PlaybooksTeam member leaves without a handover
Peopleserious40 minutes to prepare

Team member leaves without a handover

A key person departs before transferring ownership, context, credentials, work, or recurring responsibilities.

01DetectConfirm the signal
02ContainStop more damage
03RecoverRestore control
04VerifyProve it works

Your preparation

0 of 0 safeguards ready
0%
Incident worksheet

Make the next decision with evidence

Transfer operational ownership, remove access, and discover hidden work and dependencies before they become outages or customer failures.

EvidenceDecisionActionProof

Capture before evidence disappears

  • Inventory owned repositories, services, queues, dashboards, domains, vendors, automations, documents, credentials, customer relationships, and recurring calendar work.
  • Preserve recent commits, tickets, chat, deployment, audit, support, and billing history to reconstruct current state and pending promises.
  • List shared secrets, local-only files, personal accounts used for work, unfinished migrations, manual jobs, and undocumented exception handling.

Decisions that change the response

QuestionAct whenAction
Pause changes?The team cannot explain deployment, rollback, data, or operational ownership.Freeze nonessential changes while a new owner creates a safe baseline.
Rebuild hidden automation?It runs from a personal device or account and transfer is unreliable.Replace it under business ownership, validate output, and retire the old path.

Proof that recovery worked

  • Every critical asset and recurring operation has an accountable new owner and backup.
  • The departed identity cannot access systems; shared credentials are replaced and old values fail.
  • A second operator can deploy, roll back, restore, handle support, and run scheduled work.

Controls to put in place

  • Track ownership in the repository and service catalog, with no critical single-owner asset.
  • Require business accounts, centralized secrets, runbooks, and visible scheduled automation.
  • Make role changes trigger a handover checklist before access changes become urgent.
Tabletop drill

Select one role and remove its owner from the exercise. The backup must find current work, run a scheduled process, deploy and roll back, answer a customer issue, and transfer all access.

Escalate when

Use HR or counsel when data, devices, intellectual property, or obligations are disputed; treat unexplained post-departure access as a security incident.

What this means

The risk is broader than access removal. Undocumented renewals, customer promises, scheduled work, local files, and personal service ownership can fail later.

Warning signs

  • Nobody else can explain a critical system or recurring task.
  • Accounts, domains, apps, or documents use personal ownership.
  • Work exists only on a local device or private inbox.
  • Customers or vendors expect commitments the team cannot see.

Recover now

First 15 minutes

  1. Protect business access and preserve logs before removing identities.
  2. Inventory owned services, devices, repositories, documents, and customer commitments.
  3. Transfer or recover ownership through official provider processes.
  4. Assign temporary owners to critical daily and weekly responsibilities.

Today

  1. Recover business files, source, keys, contracts, and communications lawfully.
  2. Review upcoming renewals, launches, invoices, support promises, and scheduled jobs.
  3. Remove former access after evidence and ownership are secured.
  4. Document minimum operating procedures as work is reconstructed.

Verify recovery

  • Every critical service and recurring task has a current owner.
  • Business data is in business-controlled systems.
  • Former access is removed and post-departure activity reviewed.
  • Customers and deadlines have explicit follow-up.

Prepare now

Access

  • Critical services use business accounts with at least two administrators.

Backups and evidence

  • Work products and decisions are stored in shared business systems.

Contacts and ownership

  • Recurring tasks, renewals, vendors, and customer commitments have backups.

Practice

  • Each key person can be absent for one week without stopping operations.

Common mistakes

  • Deleting accounts before transferring assets and logs.
  • Focusing only on passwords.
  • Leaving temporary ownership undefined.

Sources

Last reviewed July 19, 2026Guidance changes. Confirm provider-specific actions in the linked official sources.