The Employee Offboarding Checklist: 24 Hours to Prevent a Data Breach
When employees leave, they take access with them. Here's how to revoke everything before they walk out.
A 20-person business typically has an employee logged into 15-25 separate tools by the time they leave
Illustrative figures for a small business — actual tool count depends on your stack size.
The risk in offboarding isn't the employee you're worried about — it's the account nobody remembers exists. A departing salesperson's CRM access gets revoked same-day almost every time; the shared bank-login they were added to eighteen months ago for a one-off vendor payment is the one still active three months later, because nobody owns a master list of every login an employee was ever handed.
Offboarding is a security event that happens to be scheduled by HR — treat the timeline accordingly.
Before the exit conversation
Preparation — do this before the employee is told
- Pull a full access inventory from your identity provider or password manager, not from memory
- Flag anything with financial authority: bank signer rights, payment-processor admin, payroll approval
- Name who inherits each account and client relationship before the transition, not after
- Schedule a specific person to run the revocation checklist on exit day — 'IT will handle it' is how steps get skipped
- Export or back up their email, files, and CRM notes before the account is disabled
Hours 0-2: financial and admin access
Revoke first — highest actual risk
- Bank account signer rights and payment-processor admin logins
- Password manager vault membership (removes cascading access to everything stored there)
- Email account (disable, then forward to their manager for a defined window)
- Any super-admin or owner-level role on core business systems
The bank-signer trap: an employee with signer rights can still initiate a wire the day after they leave if nobody calls the bank. Revoke same-day and get written confirmation from the bank, not just a checked box internally.
Hours 2-8: day-to-day systems
Secondary access — revoke same day
- CRM and customer-communication tools (reassign owned accounts before disabling the user)
- Team chat and video (Slack, Teams) — removing them stops both messaging and file access
- Payroll/HR system access, separate from their own employee record
- Cloud storage and shared drives
- Code repositories and any tool with API keys issued in their name
Where offboarding time actually goes
Hours 8-24: cleanup and hardware
Final steps
- Collect hardware — laptop, phone, badge, keys
- Wipe or reset any personal devices enrolled in mobile device management
- Update the org chart, directory, and any 'who to contact' documentation clients might see
- Notify clients of the account transition with a named point of contact
- Write down what was missed this time — the checklist should get more specific after every offboarding, not stay static
Set a firm end date for email forwarding — 30 days is common. Past that, a live forward to a manager becomes a live account nobody's actively watching.
The bottom line
The tools most likely to get missed aren't the ones IT set up — they're the ones a manager added someone to directly, off the books. A written access inventory, reviewed at least twice a year, is what actually closes that gap, not a faster checklist run on exit day.
Run the free BusinessAdvisor.Guide audit to map how many tools your team currently has standing access to — most owners are surprised by the number.
- Why You Should Audit Your Software Permissions Quarterly
- The SaaS Security Checklist: What to Verify Before Signing Up
- Vendor Risk Assessment: The 50-Point Checklist Before You Sign
- Avoiding Vendor Lock-In: 5 Strategies to Keep Your Data Portable
- How to Prepare for a Software Migration
- Practical decision guide: education and student-data stewardship
