When a staff member leaves your CPA firm, access to all systems, client data, and applications should be revoked within 15 minutes of notification. Modern managed IT providers maintain documented offboarding checklists that disable email, remote access, cloud applications, tax software, and client portals immediately - protecting sensitive taxpayer data and engagement files from unauthorized access during the vulnerable transition period.
Why Immediate Access Revocation Matters for CPA Firms
Accounting firms hold extraordinarily sensitive data: Social Security numbers, bank account details, tax returns, and financial statements. A departing employee - whether leaving on good terms or bad - represents a security window that must close immediately.
The IRS Publication 4557 (Safeguarding Taxpayer Data) requires CPA firms to implement procedures that restrict access to taxpayer information. When an employee departs, every minute of continued access violates this principle. Former employees have downloaded client lists, copied engagement files, and accessed systems days after termination at firms without proper protocols.
Utah's data breach notification law (Utah Code § 13-44-202) requires notification when unauthorized access to personal information occurs. A departed employee with active credentials creates both a compliance risk and a competitive threat if they're joining another firm.
Sarah, who manages a healthcare practice in Salt Lake City, experienced this firsthand when a previous IT provider took days to disable a terminated employee's access. After switching to a responsive provider, she noted: "Adam came out within a few hours and FIXED our phones immediately! He took the time to LOOK what was wrong instead of just glancing at the issues."
Immediate revocation isn't security theater - it's a documented requirement for protecting client confidentiality and maintaining your professional liability insurance coverage.
What Systems Need Immediate Deactivation
A comprehensive offboarding checklist for CPA firms includes far more than disabling a network login. Tax season complexity means staff access multiple systems throughout the day.
Email and Microsoft 365 access must be disabled first. This prevents the departing employee from forwarding client communications, downloading engagement letters, or accessing shared drives. Email forwarding rules should be checked and removed, and the mailbox converted to a shared mailbox for client continuity.
Tax software access - whether CCH Axcess, Thomson Reuters UltraTax, Lacerte, ProSeries, or Drake - requires immediate deactivation. These applications contain complete client tax returns and historical data. Most tax software platforms allow per-user license management, and credentials should be revoked through the admin console within minutes.
Remote access and VPN credentials represent a critical vulnerability. Many CPA firms allow staff to work from home during busy season. Remote desktop protocols, VPN accounts, and multi-factor authentication tokens must all be disabled to prevent after-hours access from personal devices.
Cloud applications and client portals including QuickBooks Online, Xero, client document exchange platforms (ShareFile, SmartVault), and practice management software (Karbon, Suralink) all maintain separate user accounts that require individual deactivation.
Physical access through building key cards, alarm codes, and office keys must be collected or deactivated. A departing employee shouldn't be able to return to the office after hours to access workstations or file cabinets.
Mark, who runs an insurance firm, explained why he switched to professional IT support: "We brought in 911 IT because we were at a point in our business where we needed professional IT support. Our business had outgrown the services of our previous technology provider and we couldn't afford the periodic downtime we experienced with our internet and phones."
How Fast Can a Managed IT Provider Actually Respond
Response speed depends entirely on your IT support model. A break-fix provider working hourly may take 24-48 hours to return your call, leaving systems exposed. A managed service provider with documented procedures can execute a complete offboarding within 15-30 minutes of notification.
The fastest revocation happens when your IT provider maintains a current asset inventory and pre-built offboarding templates. When you call to report a departure, the technician should already know which systems that employee accessed, which devices they used, and which credentials need disabling.
911 IT provides 24-7 live support with rapid response protocols for security-critical events like employee departures.
During business hours, most managed IT providers can begin revocation within 5-15 minutes of your call. After hours, response time depends on whether the provider offers true 24-7 support or just an answering service that creates a ticket for the next business day.
For CPA firms, this distinction matters enormously. If a staff member resigns at 4:45 PM on a Friday afternoon before a Monday tax deadline, you cannot wait until Monday morning to disable their access. A provider with genuine after-hours support can execute the full offboarding protocol immediately, even at 10 PM on a weekend.
The technical execution speed also varies. Disabling a single Active Directory account takes seconds. Reviewing and removing email forwarding rules, checking for unauthorized file shares, disabling VPN certificates, and coordinating with third-party application vendors (tax software companies, cloud providers) requires 20-40 minutes of focused work.
Large national MSPs often route these requests through a ticket queue where you'll speak with a different technician each time. At a provider like 911 IT, where every client is known by name, the technician answering your call already understands your environment and can execute immediately without researching your setup.
What Happens If Access Isn't Revoked Quickly Enough
The consequences of delayed revocation range from competitive harm to regulatory violations and malpractice exposure.
Data exfiltration is the most immediate risk. A departing employee with continued access can download your entire client list, copy engagement files, and transfer proprietary firm documents. This typically happens within the first few hours after resignation, before the firm realizes access should be disabled.
