
An employee’s departure is a practical test of information controls. A confidentiality agreement may help, but it cannot replace knowing what sensitive information exists, who can reach it, and which access paths must close. Good offboarding protects specific information without treating ordinary experience as company property.
Name the information you are protecting
The USPTO describes trade secrets as information with economic value from secrecy that is not generally known or readily ascertainable through proper means, and that is subject to reasonable efforts to maintain secrecy. See its trade-secret policy guidance. Labeling everything confidential does not establish that every item qualifies.
Prepare a specific inventory: an unpublished pricing model, manufacturing parameters, restricted source code, or a nonpublic customer analysis. Record the business value, where it lives, authorized users, and existing restrictions. Public product information and a person’s general skills should not be swept into the same category.
For a hypothetical sales manager, distinguish an internally developed margin model from publicly listed customer names. The distinction matters when deciding what to restrict and what evidence could support a later concern.
Close access paths, not just the laptop login
Coordinate HR, IT, and the information owner. Check cloud storage, source repositories, CRM exports, shared inboxes, third-party applications, API credentials, and external sharing links. Rotating one password does not necessarily revoke a reusable token or a publicly accessible document link.
Time access changes to the actual departure and business handover. Remove unnecessary permissions, transfer ownership of business files, and preserve continuity for the remaining team. Keep a dated record of the changes and who confirmed them.
For shared credentials, determine who else depends on them before rotation. Ask IT to verify that the former user’s sessions and recovery routes are addressed. Avoid improvised changes that destroy work or lock authorized colleagues out of essential systems.
Preserve facts without overreaching
If suspicious activity is reported, preserve relevant business logs and records under counsel’s direction before routine deletion erases them. Record what the system actually shows: account, timestamp, action, and file. A download alone does not prove theft, and speculation should not become an accusation.
Do not access personal accounts, remotely wipe personal devices, or demand unrelated private data without a lawful basis and appropriate review. Separate the need to preserve company records from questions about device ownership, consent, and employee privacy.
Keep the investigation narrow and documented. Do not ask an employee to delete material that may be evidence; obtain advice about preservation and a safe return or removal process instead.
Make the exit process reproducible
Use a closing checklist: information inventory checked, authorized access ended, equipment and business materials accounted for, continuing obligations explained, and exceptions assigned to an owner. Review the existing agreement rather than adding an unexamined noncompete at the last moment.
After the departure, test the controls. Can an old sharing link still open the sensitive folder? Is a former account still an owner in a vendor system? Record the test results and fix specific gaps.
Trade-secret protection is a continuing practice, not a dramatic exit interview. A precise inventory and proportionate access controls are more useful than a blanket instruction that everything the employee learned must remain unused.
Editorial note
This article is AI-assisted general information about U.S. intellectual property law, not legal advice or an attorney-reviewed opinion. Examples are hypothetical; the image is a conceptual illustration. Laws, deadlines, and individual facts require independent review. Reading this article does not create an attorney-client relationship.


Comments