Employee OffboardingChecklist for IT

A phase-by-phase IT offboarding checklist covering access revocation, device recovery, data custody, and the audit evidence your assessor will ask for. Built by Petronella Technology Group for defense contractors, medical practices, and regulated firms in Raleigh and nationwide.

CyberAB RPO #1449/BBB A+ Since 2003/Serving Raleigh Since 2002

Key Takeaways

  • An employee offboarding checklist is the written sequence of IT and security tasks that removes a departing worker's access, recovers company assets, and preserves their data before the account is closed.
  • The single most common failure is not forgetting the checklist - it is running it too slowly. Identity revocation belongs in the first hour, not the first week.
  • Offboarding is an explicit control requirement under CMMC and NIST SP 800-171 (3.9.2), HIPAA workforce security, SOC 2, and PCI DSS. An undocumented offboarding is a finding even when the access was actually removed.
  • Most missed items sit outside the identity provider: shared credentials, SaaS accounts bought on a personal card, API keys, MFA tokens, and physical or vendor-portal access.
  • Petronella Technology Group runs offboarding as a security event with recorded evidence, backed by a Registered Provider Organization team and ComplianceArmor® documentation.

What Is an Employee Offboarding Checklist?

An employee offboarding checklist is a written, repeatable sequence of IT and security tasks performed when someone leaves an organization. It revokes every form of access that person held, recovers company-owned devices and data, transfers ownership of files and mailboxes to a named successor, and records evidence that each step happened. It is the mirror image of onboarding, and it carries far more risk.

Onboarding failures are visible within hours. A new hire without a mailbox raises their hand. Offboarding failures are silent by design: nobody complains that a departed employee's VPN certificate still works, that their personal phone still holds an active session token, or that the file-share account they used for six years was renamed instead of disabled. The gap can persist for years and is usually discovered in one of two ways - during an assessment, or during an incident.

In our 24 years since 2002, the offboarding cases that turned into real incidents almost never involved a sophisticated attack. They involved an ordinary account that should have been closed on a Friday and was still live the following spring.

Why IT Offboarding Fails

Four structural gaps account for most of what we find when we audit a client's departure process.

1. HR and IT are on different clocks

HR closes out payroll and benefits on their own timeline. If the notification to IT is a forwarded email rather than a triggered workflow, revocation happens whenever someone opens that inbox. For an involuntary termination, that lag is the entire risk window.

2. The identity provider is treated as the whole map

Disabling the Microsoft 365 or Google Workspace account feels like completion, and for federated applications it largely is. But the accounts that matter most in a breach are frequently the ones that never federated: a local administrator account on a server, an FTP login, a router credential, a SaaS tool with its own password store, a personal access token in a code repository.

3. Nobody owns the data question

Deleting a mailbox destroys evidence. Leaving it open indefinitely creates an unowned, unmonitored account. Neither is a decision anyone wants to make at 4:45 on a Friday, so the account is left in place "for now" and quietly becomes permanent.

4. There is no artifact

Access may genuinely have been removed, but if no ticket, timestamp, or signed attestation exists, the organization cannot demonstrate it. Under CMMC and NIST SP 800-171, the ability to demonstrate the control is the control.

Ad Hoc Offboarding vs a Controlled Process

DimensionAd Hoc OffboardingControlled Offboarding
TriggerEmail or hallway conversationHR system event with a defined service-level target
Revocation timingWhenever IT gets to itIdentity disabled within the first hour of separation
ScopeWhatever the technician remembersDriven by the access inventory for that specific person
Shared credentialsLeft unchangedRotated, with the rotation recorded
DevicesCollected if convenientTracked as assets, wiped, and reissued or retired
DataMailbox left open indefinitelyOwnership transferred to a named successor, retention applied
EvidenceNoneTimestamped record per task, signed closeout
Assessment outcomeFinding, even if access was removedDemonstrable control

The difference between the two columns is rarely technical skill. It is whether the sequence exists in writing and whether someone is accountable for closing it out. That is also why offboarding is one of the first things we formalize when a client moves onto managed IT services with us.

Not sure who still has access?

Petronella Technology Group can run a user access review against your current environment and show you exactly which departed-employee accounts, tokens, and shared credentials are still live. Serving Raleigh, Durham, and the Triangle since 2002, plus clients nationwide.

Schedule a Free Consultation

The Employee Offboarding Checklist

The checklist below is organized by phase rather than by system, because the ordering is what protects you. Phase 2 is time-critical. Everything after it can be completed over the following days without materially increasing risk, provided Phase 2 was done correctly.

