Employee Offboarding Checklist for Small Teams
The last day is when everything breaks — because at a small company, offboarding is an event with no owner. Big companies have HR run a process; a five-person team has whoever remembers. This is the checklist that makes the leaving boring: start it the day notice lands, revoke in blast-radius order, get the hardware and the keys back before the cake, cut the mailbox over before the farewell email, and re-check two weeks later when you find out what only they knew.
1. Day zero: the kickoff happens when notice lands, not on the last day
- Two weeks of notice is two weeks of runway — spend it on paperwork, not awkwardness. The day the resignation lands, open the offboarding ticket and date-stamp it. Pull the access inventory while you can still ask them what they have: the SSO list, the apps that don't sit behind SSO (the SaaS sprawl audit output if you've run one), the devices assigned, the badge, the keys on the ring, the vendors where they're the named contact. The access request & offboarding checklist owns the revocation tickets; this page owns the event.
- Name one owner and one date. Not "HR will handle it" — at small size there is no HR, so write a name next to each item and a date next to each name. The checklist fails the same way every ops checklist fails: nobody was responsible. If the leaving person is the one who would have run it, the kickoff is the manager's job, in writing, the same day.
- Announce the last day to the systems, not just the team. Calendar hold on their meetings after the end date, a freeze on new standing access grants (no new repo, no new vendor portal in the final fortnight), and the customer-facing handover list started early enough that the successor — or you, if there is no successor — can shadow before, not after.
2. Access revocation, ordered by blast radius
- SSO first, because it is the master switch. One toggle in the identity provider kills email, calendar, and every SaaS behind it at once. Do that at the hour the employment ends — not end of day, not "when we get to it." Then walk the apps that do NOT sit behind SSO: the subscription tools someone made an account for directly, the contractor portals, the social logins. The shadow IT audit list is where those hide.
- Forwarding rules and OAuth grants are the quiet hole. The classic business email compromise: a forwarding rule set months ago keeps mailing your invoices to a personal address. Check and kill mail forwarding, delegation, and app passwords; revoke the OAuth grants (the email security checklist walks the forwarding-rule audit that catches this).
- Shared logins rotate the day they leave. The shared analytics login, the vendor portal everyone uses, the department password in a doc somewhere — every shared credential they knew changes the same day. The secrets rotation checklist is the drill; the password manager rollout is the fix that makes it a two-minute job instead of a scavenger hunt. Personal API keys and deploy tokens they minted get revoked too — tokens outlive people.
- Prove the revocation with the account itself. The test is not "we clicked the button." Try the old password from a personal machine. Check the SaaS admin panel for the seat count going down. The user access review exists because revocation systems have a way of quietly not revoking.
3. Devices, keys, and badges come back before the farewell coffee
- Hardware returns are a signed list, not a shrug. Laptop, phone, monitor, dongles, the Yubikey, the parking fob: one line each, condition noted, signature taken. The laptop gets wiped and reimaged the same week — a departed employee's MacBook in a drawer is an unpatched machine holding your source code. The lost laptop runbook covers the exposure when it never comes back; this line covers the one that does.
- Keys and badges ride the same pass. Front door, server closet, cabinet keys — mark them returned on the key inventory register the same hour, rotate any door codes they knew (door code rotation policy), deactivate the badge the day the employment ends, not the end of the month (badge access control). Physical access is the offboarding item most often forgotten, because there's no admin console reminding you.
- The personal-data download rule, decided before it's needed. Decide in advance what a leaving employee may export (their own sent mail, their personal files) and how (a supervised export, not a full mailbox download the night before). The rule written on day zero prevents the argument on the last day.
4. Mailbox and calendar cutover on day zero, not day minus-one
- Forward-with-notice, never silent forwarding. The mailbox either converts to a shared/reply-access archive or gets a graceful alias — but the auto-forward to a personal address goes off the same day the account locks. Set the out-of-office with a real human's name and a real address: "For X, contact Y." An OOO pointing back at the departed mailbox is the ops equivalent of a door with no handle.
- Meetings have owners, and owners leave. Recurring meetings the person owned die the day their calendar does. Reassign the recurring series, transfer the calendar ownership, and sweep the team's calendars for the graveyard of declined-after-the-fact meetings. Same for mailing lists: the address that only they moderated now moderates nobody.
