Payment access offboarding guide
How Do I Remove a Former Employee's Access?
Remove access through every system the person could use to view, change, refund, or report on payments. Start with individually assigned accounts, then address shared credentials, devices, integrations, physical access, and any recovery methods connected to the former employee.
The short answer
Disable the identity, then verify every access path
Use the administrator tools provided by each payment platform, processor portal, point-of-sale system, gateway, ecommerce account, accounting system, and related service. Disable or remove the former employee's individual account promptly, but do not stop there. Confirm that sessions, security keys, application tokens, shared passwords, email recovery options, and assigned devices can no longer be used.
Access inventory
Check more than the main merchant portal
Payment accounts
Review processor and gateway portals, virtual terminals, invoicing tools, ecommerce dashboards, recurring-payment systems, and chargeback portals.
Point-of-sale access
Check staff PINs, manager permissions, refund or void privileges, reporting access, cash-drawer functions, and back-office accounts.
Connected business tools
Review accounting, CRM, scheduling, delivery, inventory, help-desk, and analytics tools that can expose payment or customer information.
Devices and locations
Collect assigned hardware where appropriate, remove device-management access, and change physical keys, badges, alarm codes, or locked-office access when relevant.
Order of operations
A practical offboarding sequence
Coordinate the timing with the authorized business owner or administrator. The exact controls and labels vary by provider.
1. Identify the person's accounts and roles
Use your user directory, access list, onboarding record, password manager, device inventory, and platform administrator pages to build the checklist. Include accounts created outside the normal process.
2. Disable individual access
Remove or suspend the user's account, revoke active sessions, remove registered authentication methods, and transfer essential administrative ownership to an authorized current employee.
3. Secure shared access
Change shared passwords and PINs the person knew. Review recovery email addresses, phone numbers, API tokens, application passwords, saved browser sessions, and integration credentials. Never send secret credentials through a general contact form.
4. Confirm the result
Re-open each administrator console and verify the user is inactive, the intended owner has access, and no unexpected privileged account or recovery method remains.
Verification
Document what changed without storing secrets
A short offboarding record helps the business confirm completion and investigate later questions. Record the system, former user, action, authorized administrator, timestamp, and verification result. Do not copy passwords, full account numbers, secret keys, or sensitive authentication data into the checklist.
Check privileged roles
Confirm that owner, administrator, refund, settlement, reporting, user-management, and integration privileges are assigned only to current authorized people.
Review recent activity
Where the system provides it, review recent logins and administrative changes for unexpected activity. Escalate concerns through the provider's authenticated support channel.
Test business continuity
Make sure an authorized current employee can reach essential reports, support channels, and recovery methods before closing the task.
Close the checklist
Have the responsible administrator confirm each system was reviewed, including systems where no account was found or no change was required.
Special situations
When the standard checklist is not enough
The former employee was the only administrator
Use the provider's official account-recovery or ownership-transfer process. Be prepared to verify the business and the requester's authority; do not create a replacement identity using the former employee's information.
A shared account cannot be disabled
Change its credentials and recovery methods, revoke sessions or tokens where possible, and create individually assigned accounts for future accountability.
A device is missing
Use available device-management and platform controls, notify the appropriate internal owner, and contact the provider through an authenticated channel if payment access may remain active.
Unexpected activity appears
Preserve relevant logs, limit further access, and follow the business's incident-response process. Contact the affected provider and appropriate security or legal professionals when warranted by the facts.
Related resources
Continue your account-security review
Common questions
Former employee access FAQ
Should I delete the user's account?
Deactivation is often preferable when deletion would remove useful history. Follow the platform's controls and preserve business records.
Is changing one password enough?
Usually not. Review individual identities, shared credentials, active sessions, authentication methods, integrations, devices, and recovery channels.
Who should perform the changes?
An authorized owner or administrator should use the platform's official controls. Payments Max cannot change access for an unrelated provider account.
How often should access be reviewed?
Review access after staffing or role changes and on a recurring schedule appropriate to the business. Remove access that is no longer needed.
Last editorial review: August 11, 2026. Sources reviewed: current NIST and CISA identity and access-management guidance. Provider controls and recovery procedures vary and can change.
Next step
Turn the checklist into a repeatable process
Assign an owner, keep a current system inventory, and make access removal part of every staff departure and role change.
To learn more about how TSYS can help improve the way your organization accepts payments, markets to new customers, or manages its HR responsibilities, get in touch by calling 585-981-8463 to get started.
CONTACT US