IT Process Tracker

IT Offboarding Checklist

The access cutover, in the order it has to run. 39 steps across 4 stages, from discovery at T0 to the residual-access audit at LD+3, each with an SLA, an owner, the system its evidence lands in, and a flag on the 24 that are security-critical.

Free Excel workbook — 47 tasks across 8 phases with owners and status, plus a property recovery log and a contract key-dates worksheet.

The order is the content

Stage C runs C-1 to C-12, in that order, and the sequence is not a convenience. The legal hold goes first because it has to precede any deletion. Sessions and refresh tokens are revoked before the account is disabled, because disabling an account does not end a session already running. Secrets are rotated regardless, because a revoked account does not un-know a password. Reorder those and you have a runbook that looks complete and leaves the door open.

The IT offboarding guide explains why each of these matters. This is the runbook: every step timed off T0 or the last day, with the system its evidence lands in, and the 24 marked Security-critical separated from the 15 that are ordinary housekeeping.

It is the same 39 steps as the — not a summary of it — and the workbook adds the access revocation register, which is the artefact that turns "we revoked everything" into something auditable.

1. Intake & Access Discovery · T0 to T0+2

You cannot revoke what nobody has listed. The first two days are discovery: pull the real access report, find the privileged and standing grants, and name the service accounts and secrets only this person owned — those are the ones that break something silently when the account goes.

  • Open the offboarding ticket from the HR notification Same business day as HR notice Evidence: ITSM ticket IT Service Desk T0
  • Confirm the risk path with HR and set the cutover time Same day — accelerated cases proceed immediately Evidence: ITSM ticket IT Security T0 Security-critical
  • Check for a legal hold before touching any mailbox or drive Before any deletion, wipe or licence release Evidence: eDiscovery / hold register IT Security / Legal T0 Security-critical
  • Run the access discovery report for the identity Within 1 business day; covers SSO and non-SSO apps Evidence: IdP + access review export IAM T0+1 Security-critical
  • Identify privileged and standing access held Within 1 business day — escalates the path if found Evidence: PAM / privilege register IT Security T0+1 Security-critical
  • List sole-owned service accounts, secrets and integrations Within 1 business day — these break silently at cutover Evidence: Secrets manager + CMDB Platform Engineering T0+1 Security-critical
  • Pull the assigned asset list from the register Within 2 business days; reconcile against MDM enrolment Evidence: Asset register + MDM IT Asset Management T0+2
  • Publish the cutover runbook with named owners per system Agreed at least 2 business days before LD Evidence: ITSM ticket IT case owner T0+2

2. Pre-Cutover Preparation · T0+3 to LD-1

Everything that must happen BEFORE the account dies, because most of it cannot happen afterwards. File ownership does not transfer from a disabled account, and a repository with one departing owner is an outage waiting for a merge.

  • Transfer ownership of files, drives and shared documents Before cutover — ownership cannot transfer after disable Evidence: Workspace admin log Collaboration Admin LD-5
  • Reassign sole-owned service accounts and integrations New owner named and tested before LD Evidence: CMDB + secrets manager Platform Engineering LD-5 Security-critical
  • Transfer repository, pipeline and cloud-project ownership No repo or project left with a single departing owner Evidence: SCM + cloud IAM log Platform Engineering LD-5 Security-critical
  • Remove from on-call rotas, escalation trees and alert routing 3 business days before LD Evidence: Paging tool config IT Operations LD-3
  • Agree mailbox disposition with the manager Decided before LD: delegate, forward, convert or archive Evidence: Mail admin log Collaboration Admin LD-3
  • Send the asset-return instructions and prepaid label At least 2 business days before LD for remote leavers Evidence: Asset register IT Asset Management LD-2
  • Stage the mailbox and drive archive; verify it is readable Verified before any deletion is scheduled Evidence: Archive / backup system Collaboration Admin LD-2 Security-critical
  • Dry-run the cutover checklist; confirm every owner is available 1 business day before LD Evidence: ITSM ticket IT case owner LD-1

3. Cutover (run in order) · On LD at time C

Twelve steps, in order, and the order is the point. The legal hold goes first because it has to precede any deletion; sessions and tokens go before the account is disabled, because disabling an account does not end a live session; secrets are rotated because a revoked account does not un-know a password.