- The farewell email is a security decision. It announces to the world — customers, vendors, anyone on the thread — that a person with knowledge of your systems is no longer there, and it tells those people who to re-establish contact with. Write it deliberately: who inherits the relationship, from what address, effective when. The escalation checklist logic applies: every relationship gets a named next stop.
5. The knowledge that doesn't stop being needed
- The on-call handoff is a transfer of load, not a calendar invite. Rotations, escalation paths, the runbook locations, the pending incidents — the on-call handoff checklist covers the mechanics; the offboarding part is making sure the load moves to named people with time to absorb it, not to the queue.
- Write the "only they know" list before they leave, not after. One hour of "walk me through the things not written down anywhere" beats two weeks of archaeology after. Where the deploy script actually lives, which vendor rep answers emails, why the payment webhook has that weird retry setting. The process documentation practices page is the long-term fix; the list is this week's.
- Post-mortem the departure like a small incident. Two weeks later: what broke because they left? What did the team rediscover the hard way? The answer is your onboarding checklist for the next hire — and the honest input to the annual security review.
6. Money and admin loose ends (the ones that surface in month two)
- Final pay, benefits, and the card they still hold. Final payroll through the actual last day, benefits end date, pension/401(k) paperwork, insurance certificates, and the company card: cancel or transfer it, and sweep the card statement for subscriptions they personally signed up for — the shadow IT audit's card-statement trick, applied to a specific human.
- Vendors where they were the account contact. Every vendor portal where they're the named admin or billing contact needs a successor — especially the ones holding your data. The vendor offboarding & data deletion checklist covers the vendors you're leaving; this is the vendors you're keeping, minus their email address on the account.
- The registrar and the owner records. If they held the domain registrar login, the GitHub org owner seat, or the "admin contact" on anything — transfer it before day zero. Owner-of-record left unassigned is how a company discovers it doesn't own its own domain. The domain hijack protection checklist is the standing defense.
7. When the exit is not amicable: the hostile-variant sequence
- Revoke first, meet second. If the termination is involuntary or trust is broken, the sequence inverts: lock the accounts and collect the hardware before the conversation, not after. The polite fiction of "we'll sort access next week" is how disgruntled-exit incidents happen. The first 30 minutes runbook is what you fall back to if the exit goes wrong anyway.
- Preserve before you delete. Legal hold beats the wipe: export the mailbox and the device state before reimage if there's any dispute risk, then revoke. A deleted mailbox is evidence you can't un-delete. Document the timeline — what was revoked, by whom, when — in the same format the incident timeline template uses, because if it ever becomes a dispute, that timeline is your record.
8. The two-week-after check (where offboardings actually get verified)
- Re-run the access inventory against the people list. Two weeks after the last day, diff your SSO/SaaS admin seats against the current team list. Orphaned seats, still-enabled accounts, the vendor login you meant to rotate — this is the check that catches them. It feeds the quarterly user access review, which is the same sweep on a schedule.
- Watch the audit logs for the departed account. Sign-in attempts from the old account, API calls from keys you missed, the odd "password reset for deleted user" — two weeks of logs tells you whether the revocation was real or theatrical.
- Count the relics. The badge that wasn't returned, the key still on the register, the calendar that still has their name, the customer replying to an address nobody reads. Every relic is a process gap, and the fix is one line added to this checklist — which is how it stays alive.
9. The one-page version (print it, tape it inside the offboarding folder)
- The nine-line version: (1) notice lands → open this checklist, date it, name an owner; (2) pull access + device + key inventory same day; (3) last day: SSO off → non-SSO apps off → shared logins rotated → keys/badges in → devices wiped; (4) mailbox: forwarding off, OOO with a human, meetings reassigned; (5) on-call and customer handover confirmed to named people; (6) money: final pay, card, subscriptions, vendor contacts; (7) registrar/org-owner seats transferred; (8) hostile variant: revoke before the meeting, preserve before you delete; (9) +2 weeks: re-run the seat diff, watch the logs, count the relics.
- Small teams have no HR to catch the drift — so give the checklist a heartbeat. The moment notice lands is a trigger, not a mood: open the checklist, start the clock, work the list. The employee onboarding template is the mirror image — every revoke step here should have a matching grant step there, which is how you catch both halves of the access ledger.