Hand off company phone access during offboarding
Keep the company number in place and change the people and software that can use it. This checklist assigns an owner and evidence to each handoff step.
Identify the dependencies while access is available
Review account inventory, credential-store entries and company number labels. Find services using the departing person's phone or depending on a connection they created. Assign a receiving administrator for each account before changing ownership.
For a personal destination number, complete the service's supported update with authorized participants. For a company-held number, the identity can stay stable while its readers and credentials change.
Prove the receiving owner can use the account
Have the new owner confirm their service role and complete the relevant sign-in or verification step. They should find the number by its label, retrieve the message through their own inbox access, and reach the expected account state.
This small exercise catches an incomplete handoff: a number can be available while the new person still lacks the service's administrator role.
Review software connections alongside membership
Removing a member revokes the command-line approvals and assistant connections they made in that workspace. Shared API keys they created keep working, because they may run CI or another team's workflow. Find those keys and CI secrets, record each continuing workflow's owner and selected numbers, then replace or revoke them according to the company's offboarding policy.
Treat external service sessions separately. Removing Phonekit membership does not remove the person's account role or existing session in another product. That service's own session and recovery settings need their own completion evidence.
Close each item with an owner and evidence
| Action | Responsible role | Evidence of completion |
|---|---|---|
| Identify affected accounts | Operations / account owner | Updated inventory with receiving owner |
| Confirm service administration | Service administrator | New owner can administer the account |
| Check SMS retrieval | Receiving owner | Intended verification flow completed |
| Remove departing member access | Workspace administrator | Membership and number grants reviewed |
| Review API / CLI / CI / assistant access | Workflow owner | Revocation or replacement recorded |
| Update service sessions and recovery | Service administrator | Service-specific checks completed |
| Close outstanding number changes | Offboarding coordinator | Follow-up owner and due date, if needed |
Scroll horizontally to see all columns.
Keep the record with the company's normal offboarding evidence. The next administrator should know which work remains, without reconstructing it from old SMS messages.
Questions you may have
Do we need to replace the company number?
A company-held number can remain in place when a person leaves. Change access and review the accounts attached to it. Replace the destination only when the service or your security process requires it.
Does removing a teammate revoke every software key they used?
Not every one. Their personal command-line and assistant connections are revoked automatically. Shared API keys they created stay active, since one may power an ongoing CI job. Review those explicitly and record whether each was revoked, replaced or intentionally retained with a new owner.
Can deleted messages remain usable elsewhere?
The service that issued a code controls its expiration. Removing the copy in Phonekit does not invalidate it at that service. Account-session changes, recovery updates and credential revocation cover different parts of the handoff.