The short answer

Remove access across the actual systems they used, not just the main property-management login.

Keys hanging from a lock in an open wooden door.
Illustrative stock photo · Photo: AS Photography / Pexels · Pexels License

Follow the access trail

Check email, shared drives, payment tools, vendor portals and any physical keys. Transfer open work and account ownership before disabling access where necessary. Use the provider’s supported controls for sessions, integrations and shared links.

FTC guidance recommends restricting access to people with a legitimate business need. [1]

A completed checklist should name the system, action and completion time. Keep “requested removal” separate from “verified removed.” Do not delete business records merely because their former owner has left.

Sources

This article was generated by AI using the sources below. Editorial standards.

  1. Protecting Personal Information: A Guide for Business — FTCSupports the attributed passage: FTC guidance recommends restricting access to people with a legitimate business need. The practical workflow and labeled examples are the publication’s own applications, not source-reported cases. Source checked Sep 8, 2026.

Have a correction? See our editorial policy and correction process.