Offboarding is onboarding in reverse: every account, device and permission you granted gets closed, collected or handed over on a set schedule. Tell IT the departure date and time early, cut sign-in access at the moment the person leaves, and keep the mailbox and files your business still needs.
Most offboarding gaps aren't dramatic. A former employee's email still syncs to a personal phone. A shared vendor password never got changed. A license keeps billing for someone who left in spring. Each one is small, and together they add up to access you no longer control. This checklist mirrors our new employee IT security checklist, because a clean exit depends on a good record of what was handed out at the start.
Give IT the last working day and the exact time access should end. "Friday" isn't enough: 5:00 p.m. Friday and 9:00 a.m. Friday are very different plans. Include who the person reports to and who will take over their work, so questions about files and mailboxes have an owner.
Pull the onboarding record and confirm what the person actually has today. People collect access over time, so check beyond what they started with:
Identify which mailboxes, OneDrive or Google Drive folders and local files someone else needs, and who that person is. Decide now whether the mailbox will be converted to a shared mailbox, forwarded for a period, or archived. Deciding this on the last afternoon is how files get lost.
If your firm is regulated or involved in litigation, confirm with your compliance lead or counsel whether the person's email and files must be preserved before anything is deleted, converted or wiped. A preservation requirement changes the order of the steps below.
These steps happen together, ideally while the person is in their exit meeting or right after they leave.
Coordinate timing with IT before the conversation happens. Access should be disabled while the meeting is taking place, not afterward. Give IT the time privately, keep the circle small, and have the hardware collection plan ready. For anyone with administrator rights or access to money movement, plan this with extra care.
If the departing employee managed your systems, the scope gets bigger: admin accounts, domain and DNS registrars, firewall credentials, backup consoles and vendor relationships. See what to secure in the first week after your IT person quits.
Disabling access is required. Deleting records may not be allowed. HIPAA requires covered entities and business associates to keep required documentation, such as policies and records of security activities, for six years. SEC-registered investment advisers have books-and-records obligations under Advisers Act Rule 204-2, and broker-dealers under Exchange Act Rule 17a-4, which can include business communications such as email. Converting a mailbox to a shared or archived state, rather than deleting it, keeps you from destroying records you may need. Records of access removal also support the safeguards your firm describes in its written policies, such as a GLBA written information security program or Regulation S-P procedures.
NerdSquad is not a law firm. Confirm your firm's obligations with your compliance counsel.
For managed IT clients, an offboarding request is a ticket to our IT help desk. Send it as early as you can with the date, time and who should receive the person's mail and files. We schedule the access cutoff for the time you give us, work through the checklist above, handle the mailbox, file transfer and license steps through our Microsoft 365 support, and document what was done in the ticket. For terminations, call us so we can coordinate the timing directly. If something looks off in the sign-in logs, we tell you.
Already a client? Call (239) 465-0079 or submit a ticket. If something is down, call so we can start right away.
Not a client yet? NerdSquad Managed IT Services is a Managed Service Provider (MSP) based in Naples, Florida. We support businesses onsite across Southwest Florida and remotely nationwide. Book a discovery call or call (239) 465-0079.