Unauthorized client contact occurs when a former employee uses their still-active email to contact clients, either soliciting them to a new firm or causing confusion about who represents them. This violates client confidentiality and creates professional liability exposure.
Regulatory compliance violations emerge when auditors or regulators discover that terminated employees retained access to taxpayer data. The IRS, state boards of accountancy, and professional liability insurers all expect immediate revocation. Documented delays can trigger fines, license reviews, or policy exclusions.
Sabotage and malicious activity remain rare but devastating when they occur. Disgruntled employees have deleted engagement files, changed client contact information, and modified financial data in the brief window before access was disabled.
Even well-intentioned former employees create risk. If they retain access and later suffer a personal device compromise, attackers gain a pathway into your firm's systems through those dormant credentials.
The professional liability insurance application for most CPA firms explicitly asks about IT security procedures, including employee offboarding protocols. Insurers price policies based on your documented controls, and a pattern of delayed revocation can increase premiums or create coverage gaps.
Immediate revocation isn't paranoia - it's a documented best practice that protects both your firm and your departing employee by eliminating any ambiguity about post-employment access.
How Salt Lake City CPA Firms Should Structure Offboarding
A professional offboarding process requires coordination between your HR team, firm management, and IT provider. The protocol should be documented, tested annually, and executed identically whether the departure is voluntary or involuntary.
Pre-departure preparation begins before the employee knows they're leaving. Your IT provider should maintain a current inventory of every system, application, and access point each employee uses. This inventory should be reviewed quarterly and updated whenever new applications are added.
Notification protocol defines who calls the IT provider and what information they provide. Best practice: the managing partner or HR director calls immediately upon receiving resignation or making a termination decision. The call should include the employee name, their last day, whether they're currently in the office, and whether the departure is voluntary or involuntary.
Immediate actions happen within 15 minutes: disable Active Directory account, reset passwords on shared accounts the employee knew, disable VPN and remote access, disable email access, and check for email forwarding rules or unusual recent activity.
Extended actions within 2 hours: disable tax software licenses, revoke cloud application access, coordinate with third-party vendors for specialized software, collect physical devices (laptop, phone, key card), change alarm codes and door locks if the employee had physical access, and document all actions taken.
Post-departure review within 24 hours: audit file access logs for the 30 days before departure, review email sent items for unusual activity, confirm all access points are disabled, and brief remaining staff on client transition procedures.
For CPA firms in Salt Lake City working with local IT support providers, this coordination happens more smoothly than with distant providers. A local provider understands Utah's regulatory environment, can respond on-site if needed, and works within your time zone during the critical first hours.
Ryan, who manages a construction firm, appreciated this responsiveness: "Every time I've called in, the team at 911 IT has answered promptly and handled my issue with confidence and clarity. They're incredibly skilled at diagnosing problems and narrowing down solutions quickly, which saves us time and stress."
Comparing IT Support Options for Employee Offboarding
Not all IT providers offer the same offboarding capabilities. The differences matter significantly when you need immediate action to protect client data.
| Provider Type | Typical Response Time | After-Hours Availability | Documented Process |
|---|---|---|---|
| Break-Fix Hourly Tech | 24-48 hours | No (emergency rate if available) | Rarely documented |
| Large National MSP | 4-8 hours (ticket queue) | Yes (tier 1 helpdesk) | Generic template |
| Local Managed IT (911 IT) | 15 minutes | 24-7 live support | Client-specific checklist |
| In-House IT (single person) | Immediate (if available) | Depends on individual | Often undocumented |
Break-fix providers charge by the hour and typically lack documented offboarding procedures. You'll spend time explaining your environment, and they'll bill for every minute of research and execution. After-hours support usually isn't available, leaving you exposed if a departure happens outside business hours.
Large national MSPs like Executech or enterprise-focused providers offer documented procedures but route requests through multi-tier support queues. You'll open a ticket, explain the situation to a tier-1 technician who may not know your environment, and wait for escalation to someone with the appropriate permissions. For a small CPA firm, you're one account among thousands.
Local managed IT providers like 911 IT, Wasatch I.T., Nexus IT Consultants, or Qual IT offer the best balance: documented procedures tailored to your specific environment, technicians who already know your systems, and rapid response without ticket queue delays. The difference between 15 minutes and 4 hours can determine whether a departing employee successfully downloads your client list.
In-house IT staff provide immediate response when available, but single-person IT departments create vulnerability when that person is on vacation, sick, or leaves the company themselves. Who revokes the IT manager's access when they depart?
For CPA firms specifically, choose a provider experienced with accounting firm IT requirements who understands tax software, client portal security, and IRS Publication 4557 compliance. Generic IT support may miss critical access points specific to accounting practice.
What to Ask Your Current IT Provider About Offboarding
If you're evaluating whether your current IT support can handle employee departures properly, ask these specific questions and evaluate the answers carefully.
"What's your guaranteed response time for a security-critical employee departure?" If the answer is vague ("as soon as possible") or measured in hours rather than minutes, you lack adequate protection. A professional provider should commit to a specific timeframe, typically 15-30 minutes during business hours.
