Halian Systems | Empowering Business

Security | 6 min read

IT Offboarding Checklist: Closing the Security Gaps Employees Leave Behind

Onboarding gets a checklist, a welcome email, and a first-day plan. Offboarding often gets a laptop return and not much else – which is exactly why it’s one of the most common sources of quiet security exposure.

Access does not expire on its own

Every account, app, and shared drive an employee had access to needs to be explicitly revoked. Assuming it “expires eventually” is how former employees end up with live credentials months later.

Shared logins are the biggest blind spot

If a departing employee knew any shared or service account passwords, those need to be rotated – not just their personal login disabled.

Don't forget the accounts IT doesn't manage

Marketing tools, vendor portals, personal-device email sync – departments often set these up independently, and they’re the ones most likely to get missed.

The offboarding gaps that cause problems are never the obvious ones. They’re the accounts nobody remembers exist.

Revoke before you announce, when possible

For involuntary departures especially, sequencing matters: cut access at the same time as the conversation, not sometime that afternoon.

Recover devices and verify what's on them

Company data on a personal device or an unreturned laptop is unfinished business, not a minor detail to follow up on “when you get a chance.”

Keep a written checklist, every time

Ad hoc offboarding is where steps get skipped. A standard checklist, followed the same way for every departure, is what actually closes the gap.

The bottom line

Offboarding is a security process, not an HR formality. Treat it with the same rigor as onboarding and most of the risk goes away.

Scroll to Top