Employee IT Offboarding Workflow
IT offboarding for {{ employee_name }} ({{ department }}) Last Day: {{ last_day }} | Manager: {{ manager_name }} | Type: {{ separation_type }}
Phase 1 — Pre-Departure (3-5 business days before last day)
Access Audit
- Inventory all systems and applications {{ employee_name }} has access to
- Document all group memberships and role assignments
- Identify any shared accounts or service accounts managed by the employee
- Check for any API keys, tokens, or secrets created by the employee
- Review file shares and cloud storage permissions
Data Handling
- Coordinate with {{ manager_name }} on data transfer requirements
- Identify critical files that need to be transferred to a colleague
- Back up email mailbox per retention policy
- Back up personal drive / OneDrive / Google Drive per retention policy
- Document any knowledge transfer requirements
Device Planning
- Identify all company devices assigned to {{ employee_name }}
- Schedule device return (in-person or shipping label for remote)
- Prepare device wipe checklist
Phase 2 — Last Day (end of business on {{ last_day }})
Immediate Access Revocation
- Disable Active Directory / identity provider account
- Revoke SSO access (all connected applications disabled automatically)
- Disable email account (convert to shared mailbox if needed)
- Revoke VPN access
- Remove from MFA/2FA
- Disable remote access tools
- Revoke badge/physical access (coordinate with facilities)
Application-Specific Revocation
- Remove from Slack / Teams / collaboration platforms
- Revoke access to source code repositories (GitHub, GitLab, Bitbucket)
- Remove from cloud console access (AWS, Azure, GCP)
- Revoke ITSM portal access
- Remove from SaaS applications not covered by SSO
- Revoke any delegated admin permissions
Communication
- Set up email auto-reply / forwarding (per policy, max 30 days)
- Update voicemail greeting if applicable
- Remove from email distribution lists
Phase 3 — Post-Departure (within 5 business days)
Device Processing
- Collect all company devices (laptop, phone, tablet, peripherals)
- Verify device encryption status before wipe
- Perform secure data wipe on all returned devices
- Update asset management records (return to inventory)
- Reclaim software licenses from device
License Reclamation
- Reclaim all named-user software licenses
- Deactivate license seats for SaaS tools
- Update license count in asset management
Compliance & Documentation
- Confirm all access has been revoked (audit log review)
- Document offboarding completion in ITSM
- File offboarding checklist for compliance records
- Notify {{ manager_name }} of completion
- Close offboarding ticket
Counter-Rationalizations
| Shortcut | Counter | Why |
|---|---|---|
| "We can skip some steps for this case" | Adapt the workflow steps, don't skip them | Skipped steps are where incidents and oversights originate |
| "The user seems to already know what to do" | Complete all workflow phases with the user | The workflow catches blind spots that experience alone misses |
| "This is a minor case, full process is overkill" | Scale the process down, don't turn it off | Minor cases become major when unstructured; the process scales, not disappears |
| "I'll fill in the details later" | Complete each section before moving on | Deferred details are forgotten; real-time capture is more accurate |
| "The template output isn't necessary" | Always produce the structured output format | Structured output enables comparison, audit trails, and handoff to other teams |
Output Format
Generate a tracked offboarding report with:
- Summary with employee details and completion status
- Access revocation checklist with timestamps
- Asset return status with device details
- Compliance sign-off confirmation