Why offboarding checklists miss SaaS subscriptions
Most offboarding checklists cover the obvious ground: turn off email, revoke building access, collect the laptop, remove the person from HR systems. IT-managed software gets pulled into that same deprovisioning flow because it lives behind company single sign-on.
SaaS billing does not always follow that path. An employee trying out a new tool for a project can sign up with a company card and their own work email, without ever looping in IT or finance. A free plan they upgraded on their own initiative, a browser extension billed monthly, or a workspace they were invited into under someone else's account can all keep charging long after that person's badge stops working. The subscription was never tied to their login. It was tied to a card.
None of this is really about a departing employee doing anything wrong. It is what happens when a growing number of small SaaS purchases sit outside the systems built to track access. A day-to-day workflow for managing SaaS on virtual cards handles the ongoing side of that problem. Offboarding is the moment that workflow gets tested against a deadline.
This is not a substitute for an access review if your company already runs one. Identity and access tools are built to show who is connected to what through company logins, and that view still matters. What a virtual card adds is coverage for the subscriptions that never touched a company login in the first place, the ones an employee signed up for on their own with a card number, which an access review has no way to see.
Login access and card access are not the same thing
Login and billing run on separate rails. Removing someone's access closes the rail they used to open a tool. It has no effect on the rail the vendor uses to charge for it, which is the card number sitting in that tool's billing settings.
A virtual card puts that billing rail back under your control. Each card looks and works like a standard Visa card to the vendor's billing system, subject to the merchant's own acceptance and processing setup, so nothing about checkout looks unusual to the vendor. What changes is what happens on your side: the card carries a cardholder name, a spending cap set near the plan price, and, where the vendor supports it, a lock to that one merchant. Cancel that card from the dashboard, and the next new charge attempt against it is typically declined.
Card networks can auto-update a biller with a new card number when a card is reissued, not when it is simply cancelled, so a straight cancellation should stop new charges. That update path matters mainly for step four below, when a subscription is reissued to a new cardholder instead of shut down outright. If a charge clears after you cancel a card, treat it as a signal to also email the vendor and confirm the subscription is closed on their end, not just declined on yours.
How to close out SaaS subscriptions when someone leaves
It works the same way whether it is one card or a dozen.
-
Pull every card tied to the departing employee.
Open the dashboard and look through the card list. Every card shows the cardholder name and the vendor it pays, so SaaS cards issued to that person, or named after a tool only they used, are easy to pick out instead of guessed at from a shared statement.
-
Check whether the tool is shared before you touch the card.
Some cards cover a team plan with several active seats. Closing that card off cuts every seat, not just the one person leaving. Confirm who else depends on the subscription first.
-
Cancel or freeze the card.
If nobody else needs the tool, cancel the card from the dashboard, and the next new charge attempt against it is typically declined. If you need a short handoff window before deciding, freeze the card instead. Freezing stops the card from being used for new purchases without closing it outright, which buys you time without losing the card number or its history.
-
Reissue the card to a new owner if the tool stays in use.
When a teammate is taking over the subscription, issue a fresh card under their name instead of leaving the old card active under someone who no longer works there.
-
Log what happened to each card.
Note which cards were cancelled, which were reassigned, and which vendor still needs a direct cancellation email. This record is what you check if a charge shows up later on a card tied to someone who left.
Give every new SaaS subscription its own virtual card
Set this up before the next departure, not during it. One vendor, one card, so the card list is already clean when someone leaves.
Offboarding day: with virtual cards vs. without
The gap shows up most clearly on the day someone actually leaves, when there is no time to go tool by tool.
Access is revoked. Billing keeps running on whatever card each tool happened to use.
- IT turns off email and single sign-on, which only stops tools that were connected to those systems in the first place.
- A subscription started on a shared company card keeps charging, since the card itself was never tied to the person leaving.
- Finding every tool means checking statements, asking the departing employee's manager, or waiting for a charge to look unfamiliar.
- A subscription still needed by the team has to be recreated from scratch under a new account.
Every card already carries the cardholder name, so nothing needs to be hunted for.
- The card list shows the cardholder name and vendor on every card, so subscriptions issued to the departing employee are easy to spot at a glance.
- Cancelling or freezing a card stops the next new charge from clearing, separate from whatever happens with their login.
- A subscription the team still needs gets reissued to a new cardholder instead of rebuilt from scratch.
- The offboarding record shows exactly which cards were closed, reassigned, or left for a manual vendor cancellation.
The SaaS tools most offboarding lists miss
These four patterns account for most of what a standard offboarding checklist misses:
- The free trial someone upgraded on their own. A tool that started as a free plan and got bumped to paid mid-project may never have been logged as a company subscription anywhere.
- Workspace invites under a personal login. Being added as a guest or collaborator inside another vendor's paid workspace does not always show up as its own billing line.
- One-off vendor signups for a single project. A design tool, a stock-photo library, or an AI writing assistant picked up without finance signing off can be forgotten once the project ends, but the subscription keeps renewing.
- Browser extensions and small utilities. Low-cost monthly tools are easy to overlook precisely because the charge is small enough to not stand out on a statement.
Running a periodic review, not just an offboarding-triggered one, catches subscriptions like these before they turn into a departure-day scramble. See how to audit SaaS subscriptions with virtual cards for that broader review process, or choosing a virtual card setup for SaaS subscriptions if you are still deciding how to structure new cards in the first place.
Example: the marketing contractor's AI subscriptions
Hypothetical example, for illustration only.
A marketing contractor wraps up a six-month engagement. During that time, they signed up for two AI writing tools and a design app on their own, each on a company virtual card issued in their name. When the contract ends, HR removes their email and Slack access the same day. Finance reviews the card list, finds all three subscriptions under the contractor's name, and closes the two AI writing tools right away. The design app turns out to still be in use by someone on the sales team for a monthly report, so instead of closing that card, finance reissues it under the sales team member's name. The review takes one pass through the card list and a short message to sales, not three separate vendor logins to check.
What to do if you don't know every tool someone used
If subscriptions were not on separate cards before now, you cannot retroactively create that clean list for someone who already left. Start from what you can check: pull recent statements for any shared card the person had access to, and flag anything with a vendor name you do not recognize or a charge pattern that lines up with a monthly SaaS bill. If the concern is price creep or unrecognized renewals more broadly, not just this one departure, stopping unwanted subscription charges covers that separately.
Going forward, treat every new SaaS signup the same way, even the ones an employee expenses on their own without asking finance first. One tool, one card. That's the whole fix. Skip it, and six months from now you're back to squinting at a statement trying to remember who signed up for what.