Phase 1: Pre-Departure Planning

Run before the last day / 8 tasks
  1. Confirm the exact separation date, time, and whether the departure is voluntary or involuntary. The two paths differ in sequencing, not in scope.
  2. Pull the person's full access inventory from your identity provider, privileged access records, and IT asset inventory - not from memory.
  3. Identify every system where the person is the sole administrator, licence holder, billing contact, or domain owner, and assign a successor for each.
  4. Name the data custodian who will inherit the mailbox, home directory, and any project shares.
  5. Flag any group mailboxes, distribution lists, or on-call rotations that include the person.
  6. Check whether the person holds keys, badges, alarm codes, or a company vehicle fob.
  7. Note any client-facing accounts, vendor portals, or partner systems where the person is your registered contact.
  8. For an involuntary departure, prepare every revocation script in advance so Phase 2 executes in minutes, and coordinate the timing with HR and the manager.

Phase 2: Hour Zero - Identity and Access Revocation

Time-critical / 9 tasks
  1. Disable the primary directory account. Disable, do not delete - deletion destroys the audit trail and often the licensed data with it.
  2. Revoke active sessions and refresh tokens explicitly. A disabled account with a live token can continue working for hours in some cloud applications.
  3. Reset the account password to a value nobody knows, so the account cannot be re-enabled into a usable state by mistake.
  4. Remove registered MFA methods, including the authenticator app, hardware token, and any SMS or voice fallback number.
  5. Revoke VPN access and, where certificates are used, revoke the certificate rather than only removing group membership.
  6. Disable remote access paths that bypass the identity provider: RDP gateways, jump hosts, remote support tools, and any standing firewall rules tied to the person.
  7. Remove the account from privileged groups first, then from standard groups, so an interrupted process fails in the safe direction.
  8. Suspend or disable single sign-on application assignments and check for applications with local accounts that shadow the SSO identity.
  9. Record the timestamp of each revocation. This is the evidence an assessor will ask for.

Phase 3: Endpoint and Device Recovery

Within 24 to 72 hours / 8 tasks
  1. Recover every company-owned device on the person's asset record: laptop, desktop, phone, tablet, external drives, and dongles or security keys.
  2. For unrecovered devices, issue a remote wipe or selective wipe through your mobile device management platform and record the result.
  3. On personally owned devices under a bring-your-own-device policy, remove the company work profile, mail profile, and any managed applications.
  4. Preserve a forensic image of the primary workstation before wiping if the departure is contentious, involves suspected policy violation, or touches litigation. Craig Petronella is an NC Licensed Digital Forensics Examiner (DFE #604180) and this step becomes very difficult to reverse once skipped.
  5. Verify full-disk encryption status and recover the escrowed recovery key before reimaging.
  6. Update the device's status in IT asset management so the hardware is either staged for reissue or formally retired.
  7. Collect and account for hardware MFA tokens and smart cards. Mark them as returned or lost, and revoke lost tokens.
  8. Return or securely destroy removable media the person used, following your media handling policy.

Phase 4: Email, Files, and Data Custody

Within the first week / 8 tasks
  1. Convert the mailbox to a shared or inactive mailbox rather than deleting it, and apply your retention policy to it.
  2. Place a litigation or retention hold if the departure has any legal dimension, before any cleanup activity begins.
  3. Set up mail forwarding or an auto-reply that names a live successor, with an explicit end date so it does not run forever.
  4. Transfer ownership of the person's cloud drive, home directory, and any files where they were the only owner.
  5. Reassign ownership of shared documents, calendars, and forms - orphaned ownership becomes an access problem the first time permissions need changing.
  6. Review anything the person classified or handled under your data classification policy, particularly controlled unclassified information or protected health information.
  7. Check for company data in personal cloud storage or personal email, and address it through the exit agreement rather than technically.
  8. Record what was retained, what was transferred, and to whom. This becomes the data custody artifact for the file.

Phase 5: SaaS, Shadow IT, and Third-Party Accounts

Within the first week / 8 tasks
  1. Work through the full application inventory, not only the applications behind single sign-on.
  2. Identify subscriptions the person purchased directly, including anything expensed to a personal card and reimbursed - these are invisible to the identity provider.
  3. Transfer administrator and billing-owner roles in every SaaS platform where the person held them, before removing their account.
  4. Revoke third-party OAuth grants the person authorized against company data.
  5. Remove the person from client portals, vendor portals, and partner systems where you are the account holder, and notify those counterparties where required. Track this alongside your IT vendor management records.
  6. Remove them from code repositories, CI/CD systems, and package registries, and revoke deploy keys.
  7. Remove access to any AI tools, assistants, or model endpoints, including tools adopted without approval.
  8. Remove them from marketing, social, review, and domain registrar accounts. Domain and DNS ownership is the item most often discovered years later.

