Nobody keeps access after they leave

Ex-employees with live logins are one of the most common, most avoidable breaches. The fix is boring: a list, done the same day, every time.

Loading the tool…

How it works

  1. Choose “leaving” or “changing role”, and tick the platforms in use — from Google Workspace to kintone, freee, Chatwork and the office badge.
  2. Read the list: what to do when notice is given, on the last day, within 24 hours, a week and 30 days — with an owner for each line.
  3. Print it with tick boxes, or export Markdown/CSV into your ticketing tool.

Why nothing is uploaded

Every operation on this page is done by code running inside your browser tab, using the same engine that renders web pages. The file is read from disk into your tab’s memory, transformed there, and written back out as a download. It is never sent anywhere — not to us, not to a third party.

Verify it yourself

  1. Open your browser’s developer tools (F12) and select the Network tab.
  2. Load your file and run the tool.
  3. The only requests you will see fetch the tool’s own code — and, for a few heavy tools, their open-source engine from a public CDN — plus one small page-view ping to loreatec.jp (page address and title, nothing more). None of them carry your file.

Proof it stays local →

Frequently asked questions

Why “disable, do not delete” on the last day?

Because the mailbox and files are usually needed for handover, and some may be under retention rules. Disabling sign-in and revoking sessions and tokens removes the risk immediately; deletion is a later, deliberate step in the 30-day section.

Why rotate shared passwords — is that not paranoid?

It is the single item most often skipped. Wi-Fi keys, social-media logins, vendor portals and service accounts are known to whoever used them; a disabled personal account does nothing about those. Rotating them is what actually closes the door.

Does it cover Japanese tools?

Yes — Chatwork, LINE WORKS, freee, マネーフォワード クラウド, kintone, Sansan and rental-server control panels are in the list next to Google Workspace, Microsoft 365, Slack and the cloud consoles, with steps that match how each one is administered.

Is it also for a department transfer?

Choose “changing role”: the list then focuses on removing the old access rather than the person — old shared drives, channels and admin roles — while the account itself moves on. Access that is kept “just in case” is how privilege creeps.