finishlineMSPLet’s talk

People Ops & operations

Employee IT offboarding checklist: access, data, and devices

Coordinate the departure with the authorized manager, block access at the agreed time, preserve required business data, transfer ownership, and recover equipment. Deleting an email account alone does not complete offboarding.

Agree on timing and ownership

Before changing access, confirm the departure time, responsible manager, IT owner, and data-retention requirements. Handle the process through the organization’s approved HR and security workflow. Do not perform an unplanned deletion merely because a calendar event says the person is leaving.

  • Record the authorized access-cutoff time and time zone.
  • Identify the owner of each offboarding task.
  • Confirm who should receive ongoing business work and files.
  • Resolve retention or hold requirements with the appropriate internal owner before deletion.

Work from an application inventory

Start with identity and email, then check the application inventory for direct logins, contractor accounts, personal access tokens, shared credentials, and external workspaces. A service that is not connected to your identity provider may keep accepting a separate login after the main account is disabled.

  • Disable sign-in through the supported administrative controls.
  • Revoke sessions and tokens where the platform supports it.
  • Review code hosting, cloud consoles, finance systems, password vaults, and customer tools.
  • Rotate shared secrets the person knew when appropriate, coordinating changes to avoid breaking services.

Preserve the work before removing the account

Separate access removal from data deletion. Identify business files, calendars, mailboxes, automations, and integration ownership that need a new owner. Check the current vendor documentation for your account type and license before removing accounts or licenses: retention and transfer behavior differ between products.

  • Assign a new owner for shared business content and ongoing workflows.
  • Review mailbox handling with the authorized business owner.
  • Test important automations that may depend on the departing account.
  • Confirm preservation and transfer are complete before destructive steps.

Close the device handoff

Use the equipment record to identify the laptop, peripherals, and other company property. Agree on the return method and record receipt. Any remote lock or wipe should follow company policy and the device’s ownership model; do not treat a personally owned device like a company-owned laptop.

  • Arrange return packaging or an in-person handoff.
  • Record the received serial number and condition.
  • Preserve required data before approved wiping or reassignment.
  • Remove the former employee from the active equipment assignment.

Verify the result with the next owner

Ask the incoming owner to test the transferred files and workflows. Reconcile the completed access list with the original inventory, document exceptions, and give each exception a responsible person. Keep a completion record so future questions can be answered without reconstructing the departure from scattered chat messages.

Your working checklist

Use this as a starting point. Assign an owner and a due date to each item. Checkmarks stay on this device only; don’t enter employee information here.

0 of 16 completed

Download checklist

Common questions

Should we delete the employee account immediately?

Do not treat deletion as the first or only step. Coordinate access blocking, preservation, transfer, and retention before deleting an account. Follow the current instructions for the actual platform and account type.

Does disabling Google Workspace or Microsoft 365 remove all access?

It addresses that platform’s identity, but separately managed applications, shared secrets, tokens, and external workspaces need their own review. Verify the full inventory.

Platform references

For product-specific actions, check the current instructions for your edition and account type.