Phase 6: Privileged, Shared, and Machine Credentials

Within 72 hours / 8 tasks
  1. Rotate every shared or generic credential the person knew. Disabling their named account does nothing about a password they can still type.
  2. Rotate local administrator passwords on systems where a standing shared password was in use.
  3. Rotate service account and application account passwords the person had access to, coordinating with the application owners.
  4. Revoke API keys, personal access tokens, and webhook secrets issued to or created by the person.
  5. Revoke SSH keys, and check authorized-keys files on servers rather than trusting a central list.
  6. Rotate infrastructure credentials the person held: firewall, switch, wireless controller, hypervisor, backup console, and out-of-band management.
  7. Change shared vault or password-manager master credentials where the person had access, and remove them from all shared vaults.
  8. Rotate any credential stored in a document, script, or configuration file the person could reach. Record each rotation with a timestamp.

Phase 7: Physical, Facility, and Contact Access

Within 24 hours / 7 tasks
  1. Deactivate badge and door-access credentials, and confirm the deactivation in the access control system rather than assuming it propagated.
  2. Collect physical keys and change locks where a key was not returned.
  3. Change alarm codes and remove the person from the alarm company's authorized caller list.
  4. Remove the person from the authorized contact list at your internet provider, telephone provider, bank, and any vendor that will act on a phone request.
  5. Remove them from data center or colocation access lists.
  6. Forward or reassign the desk phone extension and any direct-dial number, and remove them from the phone system directory.
  7. Remove them from the public website, staff directory, and email signature templates.

Phase 8: Evidence, Attestation, and Closeout

Within two weeks / 8 tasks
  1. Compile the timestamped record of every revocation, rotation, and device action into a single offboarding record for the person.
  2. Capture a signed acknowledgment from the departing employee covering returned property and continuing confidentiality obligations.
  3. Have the manager or system owner attest that successor assignments are complete and functioning.
  4. Reconcile the asset record: every device on the person's record is either returned, wiped, or formally written off with a reason.
  5. Run a verification pass against the identity provider, privileged access records, and application inventory to confirm no residual access remains.
  6. Reclaim and reallocate licences so you are not paying for a departed worker.
  7. Review whether the departure exposed a control weakness worth fixing before the next one, and document the finding.
  8. File the completed record where an assessor can retrieve it. ComplianceArmor® stores this alongside the rest of your control evidence so it is not sitting in an individual technician's ticket queue.

Offboarding Timing: What Must Happen When

Not every task carries the same urgency. The table below is the sequencing we apply for client engagements, and it is the part most internal checklists leave out.

WindowTasksWhy This Window
Before the last dayAccess inventory, successor assignment, script preparationPreparation is the only thing that makes hour-zero revocation fast enough to matter
Hour 0 to 1Directory disable, session and token revocation, MFA removal, VPN and remote accessThis is the live risk window. Everything here is reachable from outside your building
Hour 1 to 24Badge and facility access, alarm codes, authorized-caller lists, phone systemPhysical and social-engineering paths that survive a disabled account
Day 1 to 3Shared credential rotation, privileged and service accounts, API keys, SSH keysKnowledge-based access the person retains regardless of account status
Day 1 to 7Device recovery and wipe, mailbox conversion, data custody transfer, SaaS cleanupImportant but lower urgency once identity and shared credentials are closed
Week 2Verification pass, attestation, licence reclamation, evidence filingTurns a completed task list into a demonstrable control

The Items Organizations Miss Most

These are drawn from what we actually find during access reviews at new client engagements, ordered roughly by how often they show up.

Missed ItemWhy It Gets MissedRisk If Left Open
Shared and generic passwordsNo named account to disable, so nothing appears on the listFull retained access with no attribution in the logs
Active session tokensDisabling the account looks like it ended the sessionContinued cloud application access after revocation
SaaS bought on a personal cardNever entered the application inventoryCompany data in an account nobody controls
API keys and personal access tokensCreated by the user, not issued by ITProgrammatic access that survives every identity change
SSH authorized-keys entriesStored on the server, not in a central directoryDirect server access bypassing the identity provider
Domain registrar and DNSRarely touched, often registered by one person years earlierLoss of domain control, mail interception potential
Vendor authorized-caller listsNot a system, so not on any technical checklistThird parties acting on instructions from a former employee
Sole-administrator applicationsOnly discovered when someone needs a change madeLocked-out platform, sometimes requiring vendor escalation to recover
Personal device work profilesAssumed removed when the person leftCompany mail and files retained on a device you do not control

How Offboarding Maps to Compliance Frameworks

Offboarding is not a best practice you can defer. It is a named requirement in every framework our clients operate under, and the requirement is almost always phrased in terms of timeliness and evidence rather than mechanism.

