Skip to content

Learn

Hand off company phone access during offboarding

Keep the company number in place and change the people and software that can use it. This checklist assigns an owner and evidence to each handoff step.

Identify the dependencies while access is available

Review account inventory, credential-store entries and company number labels. Find services using the departing person's phone or depending on a connection they created. Assign a receiving administrator for each account before changing ownership.

For a personal destination number, complete the service's supported update with authorized participants. For a company-held number, the identity can stay stable while its readers and credentials change.

Prove the receiving owner can use the account

Have the new owner confirm their service role and complete the relevant sign-in or verification step. They should find the number by its label, retrieve the message through their own inbox access, and reach the expected account state.

This small exercise catches an incomplete handoff: a number can be available while the new person still lacks the service's administrator role.

Review software connections alongside membership

Removing a member revokes the command-line approvals and assistant connections they made in that workspace. Shared API keys they created keep working, because they may run CI or another team's workflow. Find those keys and CI secrets, record each continuing workflow's owner and selected numbers, then replace or revoke them according to the company's offboarding policy.

Treat external service sessions separately. Removing Phonekit membership does not remove the person's account role or existing session in another product. That service's own session and recovery settings need their own completion evidence.

Close each item with an owner and evidence

ActionResponsible roleEvidence of completion
Identify affected accountsOperations / account ownerUpdated inventory with receiving owner
Confirm service administrationService administratorNew owner can administer the account
Check SMS retrievalReceiving ownerIntended verification flow completed
Remove departing member accessWorkspace administratorMembership and number grants reviewed
Review API / CLI / CI / assistant accessWorkflow ownerRevocation or replacement recorded
Update service sessions and recoveryService administratorService-specific checks completed
Close outstanding number changesOffboarding coordinatorFollow-up owner and due date, if needed

Scroll horizontally to see all columns.

Keep the record with the company's normal offboarding evidence. The next administrator should know which work remains, without reconstructing it from old SMS messages.

Questions you may have

Do we need to replace the company number?

A company-held number can remain in place when a person leaves. Change access and review the accounts attached to it. Replace the destination only when the service or your security process requires it.

Does removing a teammate revoke every software key they used?

Not every one. Their personal command-line and assistant connections are revoked automatically. Shared API keys they created stay active, since one may power an ongoing CI job. Review those explicitly and record whether each was revoked, replaced or intentionally retained with a new owner.

Can deleted messages remain usable elsewhere?

The service that issued a code controls its expiration. Removing the copy in Phonekit does not invalidate it at that service. Account-session changes, recovery updates and credential revocation cover different parts of the handoff.