Offboarding an Employee in 60 Minutes
Departing employees keep access far longer than owners realize. A sequenced checklist covering identity, devices, SaaS, physical access, and the accounts nobody remembers.
The short answer
Terminating an employee's access is between fifteen and forty tasks across systems that do not talk to each other. The sequence is identity first, then mail and files, then applications, then credentials they knew, then devices and physical access, then external portals, with a completion record and a 30-day recheck.
Terminating an employee's access sounds like one task. In a modern small business it is somewhere between fifteen and forty tasks spread across systems that do not talk to each other, and the ones that get missed are always the same ones.
We find former employees with active access in most environments we assess. Usually it is harmless: an old account in a marketing tool nobody logs into. Occasionally it is not, and the cases that turn into disputes almost always involve a departure that was not entirely friendly.
Do the sequencing before the conversation
The most common mistake is doing offboarding after the exit conversation. For a voluntary departure with notice, that is usually fine. For an involuntary one, the gap between the conversation and the access revocation is the window in which data leaves.
Coordinate it. The disable happens during the meeting, not after it. That requires deciding in advance who executes and having them standing by, which requires telling one IT person something confidential before it happens. Plan for that.
The sequence
Identity first. Disable the account rather than deleting it, because deletion destroys evidence and can break file ownership and calendar items in ways that are painful to undo. Then revoke active sessions and refresh tokens explicitly, because disabling an account does not always terminate a session already in flight. Reset the password. Remove the account from groups that grant standing access.
Then the second factor. Remove registered MFA methods and any authenticator enrollment so the account cannot be recovered through a self-service path.
Then handle mail and files. Convert the mailbox to a shared mailbox or apply a litigation hold depending on your retention obligations. Set up forwarding or delegate access for whoever inherits the relationships. Transfer ownership of files in personal drives, which is the item most frequently missed and can destroy institutional knowledge when a personal drive is deleted 30 days later.
Then the applications. This is where the list gets long. Every SaaS tool with a separate login. Your CRM, accounting system, payroll, project management, e-signature, password manager, social media accounts, domain registrar, the AI tools they signed up for, and anything on a personal credit card that gets expensed.
Then the credentials they knew. If the employee had access to any shared credential, rotate it. This includes the wifi password if it is a shared key, the alarm code, the shared admin accounts you have not eliminated yet, and any API key they created.
Then devices. Retrieve company hardware, and if you have mobile device management, remove company data from personal devices. Wipe and hold company devices rather than immediately reissuing, in case something needs to be recovered later.
Then the physical layer. Keys, badges, alarm codes, the storage unit, the PO box, and their name on any building access list.
Then the outside world. Remove them from vendor portals, bank access, insurance portals, and any authority granted to them at a third party. Bank access in particular has a habit of surviving for years.
The accounts nobody remembers
Four categories account for most of what gets missed.
Automations and integrations they built. A workflow tool, a scheduled report, a script running under their credentials. When the account is disabled, these break silently and somebody discovers it a month later.
Accounts registered to their personal email. The tool they signed up for during a trial and never migrated. Search your expense records for recurring charges without a matching business account.
Anything where they are the recovery contact. Their phone number or personal email as the account recovery method on a business service is a persistent back door.
Domain and DNS access. Frequently held by whoever set the website up, frequently not documented, and the single most damaging thing to lose control of.
The documentation step
Before the last day, if circumstances allow, capture what only they know. Vendor contacts, process knowledge, where things live, which client prefers what. This continuity step reduces the operational pain that often appears in month two.
After it is done
Send yourself a completion record with timestamps. If a dispute follows, the ability to show exactly when access ended is worth a great deal.
Then check again at 30 days. Run a report of accounts that have not signed in and look for their name. Something is usually still there.
Get the checklist
The Employee Offboarding Checklist is a workbook with the full sequence, a per-application inventory sheet you populate once and reuse, an involuntary-departure timing plan, the credential rotation list, a completion log with timestamps, and a 30-day verification step.
Set it up once with your actual application list and every future departure takes an hour instead of a week of remembering.
Frequently asked questions
What should be on an IT offboarding checklist?
Identity disable plus explicit session and token revocation, MFA method removal, mailbox and file ownership transfer, every SaaS application with a separate login, rotation of shared credentials, device retrieval and wipe, physical keys and codes, and removal from bank, vendor, and client portals.
Should I delete a departing employee's account?
No, disable it instead. Deletion destroys evidence and can break file ownership and calendar items in ways that are painful to undo. Disabling also does not always terminate a session already in flight, so revoke active sessions and refresh tokens explicitly as a separate step.
What access is most often missed when an employee leaves?
Four categories: automations and integrations they built that run under their credentials, accounts registered to their personal email, anything where they are the account recovery contact, and domain or DNS access. The last is the single most damaging thing to lose control of.
When should access be revoked for an involuntary termination?
During the meeting, not after it. The gap between the conversation and the revocation is the window in which data leaves. That requires deciding in advance who executes and having them standing by, which means telling one IT person something confidential beforehand.
Related reading
- Your AI Tools Have Logins Now, and Nobody Is Managing Them
- The Voice on the Phone Is Not Your CFO
- MFA Stopped Being Enough About Two Years Ago
- The Microsoft 365 Settings Most Phoenix Businesses Never Turned On
- Anyone Can Send Email as Your Company Until You Fix This
- Your Weakest Security Control Belongs to Somebody Else
Run one completion review
Thirty days after departure, choose a completed offboarding and verify the evidence. Check sign-in logs, application ownership, forwarding, shared files, vendor portals, devices, and physical access. I have seen clean checklists hide a service account or customer portal nobody remembered to put on the form.
Use what you find to improve the next offboarding. The checklist should learn with the business.