FrameworkRequirementWhat Assessors Look For
CMMC 2.0 and NIST SP 800-171Protect controlled unclassified information during and after personnel actions such as terminations and transfersA documented procedure plus records showing it ran, per departure. See CMMC 3.9.2
HIPAA Security RuleTermination procedures under workforce security, with access terminated when employment endsWritten termination procedures and evidence of timely revocation. See HIPAA workforce security
SOC 2Access is removed on a timely basis when no longer requiredPopulation testing: a sample of terminations checked against revocation timestamps
PCI DSSAccess for terminated users is immediately revokedRevocation records for cardholder data environment accounts, including shared credential rotation
FTC Safeguards RulePeriodic review and adjustment of access controls, including on personnel changeDocumented access reviews and change records
ISO 27001Termination or change of employment responsibilities, and return of assetsAsset return records and access removal evidence

The recurring theme across all six is that the artifact is the deliverable. If your team removed the access perfectly but recorded nothing, the assessment result is the same as if you had done nothing. For defense contractors specifically, this is one of the practices where a self-assessment score and a C3PAO result diverge most often - the control is present in practice but not in evidence. Craig Petronella, CMMC Registered Practitioner and author of the CMMC 2.0 Certification Guide, covers the same distinction across the 110 NIST SP 800-171 controls.

"Craig takes the time to understand our business model, not just our technology stack. It makes his recommendations more strategic and tailored to our actual goals."

Daniel Lee, TrustIndex verified review

Petronella Technology Group is rated 4.7 across 92 verified TrustIndex reviews and 5.0 across 15 Google reviews.

Voluntary vs Involuntary Departures

The task list is the same. The sequencing and the tolerance for delay are not.

Voluntary resignation with notice

You have the luxury of preparation. Use the notice period for knowledge transfer, successor assignment, and documentation of anything only that person knows. Revocation still happens at the separation time, not gradually across the notice period - partial access removal during a notice period tends to create confusion without reducing risk.

Involuntary termination

Revocation is synchronized with the conversation itself. Scripts are staged in advance, the technician executing them knows the exact time, and physical access is deactivated in the same window. This is the scenario where every minute of lag is a real exposure, and it is the scenario an unprepared process handles worst.

Internal transfer

Frequently skipped entirely, and it accumulates. Someone who moves from finance to operations should lose finance access, not simply gain operations access. Accumulated permissions across a long internal career are one of the most common findings in a user access review, and they are much harder to unwind years later than at the moment of transfer.

Contractor and temporary staff

Contractors often sit outside the HR system that triggers offboarding, so their access ends when someone remembers rather than when the engagement does. Set an expiration date on the account at creation so the default outcome is closure rather than persistence.

Get the offboarding process documented properly

Petronella Technology Group builds the written procedure, the evidence template, and the verification pass your assessor expects - then runs it with you for the first few departures. Ask about IT support for small business and security-led managed services.

Get a Free Assessment

Running It Yourself vs Running It With Petronella

Typical Internal Process

Triggered by an email

IT learns about the departure whenever someone forwards the note, so revocation timing is unpredictable.

Scoped from memory

The technician disables what they know about. Shared credentials, tokens, and unmanaged SaaS stay untouched.

No evidence produced

Work happens in a ticket with no timestamps per task, so the control cannot be demonstrated at assessment time.

Never verified

Nobody checks afterward whether residual access remains, so gaps surface during an audit or an incident.

With Petronella Technology Group

Triggered by a defined event

Separation notice starts a workflow with a service-level target for identity revocation, staged in advance for involuntary cases.

Scoped from an inventory

Revocation is driven by that person's actual access record across identity, privileged, SaaS, and physical systems.

Evidence by default

Each task produces a timestamped record, filed in ComplianceArmor® against the relevant control.

Verified and closed out

A verification pass confirms no residual access, followed by manager attestation and licence reclamation.

How We Implement Offboarding for a New Client

1

Discover what access actually exists

We inventory identity, privileged accounts, SaaS applications, shared credentials, and physical access. Most clients find applications and accounts they did not know were in use.

