Don’t wait until goodbye to protect your IP.
Apple’s lawsuit against OpenAI reads more like a Silicon Valley thriller than a corporate legal filing.
According to Apple, former employees retained access to internal systems, downloaded confidential files after leaving, used secret project codenames during recruiting, and even encouraged job candidates to bring Apple hardware to interviews for “show and tell.”
The complaint also alleges that one former engineer discovered he could still access Apple’s network after leaving, joked that the security flaw was “so funny,” and continued downloading confidential files. Apple further claims an internal document outlining its employee-departure security procedures was shared with future OpenAI hires before they resigned.
OpenAI denies wrongdoing, and none of Apple’s allegations has been proven in court.
Regardless of how the case unfolds, it raises a question every founder should ask: What happens to your company’s most valuable information after an employee walks out the door?
Employee offboarding is an operating system
Most founders think of offboarding as an administrative event.
Collect the laptop. Disable the email account. Conduct an exit interview. Maybe order a sheet cake, if nobody is too angry.
But offboarding isn’t merely the end of employment. It’s the final stress test of your intellectual-property protection system.
Your company’s most valuable knowledge may include product designs, customer information, pricing models, supplier relationships, source code, operating procedures, strategic plans, and lessons learned through expensive mistakes.
Some of that is documented. Other knowledge lives inside software. The rest exists only in someone’s head.
All of it can become vulnerable during a transition. Also, the more valuable the employee, the more access that person may have accumulated.
Trust isn’t a control system
Founders often resist tighter controls because they don’t want employees to feel distrusted. Great companies are built on trust. But trust and control aren’t opposites.
You can trust good people while still creating systems that don’t require everyone to behave perfectly. Your accounting system doesn’t eliminate approvals because employees seem honest. Your building doesn’t stop using locks because your team feels like family.
IP protection deserves the same discipline.
Employees should have access to the information they need—not every file they might someday find interesting. Sensitive access should be role-based, logged, reviewed, and removed when responsibilities change.
That protects the company. It also protects employees by making the boundaries clear.
That control system must be designed long before an employee becomes a departure risk.
Offboarding begins before the resignation
The worst time to discover what an employee can access is after that employee gives notice.
By then, the organization is scrambling to identify devices, accounts, shared folders, outside vendors, prototypes, personal downloads, cloud services, and passwords shared three managers ago because someone needed to “get this done quickly.”
That isn’t an offboarding problem. It’s a systems problem that offboarding finally exposed.
The offboarding process actually begins when access is granted. Every permission should have an owner, a purpose, and a way to revoke it.
When an employee changes roles, their access should change with them. When they leave, HR, IT, legal, security, and the employee’s manager should already know what must happen and who is responsible.
Documentation alone isn’t protection
The popular takeaway from Apple’s lawsuit is that your IP walks on two legs, so founders should document everything. That’s only half right.
Companies should document essential knowledge so the business doesn’t depend on any single employee. But Apple’s allegations involve information already documented: technical specifications, engineering presentations, project data, supplier information, and security procedures.
The alleged problem wasn’t simply that knowledge lived inside people. It was that people may have retained access to knowledge they were no longer authorized to possess.
Documentation protects continuity. Access controls protect confidentiality. Founders need both.
Build the system before you need it
No system can guarantee that confidential information will never be misused. Human beings remain stubbornly human.
However, founders can make misuse harder, easier to detect, and far less damaging.
Start with one uncomfortable exercise: Identify the three people with the broadest access to your company’s most valuable information. Then ask what they can reach, why they can reach it, whether their activity is logged, and how quickly that access could be removed.
If the answers aren’t clear, you’ve found the weakness before an employee exit or a competitor finds it for you.
Your intellectual property may walk on two legs, but it should never be able to walk out because your systems held the door open.
This post originally appeared at inc.com.
“Click here to subscribe to the Inc. newsletter: inc.com/newsletters"