What happens if an employee leaves or loses a signing device?
3 min readYour authority and recovery design should define how the business handles unavailable participants and departing staff. Planning this before an incident helps avoid depending on one person’s continued availability.
Identify which responsibility is affected
A departing employee may have account access, approval responsibility, a device used for authorization, or another operational role. These are not necessarily the same as holding a cryptographic signing share. Start by identifying the exact access that must change. Record the affected wallet and environment, and involve the people responsible for the supported offboarding or recovery process. Avoid solving a staffing problem by informally sharing a replacement person’s credentials.
Remove old access as well as adding new access
Continuity is only half the job. The organization also needs to know that a former employee or lost device no longer has inappropriate authority. Ask which supported changes revoke access, which records demonstrate the change, and whether outstanding approvals need review. Do not assume that changing a contact name or an application password changes every wallet-related permission. Each affected role should be checked at the boundary where it actually grants access.
Prepare the procedure before it is urgent
Build an offboarding checklist around your real deployment and assign an owner to each action. Include a case where the employee cannot participate, such as a lost device or unexpected absence. Test only through an agreed safe workflow, retaining the results without recording secrets in the checklist. If the necessary replacement or recovery operation is not enabled, escalate that dependency rather than improvising a signing process. The goal is continued legitimate control without preserving unwanted access.
Illustrative example
A pilot rehearses an unavailable approver and records who may authorize the next permitted recovery step.
Conditions & limitations
Do not assume an automatic replacement, unchanged wallet address, or provider-assisted recovery. Those outcomes depend on the actual deployment and enabled procedure.
What to do next
Document offboarding and recovery responsibilities, then rehearse through an authorized route without exposing secrets.