Loading...
hr

Offboarding Access Deprovisioning Coordination Checklist

Use this offboarding access deprovisioning coordination checklist to track account shutdowns, badge returns, device collection, and final verification on an employee’s separation date. It helps HR, IT, and managers close access cleanly without leaving lingering permissions behind.

Get Started

Trusted by frontline teams 15 years of frontline software AI customization in seconds

Built for: Saas · Healthcare · Manufacturing · Financial Services · Professional Services

Overview

This template is a separation-day coordination checklist for removing an employee’s access to systems, data, and physical assets. It is built for the handoff between HR, IT, Security, Facilities, and the manager so account revocation, badge deactivation, device collection, and final confirmation happen in the right order.

Use it when an employee is leaving and access must end at a specific time, especially if the person has email, VPN, shared drive, SaaS, admin, or building access. It is also useful when multiple teams own different parts of the offboarding process and you need one place to track the DRI, blocking dependencies, and verification steps. The checklist format works well for planned resignations, involuntary terminations, contractor end dates, and high-risk exits where privileged access must be removed quickly.

Do not use this template as a generic HR exit interview form or as a broad separation policy document. It is not meant for performance management, benefits administration, or legal settlement workflows. It is also not the right fit if your organization has no system access to revoke or no physical assets to collect. The value here is operational: each checklist item should be independently verifiable, with a clear yes/no/N/A outcome and a final check that confirms no access lingers after termination.

Standards & compliance context

  • This checklist supports access-control and least-privilege practices commonly expected in security and audit programs by documenting timely deprovisioning.
  • It aligns with ITIL-style runbook coordination by assigning ownership, sequencing blocking steps, and recording verification for each action.
  • For regulated environments, it helps show that separation access was removed in a controlled way rather than through informal messaging.
  • If the organization handles protected data, use the checklist to confirm that account closure, device return, and data retention steps follow internal policy and applicable privacy rules.

General regulatory context for orientation only — verify current requirements with counsel or the relevant agency before relying on this template for compliance.

How to use this template

  1. 1. Add the employee’s name, separation date and time, manager, and DRI for HR, IT, Security, and Facilities before the last day begins.
  2. 2. List every access point that must be removed, including identity provider accounts, email, VPN, shared drives, SaaS tools, badges, and any company-issued devices or tokens.
  3. 3. Mark which checklist items are blocking and which are non-blocking so the team knows what must finish before the separation is final.
  4. 4. Assign each checklist item to the team that can verify completion, and require a yes/no/N/A result plus a note when the answer is no.
  5. 5. Run the checklist on the separation date, confirm each revocation or return step, and record the final verification that access has been removed.
  6. 6. Review any exceptions after completion, such as retained legal holds, shared mailbox access, or delayed device returns, and create follow-up tasks for unresolved items.

Best practices

  • Set the exact cutoff time for access removal, not just the calendar date, so IT and managers do not interpret the separation window differently.
  • Separate account revocation from asset collection, because a badge return does not prove system access has been removed.
  • Treat privileged accounts, admin roles, and shared credentials as critical checklist items because they can create immediate security exposure if missed.
  • Use a verification step for every high-risk item, such as confirming the account is disabled in the identity provider rather than assuming the request was sent.
  • Keep checklist items atomic, such as disabling VPN access or collecting a laptop, so each step can be answered clearly and audited later.
  • Flag legal-hold or retention exceptions explicitly so teams do not delete data that must be preserved after the employee leaves.
  • Avoid priority inflation by reserving critical for safety, security, or compliance-impacting items and keeping routine returns as normal priority.

What this template typically catches

Issues teams running this template most often surface in practice:

Email and collaboration access remain active after the employee’s last day because the revocation request was not tied to a cutoff time.
A shared mailbox, delegated inbox, or forwarded account is left open after the employee departs.
VPN, SSO, or admin privileges are removed in one system but remain active in a connected application.
A laptop, badge, token, or other company asset is not returned or is returned without being logged and verified.
The checklist shows a request was made, but no one confirmed the account was actually disabled.
Legal hold or retention requirements are missed, leading to accidental deletion of records that should have been preserved.
Offboarding steps are handled in chat or email threads, so no one can prove who owned each action or when it was completed.

