TREADSTONE LAW · ONTARIO · DIGITAL LEGAL SERVICES · EST. MMXXI ·TSL
Home/Case Studies/Corporate
№ 379 Case Study — Corporate

A Departing Director, a Slow Offboarding, and a Client List

Rosario and Jerome had built the company together as friends first and business partners second. When Jerome announced he was leaving to start a competing venture, the friendship made the exit slower than it should have been.

Corporate8 min readPerth, OntarioLeaks from the boardroom
All Corporate case studies
ClientRosario, owner-operator of a twenty-person company in Perth
The issueA departing director kept portal and system access for weeks after resigning
ServiceCorporate governance advice, an access audit, and a negotiated resolution with the departing director
ResolutionA clear win — access was closed, the company's position was documented, and no client relationships were lost

The situation

Rosario and Jerome had known each other for eleven years before they became business partners. Rosario, who had trained as an actuary before deciding she wanted to build something instead of measuring risk for other people's ventures, started the company with Jerome as a board member and a source of early capital. Jerome had a veterinary practice of his own and never worked in the business day to day, but he sat on the board, had a seat in the shareholder agreement, and over the years had come to see himself as more than a passive investor. He used the word 'we' about the company as often as Rosario did, even though he had not drawn a paycheque from it in years.

The company had grown into a twenty-person operation with revenue in the five to twenty million dollar range, supplying custom parts to a small number of long-standing industrial clients. Those relationships were the business, built over years of on-time delivery and direct personal contact between Rosario and each client's own operations team. Losing even one client of meaningful size would have been felt immediately, and replacing that revenue would have taken longer than the company could comfortably absorb.

Zainab, the company's operations manager, was the one who noticed something was off. Jerome had told Rosario at a dinner in early spring that he intended to resign from the board and pursue 'something of his own' in a related space. The resignation was handled amicably on paper, with a short letter and a warm exchange of texts afterward. What did not happen, in the weeks that followed, was a proper technical offboarding. Jerome kept his login credentials to the client relationship system, the shared drive, and the company email distribution lists for close to a month after his resignation letter was signed, because nobody on Rosario's small team had a checklist for closing that access and Rosario herself did not think to ask.

Rosario did not want to believe Jerome would use that access against her. They had raised money together, sat through hard years together, and she treated the delay as an administrative oversight rather than a warning sign. By the time Zainab flagged unusual login activity — access to the client contact list at hours when nobody else was working — the company's competing offer to one of its largest clients was already being drafted somewhere else, and Rosario was left trying to understand how quickly a friendship could turn into a competitive threat.

What the other side was relying on

Jerome's position, when it was finally put to him directly, rested on a simple claim: nothing in his shareholder or director agreement said he had to delete anything, and he had signed nothing on his way out that restricted what he could do next. He was relying on the fact that the company's own paperwork was thin. There was no separate confidentiality or non-solicitation agreement layered on top of the shareholder agreement, and the director agreement he had signed years earlier said little about what happened to information access when a director left. In his mind, that silence meant permission.

He was also relying, whether he said so or not, on the relationship. Jerome and Rosario had built the company as friends, and he seemed to be counting on the awkwardness of that history to slow down any response. A formal legal letter felt, to Rosario, like a betrayal of eleven years of trust, and Jerome appeared to be banking on that discomfort keeping her from acting decisively. His approach — informal, personal, framed in conversation as 'just exploring options' — was designed to keep things in that register for as long as possible, because the longer the company treated this as a personal matter rather than a legal one, the more time he had to build his competing offer and approach clients before anyone stopped him.

There was a real evidentiary problem underneath the personal one, even if the underlying law was on the company's side. A director's obligations do not simply switch off at resignation: someone who resigns still cannot take up a business opportunity that was maturing for the company while they were in office, and the duty not to use the company's confidential information for a personal advantage continues afterward. What gets harder with time is proving a breach, not the obligation itself. Jerome's resignation had already been accepted before anyone raised concerns, and the clock that mattered was evidentiary: every week of continued access blurred the record further, making it easier for him to argue later that anything he knew came from general industry knowledge rather than privileged access.

The company also had to reckon with an uncomfortable fact: it could not prove, on the first day it raised the issue, exactly what Jerome had taken or when. The access logs told a story, but not a complete one, since the systems in question logged logins more reliably than they logged what was actually viewed or copied. Jerome's advisors, once he retained them, pushed hard on that gap, arguing the company was speculating about motive rather than pointing to a clear, provable breach, and suggesting that ordinary continued access after a friendly resignation was not evidence of anything improper on its own.

