the awkward screenshot three weeks later.
A QR code is a printed pointer. Once it's on a card in a customer's wallet, it exists forever and you cannot change it. What you can change is where it lands. If it points at a page you issued, revoking the page ends the card's usefulness immediately. If it points at a page the person owns, the card keeps working and now advertises whatever they decide to put there — possibly their new employer. Same piece of cardboard, entirely different outcome, decided by whose account the destination sits in. How QR code business cards actually work for teams covers this in more detail.
One honest boundary: Biotree doesn't sell NFC cards, plastic smart cards or any card hardware, and it doesn't do vCard-style "tap to save my contact to your phone" exchange. A Biotree page is the destination a card or QR code points to — the part you can update centrally and take down later. If your team specifically needs tap-to-save-contact hardware, that's a different category of product, and plenty of organizations sensibly use both: the hardware for the tap, an issued page for the destination.
The offboarding sequence that works
Put the public footprint into the existing checklist rather than running a separate process, and split it by who holds the keys:
- Last day — revoke the issued page, rotate shared credentials, retrieve the SIM, remove them as a user on business profiles and ad accounts, update the signature and voicemail.
- Week one — the search-and-find pass: directories, review profiles, partner listings, event bios. Assign it to a named person with a deadline, or it doesn't happen.
- Week one, also — the specific, itemised request for anything in their personal accounts. Name each item. Give a date.
- Ongoing — accept that print is permanent and make sure new print points at destinations you control, so that the next departure is a revocation rather than an investigation.
The honest summary is that offboarding is only as clean as onboarding was deliberate. Every asset you issued, you can withdraw. Every asset someone improvised, you can only ask about. That's the same argument, viewed from the other end, as setting up a new rep's digital presence properly on day one, and it's the practical case for treating public pages as company infrastructure in the complete guide to link in bio for teams and organizations.
If you'd rather your next departure be a one-line revocation than a fortnight of chasing, look at how Biotree for Organizations issues and revokes managed pages for your team, or provision a couple of test pages through the Partner API and try revoking one.
Related guides
Frequently Asked Questions
What digital assets should be removed when an employee leaves?
Beyond the usual email, laptop, Slack and CRM access, remove or update the email signature and voicemail greeting, rotate every shared credential they could reach, remove them as a user on business and ad accounts, take down their staff bio and any company-issued profile page, and work through third-party listings such as industry directories, review profiles and partner locators. Then handle print separately: cards and signage already in circulation can't be recalled, so what matters is whether the destination they point to is one you still control.
Can a company take down an ex-employee's social media or bio page?
Not if the account was opened in the person's own name with their own email address. There is no technical route into an account you don't own, so your only options are a request and whatever your employment agreement says about returning brand assets and removing brand identifiers. This is why pages that carry your brand are better issued from a company account, where withdrawing them is an administrative action rather than a negotiation.
What happens to a QR code on a business card after someone leaves?
The printed code itself can never be changed or recalled, but the page it points to can be. If the destination is a page your company issued, revoking that page makes the card lead nowhere. If the destination sits in the ex-employee's own account, the card keeps working and shows whatever they choose to publish there, including a new employer's details.
How long should offboarding digital assets take?
Internal systems and anything you provisioned should be done on the last day. The search-and-find pass across directories, review sites and partner listings realistically takes a week and needs a named owner with a deadline. Requests for material sitting in someone's personal accounts have no guaranteed timeline at all, which is the reason to minimise how much of your public footprint ends up there.
Who should own an employee's public bio or link page?
The organization, if the page carries the company's brand and is given to customers. Company-owned pages are provisioned on the employee's work email, controlled centrally and revoked on departure in a single action. An employee's personal page remains a separate asset that the company never controls, converts or takes down, and that separation is what keeps offboarding clean.
Does revoking a company-issued page delete the content?
With Biotree for Organizations, revoking unpublishes the page so the URL stops serving, but the underlying content is preserved. If the person returns, or the page belonged to a role you're rehiring into, re-granting restores what was there. The organization can only act on pages it created, so a person's separate personal page is untouched.