Agree on timing and ownership
Before changing access, confirm the departure time, responsible manager, IT owner, and data-retention requirements. Handle the process through the organization’s approved HR and security workflow. Do not perform an unplanned deletion merely because a calendar event says the person is leaving.
- Record the authorized access-cutoff time and time zone.
- Identify the owner of each offboarding task.
- Confirm who should receive ongoing business work and files.
- Resolve retention or hold requirements with the appropriate internal owner before deletion.
Work from an application inventory
Start with identity and email, then check the application inventory for direct logins, contractor accounts, personal access tokens, shared credentials, and external workspaces. A service that is not connected to your identity provider may keep accepting a separate login after the main account is disabled.
- Disable sign-in through the supported administrative controls.
- Revoke sessions and tokens where the platform supports it.
- Review code hosting, cloud consoles, finance systems, password vaults, and customer tools.
- Rotate shared secrets the person knew when appropriate, coordinating changes to avoid breaking services.
Preserve the work before removing the account
Separate access removal from data deletion. Identify business files, calendars, mailboxes, automations, and integration ownership that need a new owner. Check the current vendor documentation for your account type and license before removing accounts or licenses: retention and transfer behavior differ between products.
- Assign a new owner for shared business content and ongoing workflows.
- Review mailbox handling with the authorized business owner.
- Test important automations that may depend on the departing account.
- Confirm preservation and transfer are complete before destructive steps.
Close the device handoff
Use the equipment record to identify the laptop, peripherals, and other company property. Agree on the return method and record receipt. Any remote lock or wipe should follow company policy and the device’s ownership model; do not treat a personally owned device like a company-owned laptop.
- Arrange return packaging or an in-person handoff.
- Record the received serial number and condition.
- Preserve required data before approved wiping or reassignment.
- Remove the former employee from the active equipment assignment.
Verify the result with the next owner
Ask the incoming owner to test the transferred files and workflows. Reconcile the completed access list with the original inventory, document exceptions, and give each exception a responsible person. Keep a completion record so future questions can be answered without reconstructing the departure from scattered chat messages.
Your working checklist
Use this as a starting point. Assign an owner and a due date to each item. Checkmarks stay on this device only; don’t enter employee information here.
0 of 16 completed
Common questions
Should we delete the employee account immediately?
Do not treat deletion as the first or only step. Coordinate access blocking, preservation, transfer, and retention before deleting an account. Follow the current instructions for the actual platform and account type.
Does disabling Google Workspace or Microsoft 365 remove all access?
It addresses that platform’s identity, but separately managed applications, shared secrets, tokens, and external workspaces need their own review. Verify the full inventory.
Platform references
For product-specific actions, check the current instructions for your edition and account type.