  • Apply the legal hold, if one is required First action — before any revocation or wipe Evidence: eDiscovery hold IT Security / Legal C-1 Security-critical
  • Revoke active sessions, refresh tokens and app passwords At C — disabling an account alone does not kill live sessions Evidence: IdP session log IAM C-2 Security-critical
  • Disable the SSO / identity-provider account At C; disable rather than delete, to preserve audit trail Evidence: IdP audit log IAM C-3 Security-critical
  • Remove MFA factors and registered devices At C — prevents self-service re-enrolment Evidence: IdP audit log IAM C-4 Security-critical
  • Revoke non-SSO and privileged access At C: production consoles, databases, PAM, break-glass Evidence: PAM + per-app logs IT Security C-5 Security-critical
  • Rotate every shared secret the leaver could have held Within 24 hours of C; immediately for privileged leavers Evidence: Secrets manager log Platform Engineering C-6 Security-critical
  • Revoke API keys, personal access tokens and SSH keys At C — these survive account disable Evidence: SCM + cloud IAM log Platform Engineering C-7 Security-critical
  • Remove VPN, network and remote-access paths At C: VPN profile, certificates, jump hosts, allowlists Evidence: VPN + firewall log Network Operations C-8 Security-critical
  • Apply the agreed mailbox and chat disposition At C: auto-reply, forwarding, delegation, convert or archive Evidence: Mail admin log Collaboration Admin C-9
  • Terminate MDM enrolment and mark devices for wipe At C for company-owned; selective wipe only on BYOD Evidence: MDM console Endpoint Management C-10 Security-critical
  • Deactivate badge, door and facility access At C, synchronised with the IT cutover Evidence: Access-control system Facilities / Security C-11 Security-critical
  • Confirm cutover complete and log every timestamp Within 1 hour of C; exceptions raised immediately Evidence: ITSM ticket IT case owner C-12 Security-critical

4. Post-Departure & Verification · LD+1 to LD+30

Revocation is a claim until somebody verifies it. This stage is the audit — zero active grants across SSO and non-SSO, rotation confirmed, egress alerts reviewed — plus the licences, which are the largest recoverable cost in the whole process.

  • Collect or confirm shipment of all assigned devices Received or tracked within 1 business day of LD Evidence: Asset register IT Asset Management LD+1
  • Reclaim paid licences and software seats Within 1 business day — largest recoverable cost in offboarding Evidence: Licence management IT Asset Management LD+1
  • Remove from distribution lists, groups and channels Within 1 business day of LD Evidence: Directory + workspace Collaboration Admin LD+1
  • Update the CMDB, directory and org chart Within 1 business day of LD Evidence: CMDB + directory IT Service Desk LD+1
  • Run the residual-access audit across SSO and non-SSO systems Within 3 business days of LD; zero active entries expected Evidence: Access review report IT Security LD+3 Security-critical
  • Verify secret rotation is complete; no old credential works Within 3 business days of LD Evidence: Secrets manager log Platform Engineering LD+3 Security-critical
  • Review pre-departure data-egress alerts Within 3 business days; escalate anomalies to Security and Legal Evidence: DLP / audit log IT Security LD+3 Security-critical
  • Wipe and re-image returned devices, or certify destruction Within 7 business days of receipt; not before the hold clears Evidence: MDM + disposal record Endpoint Management LD+7 Security-critical
  • Decommission integrations and scheduled jobs left behind Within 7 business days; confirm no failing sync or data gap Evidence: Monitoring + CMDB Platform Engineering LD+7
  • Close the ticket with the full evidence pack attached Within 30 days of LD; unresolved items escalated Evidence: ITSM ticket IT case owner LD+30
  • Release the mailbox and drive archive at end of retention Per retention schedule; never while a hold is active Evidence: Archive system Collaboration Admin Per policy Security-critical

Every access path to close

The workbook's revocation register, one row per path, each needing a revoker, a timestamp and a verifier. The target is zero un-revoked rows at LD+3 — and a path is marked N/A rather than deleted, so the register shows what was considered as well as what was closed.

System or app Access type
Identity provider / SSO Primary account
MFA factors & registered devices Authentication
Email & calendar Mailbox
Chat / collaboration Workspace
File storage & shared drives Data
VPN / remote access Network
Jump hosts & bastion Network
Cloud console — production Privileged
Cloud console — non-production Standard
Source control Privileged
CI/CD pipelines Privileged
Databases Privileged
PAM / break-glass accounts Privileged
API keys & personal access tokens Credential
SSH keys Credential
Secrets manager Credential
Monitoring & paging Standard
ITSM / service desk Standard
HRIS / finance systems Sensitive
Non-SSO SaaS apps Standard
Third-party / customer systems External
Badge & facility access Physical
MDM enrolment Endpoint

Next

General IT process guidance, not legal advice. Never wipe a device or release an archive while a legal hold is in place, and take advice before a selective wipe on a personal device — retention duties and what may be done to employee-owned hardware vary by state and by policy.

Free template

IT Offboarding Process Tracker

The working runbook: 39 steps across 4 stages, each with its timing, SLA, responsible team and evidence system, plus Timestamp and Verified-by columns so the cutover is auditable after the fact.

Two more tabs come with it — an access revocation register covering 24 access paths, and a device and licence recovery log that tracks wipe and seat reclaim separately, because a returned laptop is not a closed ticket.

Ready to Let AI Run Your HR?

Join 500+ US companies that replaced HR busywork with AI agents. Sign up and start in minutes.

Get Started