2

Close the historical backlog

Before changing the process, we clear the accumulated residue: still-active accounts from past departures, orphaned tokens, and un-rotated shared credentials.

3

Write the procedure

The phase structure above, adapted to your systems, with named owners and time windows. Written so a technician who has never done it can execute it correctly.

4

Build the evidence template

A per-departure record mapped to the specific controls in your framework, so the artifact is produced as a by-product of the work rather than reconstructed later.

5

Run it together

We execute the first departures with your team, then hand over. Involuntary terminations are rehearsed before they are needed.

6

Review on a schedule

Quarterly access reviews catch what the process missed and confirm that offboarding is holding. This is also where internal transfers get reconciled.

Offboarding sits alongside the other controls we manage: IT help desk services for the day-to-day request handling, security awareness training so the workforce understands why credentials are not shared in the first place, and ongoing access governance. Petronella Technology Group serves Raleigh and the Triangle as well as clients nationwide.

Frequently Asked Questions

How quickly should employee access be revoked after termination?

Identity revocation should happen within the first hour of separation, and for an involuntary termination it should be synchronized with the termination conversation itself. Frameworks including PCI DSS use the word "immediately," while SOC 2 and HIPAA use "timely" without a fixed number. In practice, assessors evaluate the gap between the separation timestamp and the revocation timestamp, which is why recording both matters as much as acting quickly.

Should we delete a departing employee's account or just disable it?

Disable it. Deleting the account destroys the audit trail, often removes the associated mailbox and files, and in some platforms cannot be reversed after a grace period. Disable the account, revoke its sessions and MFA methods, reset the password to an unknown value, then convert the mailbox to a shared or inactive mailbox under your retention policy. Delete only after the retention period expires and no legal hold applies.

What is the difference between offboarding and a user access review?

Offboarding is event-driven and applies to one person at the moment they leave. A user access review is periodic and applies to everyone, catching what offboarding missed as well as permission accumulation from internal transfers. Both are required by most frameworks. Running access reviews without an offboarding process means you find stale access months late; running offboarding without access reviews means nothing ever verifies that it worked.

Do we need to change shared passwords when someone leaves?

Yes, and it is the single most commonly skipped step. Disabling a named account does nothing about a password the person memorized. Any shared or generic credential the departing person knew should be rotated within 72 hours, including local administrator passwords, service accounts, infrastructure device credentials, and shared vault access. Record each rotation with a timestamp. The better long-term fix is eliminating shared credentials so the question stops arising.

What happens to company data on a personal phone or laptop?

If the device is enrolled in mobile device management under a bring-your-own-device policy, issue a selective wipe that removes the company work profile, mail profile, and managed applications while leaving personal data intact. If the device was never enrolled, you have no technical remedy, which is why the enrollment requirement belongs in the policy the employee signs at hire. Address residual copies through the exit agreement and confidentiality acknowledgment.

Is an offboarding checklist required for CMMC compliance?

Effectively yes. CMMC 2.0 and NIST SP 800-171 require protecting controlled unclassified information during personnel actions including terminations and transfers. Assessors expect a documented procedure plus per-departure records demonstrating it ran. A team that removes access correctly but keeps no records will still receive a finding, because under CMMC the ability to demonstrate the control is the control.

How do we handle offboarding for contractors and temporary staff?

Set an expiration date on the account when it is created, so the default outcome is closure rather than indefinite persistence. Contractors typically sit outside the HR system that triggers employee offboarding, so their access tends to outlive the engagement. Apply the same phase structure, and pay particular attention to third-party portals and any credentials the contractor created rather than received.

Who should own the offboarding process, HR or IT?

HR owns the trigger and the employment-side tasks. IT owns execution of the technical revocation and the evidence. The failure mode is treating the handoff as informal - a forwarded email rather than a defined event with a service-level target. Assign one accountable owner for closeout who confirms every phase completed, because in practice the tasks that get dropped are the ones sitting between the two departments.

Talk to a Registered Provider Organization

Petronella Technology Group has been securing regulated businesses from Raleigh since 2002, as a CyberAB Registered Provider Organization (RPO #1449) with a BBB A+ rating since 2003. We can review your offboarding process, close the historical backlog, and produce the evidence your framework requires.

Schedule a Free Consultation Call 919-348-4912

Last Updated: August 27, 2026 | Petronella Technology Group, Inc. | 5540 Centerview Dr., Suite 200, Raleigh, NC 27606 | 919-348-4912