Before the departure
Confirm the departure time, risk level, legal requirements, responsible owners and whether access should end immediately or at a scheduled time.
A reliable offboarding process coordinates HR, IT, security, managers and data owners. Use this checklist to end access promptly without losing business records or leaving unmanaged shares behind.
Confirm the departure time, risk level, legal requirements, responsible owners and whether access should end immediately or at a scheduled time.
Disable the primary identity, revoke active sessions, remove passkeys or tokens where required, and confirm recovery methods no longer point to the departing employee.
Remove supported access to email, chat, cloud storage, developer tools, finance systems, customer platforms and third-party integrations.
Find externally shared documents, protected messages, deal rooms and agreement workflows owned by or shared with the employee. Revoke access that no longer has a valid purpose.
Reassign business-critical files, groups, automations, calendars and signing workflows before deleting or archiving accounts.
Recover managed devices and rotate shared passwords, API keys, certificates or physical access credentials the employee could use.
Review vendors, clients and partners introduced by the employee. Preserve valid relationships while removing obsolete accounts and links.
Record who approved each action, when it completed and any exception that remains. Avoid placing confidential content itself in general-purpose analytics.
Check for failed automation, unexpected sign-ins, orphaned resources and lingering access after the departure window.
Feed exceptions back into role templates, ownership rules and automated lifecycle controls so the next offboarding is faster and more complete.
The organization should define a precise cutoff based on the departure type and risk. In higher-risk cases, coordinate revocation with the formal notification.
Talk through your products, integrations and access requirements with the team.