"Do you maintain a current inventory of every system and application each of our employees can access?" If they need to research this when you call, they'll waste critical minutes during an actual departure. The inventory should already exist and be reviewed quarterly.
"Can you show me your documented offboarding checklist for our firm specifically?" Generic checklists miss firm-specific applications. Your checklist should list your exact tax software, your specific cloud applications, your practice management system, and your client portal by name.
"What happens if an employee resigns at 6 PM on a Friday or during tax season?" True 24-7 support means a qualified technician answers and executes immediately, not an answering service that creates a Monday morning ticket. For CPA firms, after-hours and busy-season support isn't optional - it's when you're most vulnerable.
"How do you audit whether the offboarding was complete?" Professional providers review access logs after departure to confirm the employee didn't access systems after termination and didn't exfiltrate data before revocation. This audit should happen automatically, not only if you request it.
"What's included in your standard managed services rate versus what costs extra?" Some providers charge separately for after-hours support or security-related work. Employee offboarding should be included in your base managed IT services agreement, not billed as an emergency project.
If your current provider can't answer these questions confidently with specific procedures and timeframes, you're exposed. CPA firms cannot afford ambiguity about access control during employee transitions.
Why 911 IT Offers the Best Offboarding Response for CPA Firms
When a staff member leaves your Salt Lake City CPA firm, you need a provider who treats your security emergency as their priority, not just another ticket in a queue.
911 IT maintains client-specific offboarding checklists that document every system, application, and access point your employees use. When you call to report a departure, the technician already knows your environment - your tax software, your client portal, your cloud applications - and can execute the complete revocation protocol within 15 minutes.
The 24-7 live support means you reach a qualified technician immediately, whether the departure happens at 9 AM on a Tuesday or 7 PM on a Saturday during tax season. There's no answering service, no ticket queue, no waiting for escalation. The person who answers your call can disable accounts, reset passwords, and coordinate with third-party vendors right then.
As a local provider serving Utah businesses, 911 IT understands the specific compliance requirements for CPA firms under IRS Publication 4557 and Utah data breach notification laws. The offboarding process includes the security audit and documentation you need for professional liability insurance and regulatory compliance.
Mitch, who manages a manufacturing company, summarized the difference: "911 IT is able to resolve all of our IT issues, even if the problem has been intermittent. Outsourcing to 911 IT has been a huge relief for our company! They have a quick response time and are honest with all of our problems."
Employee offboarding is included in your managed services agreement, not billed as an emergency project. You won't receive a surprise invoice for after-hours support or security work - it's part of the proactive protection you're already paying for.
With 911 IT's documented procedures, rapid response, and process-driven approach, you get the peace of mind that your client data is protected the moment an employee gives notice. That's the difference between a provider who knows you by name and one where you're account number 4,847 in a ticket system.
Frequently Asked Questions
How long does it take to fully revoke all access for a departed employee?
Complete access revocation takes 15-30 minutes for immediate systems (email, network, VPN) and 1-2 hours for comprehensive offboarding including third-party applications, cloud services, physical access, and audit documentation. Professional managed IT providers maintain client-specific checklists that ensure no access point is overlooked during the critical first hour after notification.
Should we revoke access before or after telling the employee they're terminated?
For involuntary terminations, coordinate with your IT provider to disable access simultaneously with the termination meeting, not before (which alerts the employee) or after (which creates exposure). For voluntary resignations, disable access immediately upon receiving notice. Your IT provider should be on standby during planned termination meetings to execute revocation within minutes of the conversation ending.
What happens to emails sent to a departed employee's address?
Best practice: convert the departed employee's mailbox to a shared mailbox accessible by their supervisor or a designated staff member. Set up an auto-reply explaining the employee has left and providing an alternative contact. Never forward all emails automatically to another employee without review, as this may expose confidential HR or personal communications inappropriately.
Do we need to revoke access immediately even if the employee is leaving on good terms?
Yes. Immediate revocation protects both your firm and the departing employee by eliminating any ambiguity about post-employment access. Even well-intentioned former employees create security and compliance risk if they retain credentials. Professional liability insurers and regulators expect immediate revocation regardless of departure circumstances. The documented procedure should be identical for all departures.
Can a departed employee still access our systems if we only changed their password?
Changing a password alone is insufficient. Employees may have active sessions on multiple devices, saved credentials in browsers, VPN certificates, application-specific passwords, and API tokens that continue functioning after the main password changes. Complete revocation requires disabling the account entirely, revoking certificates, clearing active sessions, and coordinating with each third-party application vendor individually.
What should we do if we discover a former employee still had access weeks after departure?
Immediately disable all remaining access and conduct a forensic audit of their activity since departure. Review access logs, file downloads, email sent items, and system changes. Document findings for potential legal or regulatory needs. Notify your professional liability insurance carrier and legal counsel if any unauthorized access or data exfiltration occurred. Use the incident to improve your offboarding procedures and provider accountability.
