top of page

Employee Offboarding IT Checklist for Small Teams

Writer: Cory Allen
Cory Allen
Sep 10
6 min read

When an employee leaves, their last day can get busy quickly. There are final meetings, workload handoffs, and payroll details to manage. But if access to email, files, software, and company devices is left open, a simple departure can create a costly security gap. A clear employee offboarding IT checklist helps your small business close that gap without turning a stressful day into a technical fire drill.

For small teams, offboarding is not just an HR task or an IT task. It is a coordinated business process. Someone needs to know the employee is leaving, what they can access, which equipment they have, and who will take over their work. The goal is simple: protect the business while treating the departing employee fairly and professionally.

Why employee offboarding needs an IT checklist

Every employee account is a potential path into your business. That includes their work email, cloud storage, shared folders, accounting platform, customer database, chat app, password manager, and the laptop or phone in their possession. Even a well-intentioned former employee may still have access if nobody closes the right accounts.

The risk is not always malicious. A missed subscription can keep billing. An unattended inbox can cause a customer request to go unanswered. Files saved only on a local computer can disappear when that device leaves the office. In regulated industries, failing to remove access may also create compliance problems.

A written process removes guesswork. It also prevents a common small-business problem: one person knows where everything is, but no one else knows how to shut it down when they leave.

Start before the employee's final day

Offboarding works best when HR, the employee's manager, and whoever manages IT communicate early. The right timing depends on the situation. For a planned resignation, you may have time to prepare a transition. For an involuntary termination, access may need to be removed immediately and coordinated carefully.

First, identify the employee's role and the systems tied to it. A sales employee may need access to a CRM, quoting software, and a shared sales inbox. A bookkeeper may have banking, payroll, and accounting access. A field technician may use a company phone, mobile apps, and customer records. Do not rely on a generic list alone. Review the person’s actual responsibilities.

It is also wise to confirm where business information lives. Ask the manager which projects, customer conversations, files, vendor contacts, and recurring tasks need a new owner. This is where offboarding becomes business continuity, not just account removal.

Employee offboarding IT checklist: accounts and access

Access should be reviewed as a complete inventory, not as a single email account. Your checklist should cover the following areas:

  • Work email, calendars, shared mailboxes, aliases, and email forwarding rules

  • Microsoft 365, Google Workspace, cloud storage, shared drives, and collaboration tools

  • Business software such as CRM, accounting, payroll, POS, project management, and scheduling platforms

  • Password managers, remote access tools, VPNs, Wi-Fi credentials, and multifactor authentication methods

  • Administrative access to websites, domains, social media accounts, cloud services, and vendor portals

Begin by disabling sign-in access at the appropriate time. In many cases, it makes sense to block access first rather than immediately deleting the account. This preserves data and gives your team time to transfer ownership, review files, and set up a professional response for incoming messages.

Next, remove the employee from groups, shared folders, distribution lists, and third-party applications. Disabling an email account alone does not necessarily remove access from every system. If the person used a separate login for your accounting tool or had an admin role on a website, those permissions must be handled separately.

Multifactor authentication deserves special attention. Remove personal phone numbers, authenticator app connections, recovery email addresses, and backup codes. Otherwise, a former employee may be unable to access the account but could still receive security prompts or account-recovery notices.

Preserve data before deleting anything

Deleting an account too early can erase information your business needs. Before removing licenses or permanently deleting files, transfer ownership of important data to a manager or shared business account.

Review email for active customer conversations, vendor agreements, invoices, and project details. Set an auto-reply that directs senders to the right person, but keep it brief and respectful. You do not need to share personal details about why someone left. A simple message saying the employee is no longer with the company and providing a new contact is usually enough.

For cloud files, identify the folders that need to remain with the business. Personal drafts and clearly private material should be handled according to your company policies and applicable laws. When in doubt, avoid casually searching through employee content. Focus on legitimate business records and involve HR or legal counsel when the situation is sensitive.

Retention also depends on your industry. A company handling healthcare, financial, legal, or customer payment information may have stricter requirements for records and access logs. Your IT process should support those rules rather than accidentally working against them.

Collect and secure company devices

A laptop with an active login can be more valuable to an attacker than a password written on a sticky note. Recovering company devices is a core part of offboarding, whether the employee works in the office, from home, or on the road.

Document every item issued to the employee: laptop, desktop, monitor, phone, tablet, charger, security key, headset, and any printed materials containing sensitive information. When the equipment is returned, check that it is in working condition and confirm the serial number or asset tag.

The device should not simply be handed to the next employee. IT should verify that business data is backed up, remove the departing employee’s access, check for unauthorized software, and apply pending updates. Depending on your device-management setup, the best approach may be to reset and redeploy the device. For a shared workstation, a separate user profile may be enough, but only if files and permissions have been reviewed.

If a device cannot be recovered promptly, change passwords for accounts used on it and consider remotely locking or wiping it. This is one reason managed device tools can make a major difference for small businesses. They allow you to act even when a laptop is sitting in someone’s home office hundreds of miles away.

Handle passwords, vendors, and hidden access

The accounts you remember are often not the ones that cause trouble. Many businesses have a few services that were set up years ago under an employee’s personal email address or credit card. Those accounts can be difficult to recover after the person leaves.

During offboarding, review vendor relationships and administrative ownership. Confirm that domain registrations, website hosting, online advertising, social accounts, payment processors, shipping portals, and software subscriptions are owned by the business, not an individual employee. Update the primary contact and billing contact where needed.

If the employee knew shared passwords, change them. This includes Wi-Fi passwords, alarm codes, printer admin passwords, shared mailbox passwords, and vendor logins. A password manager makes this much easier because you can revoke access to a shared vault instead of hunting through spreadsheets or old emails.

Do not forget physical security. Collect building keys, access cards, parking passes, and alarm credentials. Technology security and physical security often overlap more than small businesses expect.

Document the handoff and confirm completion

A checklist only works if someone owns it. Assign a responsible person for each offboarding step, then record when it was completed. For smaller organizations, that may be a manager working with an outsourced IT provider. The key is having a repeatable record, not creating extra paperwork for its own sake.

Keep a short offboarding file that documents the final access date, systems reviewed, devices returned, data transferred, and any follow-up actions. This record can be helpful if a question comes up later about account access, customer communications, or missing equipment.

It is also a good time to review what the departure revealed. Did the employee have more access than their role required? Were business accounts tied to a personal email? Did critical knowledge live only in one inbox? Small improvements after each transition can prevent bigger problems later.

Make offboarding part of everyday IT care

The best time to prepare for an employee exit is before anyone gives notice. Keep an updated list of software, devices, account owners, and admin permissions. Use individual accounts instead of shared logins whenever possible. Require multifactor authentication, back up business data, and make sure at least two trusted people can access essential systems.

Cloudigan helps small businesses put those basics in place so offboarding is a controlled process rather than a scramble. With managed devices, clear account ownership, and ongoing support, you can spend less time worrying about who still has access and more time supporting the team members who remain.

A departing employee should leave with a clear transition, and your business should keep moving with confidence. A simple checklist, followed consistently, gives you both.

 
 
 

Comments


bottom of page