Loading...
hr

Offboarding Access Deprovisioning Coordination Checklist

Coordinate employee offboarding access removal with IT, HR, and facilities using a checklist that tracks accounts, badges, devices, and final verification on the separation date.

Get Started

Trusted by frontline teams 15 years of frontline software AI customization in seconds

Built for: Saas · Healthcare · Manufacturing · Financial Services · Professional Services

Overview

This template is a coordination checklist for removing a departing employee's access to systems, data, and physical assets. It is built for the handoff between HR, IT, security, and facilities so the separation date does not create an access gap, a missed badge return, or a lingering account that should have been disabled.

Use it when an employee resigns, is terminated, or reaches the end of a contract and multiple owners must act in a specific order. The checklist helps you track account disablement, MFA reset, VPN and SSO access, shared mailbox access, device return, badge collection, and final verification. It is especially useful when some steps are blocking, such as removing privileged access before the employee leaves, while others are non-blocking, such as collecting a laptop after deprovisioning is confirmed.

Do not use it as a generic HR exit interview form or as a policy document. It is also not the right tool for simple role changes where access is being adjusted but employment is continuing, unless you need a formal deprovisioning pass for elevated permissions. The value of the template is in making each checklist item independently verifiable, assigning a DRI, and confirming that the revocation actually happened rather than assuming an email request was enough.

Standards & compliance context

  • This template supports least-privilege access removal by documenting timely deprovisioning after employment ends.
  • It helps create an audit trail for internal controls by recording who removed access, when it happened, and how it was verified.
  • If your organization handles regulated data, use the checklist to confirm that access to sensitive systems is removed according to your retention and offboarding rules.
  • Where badge access, device return, or mailbox retention is governed by policy, record the policy exception or approval directly in the task.

General regulatory context for orientation only — verify current requirements with counsel or the relevant agency before relying on this template for compliance.

How to use this template

  1. Create the checklist as soon as HR confirms the separation date and enter the employee name, last day, and any special access risks that change the order of work.
  2. Assign each checklist item to a DRI in IT, security, HR, or facilities, and mark which steps are blocking versus non-blocking so the team knows what must finish before departure.
  3. Complete the access revocation steps in the identity provider, email, VPN, SaaS apps, shared drives, badge system, and device management tools, then record the verification step for each one.
  4. Collect physical assets such as laptops, tokens, and badges, and log any exceptions like remote shipping, missing equipment, or delayed returns as separate follow-up tasks.
  5. Review the checklist at the end of the offboarding window, confirm all critical items are closed, and escalate any open access or missing asset issues immediately.

Best practices

  • Keep each checklist item atomic so one owner can answer yes, no, or N/A without interpretation.
  • Mark only safety, privacy, or access-control failures as critical; do not inflate priority on routine admin steps.
  • Treat privileged accounts, shared credentials, and admin consoles as blocking items that must be verified before the separation is complete.
  • Use a separate verification step for every system where possible, because a request to disable access is not proof that access is gone.
  • Include remote-return instructions for laptops, badges, and hardware tokens when the employee does not work on-site.
  • Document exceptions such as legal holds, mailbox retention, or manager-approved access extensions in the checklist rather than in chat threads.
  • Review the checklist against your HRIS, identity provider, and asset inventory so no system is left out of the offboarding path.

What this template typically catches

Issues teams running this template most often surface in practice:

A SaaS account remains active because the disable request was sent but never verified.
Badge access is removed, but VPN or SSO access is still open.
A shared mailbox or delegated inbox is forgotten during the offboarding sequence.
The laptop is returned late or not at all, leaving local data exposure unresolved.
Privileged admin access is left in place because the employee had multiple roles or temporary elevation.
Facilities and IT each assume the other team collected the badge or token.
The checklist closes before the final verification step confirms all access paths are disabled.

Common use cases

SaaS company HR offboarding
A people ops team coordinates with IT to remove access to Google Workspace, Slack, CRM, and password manager accounts on the employee's last day. The checklist keeps the process visible across teams and prevents a missed admin console or shared drive permission.
Healthcare clinic separation workflow
A clinic uses the checklist to remove access to scheduling, EHR, badge readers, and shared workstations when a staff member leaves. The verification step matters because patient data access must be removed cleanly and documented.
Manufacturing plant badge and device return
An operations manager uses the template to coordinate badge collection, laptop recovery, and system lockout for a plant employee. The checklist helps facilities and IT avoid gaps when the employee has both physical and digital access.
Finance team privileged access shutdown
A financial services firm uses the checklist for employees with elevated permissions in treasury, reporting, or admin tools. Blocking steps ensure privileged access is removed before the separation is finalized, with clear ownership for each control.

Frequently asked questions

What does this offboarding checklist cover?

It covers the coordination steps needed to remove an employee's access at separation, including identity systems, email, SaaS apps, VPN, badges, shared credentials, and company devices. It is meant to track who owns each action, when it must happen, and whether verification is complete. Use it as the control point for the offboarding process, not as the HR termination notice itself.

When should this checklist be run?

Run it before the separation date to prepare access changes, then complete the critical revocation steps on the employee's last day or at the agreed cutoff time. For involuntary separations, the checklist should be treated as time-sensitive and blocking until the highest-risk access is removed. For planned departures, it can also be used to stage device return and mailbox handoff in advance.

Who should own this checklist?

HR usually initiates the offboarding task, but IT or security should own the access revocation work, and facilities or office management may own badge and asset collection. The checklist works best when each checklist item has a clear DRI and a verification step. If your process spans multiple teams, assign one coordinator to confirm nothing is left open.

Is this checklist relevant for compliance or audits?

Yes, because it creates a documented trail showing that access removal was requested, completed, and verified. That matters for internal controls, privacy obligations, and audit readiness when you need to prove timely deprovisioning. It also helps reduce the risk of lingering access after employment ends, which is a common control failure.

What are the most common mistakes when using this template?

The biggest mistake is treating offboarding as a single IT ticket instead of a coordinated checklist with separate owners and verification. Another common issue is forgetting non-obvious access such as shared drives, password managers, badge systems, or third-party vendor portals. Teams also sometimes close the task before confirming the account is actually disabled and the device return is logged.

Can this checklist be customized for different employee types?

Yes. You can add or remove checklist items for contractors, executives, remote workers, field staff, or employees with privileged access. For example, executives may need extra device recovery steps, while contractors may only need SaaS and badge removal. Keep the checklist item wording atomic so each step can be answered yes, no, or N/A.

How does this compare with handling offboarding through ad-hoc emails or chat messages?

Ad-hoc coordination is easy to miss because requests get buried, owners are unclear, and no one can see what is still blocking completion. This checklist gives you a repeatable sequence, explicit ownership, and a final verification step so access removal is not assumed. It is especially useful when multiple systems and teams must act on the same separation date.

Can this template connect to other systems or workflows?

Yes, it can be paired with HRIS triggers, IT service desk tickets, badge management, device inventory, and identity provider workflows. Many teams use it as the human coordination layer while automations handle the actual account disablement. That combination helps keep the process visible without relying on memory or scattered messages.

Go deeper on the topic

Related concepts
  • Human resources (HR) — increasingly called people operations, people ops, or simply "people" — is the organizational function responsible for the systems and...
Related guides

Ready to use this template?

Get started with MangoApps and use Offboarding Access Deprovisioning Coordination Checklist with your team — pricing built for small business.

Get Started