The order is enforced
The cut-off task halts the checklist, so no account, key or licence step can be ticked before sign-in is blocked. A second halt holds the wipe and the licence until the manager confirms the handover.
This free IT offboarding checklist is the IT team’s side of every leaver, run with HR and the line manager. It confirms the last day and leaver type, cuts single sign-on and email at a set time, closes accounts, rotates the secrets the person could see, moves their data, wipes their devices, reclaims licences and ends with a final access review. Due dates count from the last working day, and an involuntary exit gets a cut-off task only the IT owner can open.
A departure touches three teams, and each needs a list it can finish. HR owns the person, IT owns the access and the equipment, and dozens of apps sit in between. One HR form gives IT a single line saying “remove access”, which is how a dismissed employee keeps a working VPN profile for a week.
Covers: notice, final pay, knowledge handover, the exit interview and team communication.
Owner: HR, with the manager.
IT’s part: one phase that hands off to a technical checklist.
Covers: identity and email cut-off, accounts, secrets, data, devices, licences, groups and the on-call rota.
Owner: IT, triggered by HR, with the manager confirming the handover.
Done when: a final access review finds nothing active and the approver signs off.
Covers: every app the leaver used, including shadow IT, OAuth grants and personal tokens.
Owner: IT or the SaaS owner, with each app admin.
Used when: the app estate is too big for one task row.
Pay and the exit interview stay in the Employee Offboarding Checklist, and apps outside single sign-on go to the SaaS Access Offboarding Checklist. Remote leavers add courier returns and time zones, covered by the Remote Employee Offboarding Checklist. Someone changing roles needs the Internal Transfer & Role Change Checklist, because their access changes rather than ends.
Seven phases run once per leaver, in the order that keeps access closed. The leaver type picks the cut-off task, scope answers add privileged-access and legal-hold tasks, and the checklist halts at the cut-off, the handover decision and the sign-off.
The people picked on the first task are assigned the later tasks. An involuntary exit hides the file request, so nothing tips the leaver off.
The first task appears only for an involuntary exit: assigned exclusively to the IT owner, due at the cut-off minute, and halting the checklist. Other leavers get the scheduled block in the second task, which also halts.
The guest-account task appears only for a contractor.
The last three tasks appear only when the leaver held admin or privileged access.
The hold task appears only under a legal hold or investigation. The checklist halts at the manager’s Approved or Not approved decision, so no device is wiped and no licence released before the handover is confirmed.
A legal hold shows the preserve task instead of the wipe. The own-device task is for contractors only.
The sign-off approver records Approved or Not approved on the last task, with the evidence attached.
The steps barely change between leavers. Their timing does. A resignation gives IT weeks; a dismissal gives minutes; a contractor often leaves on a date nobody told IT about.
| Step | Voluntary | Involuntary | Contractor |
|---|---|---|---|
| Checklist starts | When notice is accepted | When HR books the meeting, before the leaver knows | When the end date is confirmed with the engagement owner |
| Access cut-off | End of the last working day | During the meeting, at a set minute | The contract end date and time |
| Files handed over | By the leaver, during notice | By the manager and IT, after the cut-off | As the contract’s handover terms require |
| Devices | Handed in on the last day | Collected in the meeting | Company kit returned; own kit confirmed clean in writing |
| Accounts | Member account disabled | Member account disabled at once | Guest or vendor account removed, sponsor link ended |
| Who can act on the cut-off | The IT owner | The IT owner only, by exclusive assignment | The IT owner |
NIST SP 800-53 control PS-4, Personnel Termination, asks organisations to disable system access within a period they define, revoke the leaver’s authenticators and credentials, retrieve security-related property and keep access to the information the person controlled. ISO/IEC 27001:2022 covers the same ground in Annex A controls 5.11 (return of assets), 5.18 (access rights) and 6.5 (responsibilities after termination or change of employment). Either way, an auditor wants evidence that each leaver’s access ended when your policy said it would.
In Microsoft Entra ID, access tokens already issued last an hour by default after the account is disabled, so sessions are revoked straight after the block and the logs checked next morning. And a Microsoft 365 mailbox needs its licence while it is converted to a shared mailbox, so licences are reclaimed in Phase 7, not on the last day.
The cut-off task halts the checklist, so no account, key or licence step can be ticked before sign-in is blocked. A second halt holds the wipe and the licence until the manager confirms the handover.
For an involuntary exit, the cut-off task is assigned exclusively to the IT owner picked in Phase 1. Only its assignees can open or complete it, others on the checklist see it greyed out, and a Guest sees only their own tasks, so a sensitive step stays with the people doing it.
Dynamic due dates run from the last working day and cut-off time entered in Phase 1. Conditional logic adds contractor, privileged-access and legal-hold tasks only when they apply, and the activity trail records who did each step.
See how CheckFlow’s IT offboarding checklist software coordinates IT, HR and the manager, and read the IT offboarding security guide for the reasoning behind each step. A webhook or Zapier trigger from your HR system can start this checklist the moment a leaver is confirmed.
The quarterly User Access Review Checklist and the Active Directory & Entra ID Account Cleanup Checklist find what slipped through, and devices that will not be reissued continue to the IT Asset Disposal Checklist.
The leaver’s type and last day, the identity and email cut-off, accounts in each tool, shared secrets and API keys, data and mailbox handover, device wiping, licences, groups and the on-call rota, and a final access review with a sign-off. Each step needs an owner and a due date counted from the last working day.
For a resignation, at an agreed time at the end of the last working day. For a dismissal, during the meeting, at a minute agreed with HR beforehand, so nothing can be copied after the news. For a contractor, at the contract end date and time. Revoke sessions straight after the block.
Block sign-in and revoke sessions, close accounts in each tool, then rotate the secrets the person could see. Transfer data and convert the mailbox before anything is wiped, wipe devices once the handover is confirmed, and reclaim licences last. A final access review two weeks later catches what was missed.
Disable first and delete later. Deleting too early can take files, calendars and mail with it, and in Microsoft 365 a converted shared mailbox needs the original account as its anchor. Delete once the data is transferred and the retention period has passed. Note that Google Workspace still charges for a suspended user.
Usually it becomes a shared mailbox the manager can open, or new mail is forwarded to a successor, with an automatic reply naming the new contact. In Microsoft 365, convert while the licence is still assigned; under 50 GB the shared mailbox then needs none. Under a legal hold, place the hold first.
All three. HR confirms the leaver, the type and the last day. IT runs the cut-off, accounts, secrets, devices and licences. The line manager hands over on-call shifts, says which files matter and confirms the handover before anything is wiped. A named approver signs off.
14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.