What we did

  1. Separated the personal conversation from the legal one. Rosario's instinct was to call Jerome and work it out over dinner the way they had worked out disagreements before. We advised against that as a first step, not because the relationship did not matter, but because an informal conversation with no record would have given Jerome room to characterize any later legal step as an overreaction to a misunderstanding. We needed the record to start clean.
  2. Ran an access audit before making any accusation. Before anyone contacted Jerome, we had the company's IT contractor pull a full log of what systems he had accessed since his resignation date, what had been viewed, downloaded, or forwarded, and when. This mattered because a fiduciary duty claim is only as strong as the evidence behind it, and we did not want to open a conversation we could not back up.
  3. Closed every remaining point of access immediately. Regardless of what conversations followed, the company revoked Jerome's credentials to the client system, shared drives, and email lists the same day the audit was requested, rather than waiting for a formal response from him first. Stopping the bleeding came before assigning blame, because every additional day of access made the eventual legal position weaker, not stronger, and it removed any risk of him arguing later that continued access implied continued consent.
  4. Wrote to Jerome directly, addressing both the relationship and the law. Given how personal the situation was, we drafted a letter that acknowledged the history between Rosario and Jerome plainly, rather than pretending it did not exist, while setting out the company's position on his fiduciary obligations as a former director and the specific conduct the access logs showed. A letter that ignored the emotional context would have hardened his position; one that only addressed feelings would have given up ground.
  5. Set out what the company needed, not what it wanted to punish. Rather than opening with threats, the letter asked for three concrete things: written confirmation that no client information had been shared with any third party, destruction of anything downloaded, and a short list of clients Jerome had contacted since his resignation. Framing the ask this way gave Jerome a path to resolve the matter without a drawn-out fight, which mattered because litigation against a former friend and co-founder carries costs beyond legal fees.
  6. Reached out to the client whose contract was at risk before Jerome could. With Rosario's approval, we helped her draft a short, calm message to the client reaffirming the relationship and the service commitment, without disclosing the internal dispute. Getting ahead of any approach from Jerome meant the client heard from the company first, on the company's terms.
  7. Negotiated a written resolution rather than filing anything. Once Jerome's advisors understood the strength of the access logs and the narrowness of his legal footing, we negotiated a signed acknowledgment: Jerome confirmed he had not shared client information externally, agreed to destroy what he had downloaded, and agreed not to solicit the company's existing clients for a defined period. Getting this in writing, rather than accepting a verbal assurance, gave the company something enforceable if the conduct recurred.

The outcome

The client relationship at risk stayed with the company. Jerome signed the acknowledgment within three weeks of the company's first letter, confirmed in writing that he had not disclosed or used the client contact information for his new venture, and agreed to a period during which he would not approach the company's existing clients directly. No litigation was filed, and no client ever learned there had been a dispute at all, which mattered to Rosario almost as much as the outcome itself.

The company did concede something to get there quickly: it did not pursue a claim for damages over the weeks of unauthorized access, and it accepted Jerome's word, backed by the written acknowledgment, rather than demanding an independent forensic review of his personal devices, which would have been slower, costlier, and harder to enforce against someone who was no longer under any contractual obligation to cooperate. Rosario weighed the cost and disruption of pushing further against the value of closing the matter cleanly, and chose speed and certainty over a harder-fought result that might have taken a year or more to resolve through the courts, with no guarantee of a better outcome at the end of it.

What made the difference was not aggression. It was closing the access gap immediately, building a factual record before any conversation happened, and keeping the personal relationship and the legal position in separate lanes so that neither one undermined the other. The friendship between Rosario and Jerome did not survive the episode in its old form, but the business did, with its client base intact and a clearer governance process for the next departure. Rosario also asked us to draft a standard offboarding checklist for future board and staff exits, so that no future access gap would depend on someone remembering to close it in time.

What you can learn from this

  • Revoke a departing director's or officer's system access on the day they leave, not weeks later — every extra day of access weakens your ability to show what happened and when.
  • A personal relationship with someone leaving your board is not a reason to skip a proper legal process; it is a reason to be more careful about keeping the two separate.
  • A director's confidentiality and opportunity duties do not end at resignation. What gets harder with time is proving a breach, not the obligation itself, so delay in addressing one only weakens the record you'd need to prove it.
  • Build your evidence before you confront anyone. An access log pulled after the fact is far weaker than one that shows exactly what happened while it was still fresh.
  • A written resolution that gives up some ground quickly can protect a business relationship better than a drawn-out claim that wins more but costs a year and the client along the way.
This case study is entirely fictional. It does not describe any real client, file, or matter handled by Treadstone Law, and it is not a real file with details changed. All names, people, properties, businesses, dollar amounts, dates, and events are invented, and any resemblance to a real person, business, or situation is coincidental. Fictional scenarios like this one illustrate the kinds of legal issues people in Ontario commonly face and how a lawyer can help. They are general information, not legal advice — no two matters unfold the same way, and nothing here predicts the outcome of any real case. Reading a case study does not create a lawyer-client relationship. If you are facing something similar, speak with a lawyer about your specific circumstances.

This is a corporate problem we handle

Start a file online — flat, published fees, reviewed by a licensed lawyer before a dollar is owed.

ContactStart a File →