Common use cases

HR Offboarding for a Corporate Employee
HR uses the checklist to coordinate IT account shutdown, manager sign-off, and Facilities badge return on the employee’s final day. It is useful when the separation is planned and multiple teams need a single source of truth.
Security-Led Termination for a Privileged Admin
Security uses the template to ensure admin roles, VPN access, and shared credentials are removed immediately and verified before the termination is finalized. The checklist helps separate blocking security steps from non-blocking admin cleanup.
Remote Contractor End-of-Engagement
A manager and IT team use the checklist to collect a laptop by courier, disable SaaS access, and confirm the contractor no longer has access to internal systems. It works well when physical return and system revocation happen in different places.
Healthcare or Financial Services Separation
A regulated organization uses the checklist to document access removal for systems that contain sensitive records and to confirm any retention or legal-hold exceptions. The template helps create an audit-friendly trail without turning the process into a policy document.

Frequently asked questions

What does this checklist cover?

This template covers the coordination steps needed to remove an employee’s access at offboarding, including identity accounts, SaaS logins, VPN, email, shared drives, badges, and company devices. It is designed to track both the request and the verification step so nothing is assumed complete. It also helps document who owns each action, which is important when HR, IT, Security, and Facilities all have separate tasks.

When should this checklist be used?

Use it for planned resignations, involuntary terminations, retirements, and end-of-contract separations where access must end on a specific date and time. It is especially useful when multiple systems must be disabled in sequence or when physical assets must be returned before the employee leaves. It is not a general onboarding or role-change checklist, because those cases usually require access changes rather than full deprovisioning.

Who should run this checklist?

HR usually initiates the checklist, but IT, Security, Facilities, and the employee’s manager often own the actual checklist items. The best setup assigns a DRI for each action so the checklist does not depend on one person remembering every handoff. If your organization uses a service desk or identity team for deprovisioning, they can own the technical steps while HR coordinates timing.

How often is this checklist used?

This is a recurrence-based operational checklist that is run whenever an employee separates from the company. It is not a daily or weekly recurring task unless your organization processes separations in batches and wants a standard workflow for each case. The key is to trigger it on the separation date or the approved last working day so access removal aligns with policy.

Does this checklist help with compliance requirements?

Yes, it supports common access-control and record-retention expectations by creating a clear trail of who revoked access, when it happened, and what was verified. That matters for security reviews, audit readiness, and separation controls tied to internal policy or external frameworks. It does not replace legal advice, but it does help teams prove that deprovisioning was coordinated instead of handled ad hoc.

What are the most common mistakes when using an offboarding checklist?

The biggest mistake is treating account closure as a single IT task instead of a coordinated sequence that includes badges, devices, shared credentials, and third-party apps. Another common issue is missing the verification step, which leaves teams assuming access was removed when it was only requested. Teams also run into trouble when they do not define the separation timestamp clearly, especially for remote employees or involuntary exits.

Can this template be customized for different employee types?

Yes, you can tailor the checklist for contractors, interns, executives, remote staff, or employees with privileged access. For example, executives may need extra steps for assistants, travel cards, or delegated inboxes, while contractors may only need a narrower set of system removals. Keep the items independently verifiable so each role-specific step still has a clear yes, no, or N/A outcome.

How does this compare with handling offboarding through email or chat?

Email and chat are easy to miss because they do not enforce ownership, timing, or verification. A checklist creates a repeatable workflow with clear task types, priorities, and blocking dependencies so access removal is not buried in a thread. It also gives you a record of completion, which is much harder to reconstruct from informal messages later.

Go deeper on the topic

Related concepts
  • Human resources (HR) — increasingly called people operations, people ops, or simply "people" — is the organizational function responsible for the systems and...
Related guides

Ready to use this template?

Get started with MangoApps and use Offboarding Access Deprovisioning Coordination Checklist with your team — pricing built for small business.

Get Started