Onboarding is a first impression, so companies invest in it. Offboarding is an ending, so most companies wing it. That imbalance is exactly backwards from a security standpoint: onboarding a new hire with a slightly-too-slow laptop setup is an inconvenience, offboarding an employee without fully revoking their access is a standing liability that can sit undiscovered for months.

Why offboarding fails more often than onboarding

Onboarding has a hard deadline everyone respects, a start date. Offboarding often doesn't, especially for a resignation with two weeks' notice or a departure that happens quietly over a Friday afternoon. Without a fixed, non-negotiable checklist, offboarding becomes reactive: HR tells IT the person is leaving, IT disables the obvious account, and whatever wasn't obvious, a personal device with company email synced, a third-party tool the person set up under their own login, a shared password only they knew, gets missed.

The checklist: identity and access first

  • Disable the primary account (email, SSO/identity provider) the moment access should end, not at end of business that day
  • Revoke or transfer ownership of any shared mailboxes, calendars, or distribution lists the person managed
  • Remove the person from every group, security role, and admin permission, not just their own account
  • Reset or rotate any shared credentials the person had access to (shared logins should be rare, but audit for them anyway)
  • Revoke API keys, service accounts, or integrations the person personally provisioned

The checklist: devices and data

  • Remotely wipe or lock company data on any personal device enrolled under a BYOD policy
  • Collect and wipe company-owned hardware, and confirm the wipe, don't just collect the device
  • Redirect or archive the person's email and files to a manager or designated owner before the account is deleted
  • Check for local, unsynced files on the person's device that never made it to shared storage

The checklist: third-party and SaaS access

This is the category that gets missed most often, because it isn't centralized. Any SaaS tool an employee could sign up for with a work email is a potential loose end: marketing platforms, dev tools, scheduling apps, vendor portals. A periodic access audit, not just an offboarding-day scramble, is the only reliable way to catch tools that were never provisioned through central IT in the first place.

The accounts you remembered to disable were never the risk. The risk is always the one nobody remembered existed.

Timing: same-day for involuntary, planned for voluntary

Involuntary departures need access revoked at the moment of notification, before the conversation ends if possible, not after. Voluntary departures with notice periods have more room, but "more room" should mean a scheduled, calendared offboarding date, not an open-ended one. The riskiest pattern is a resignation where access quietly lingers for a few extra days because nobody explicitly owns the task of cutting it off.

Who owns the checklist matters more than the checklist itself

A checklist that exists in a shared drive but has no assigned owner will get followed inconsistently. Offboarding needs a single accountable party, usually IT or a managed services partner, who is notified automatically the moment HR marks someone as departing, and who works the list the same way every time regardless of how the departure happened. Consistency is what closes the gaps that ad hoc processes leave open.

A five-minute audit to run today

Pull a list of every employee who's left in the last twelve months and check whether their account, their device, and any tools they personally set up are fully deprovisioned. Most companies that run this audit for the first time find at least one account that should have been closed months ago. That's not a hypothetical, it's the most common finding in an IT readiness review.

Want a second set of eyes on your offboarding process?

Take our free IT Readiness Assessment and get a grounded recommendation based on your current setup, no sales pressure attached.

Take the Free IT Assessment
Workplace Managed IT Security