Employee offboarding is one of the highest-risk operational moments for any IT department. Done well, it's invisible. Done poorly, it creates security vulnerabilities, compliance gaps, and asset losses that surface months later.
The average employee has access to 11 different SaaS applications, 2–3 physical devices, and various shared resources at the point of departure. In the chaos of notice periods, knowledge transfer, and HR paperwork, IT tasks frequently fall through the cracks. A formal, tracked checklist is the only reliable solution.
As soon as a departure is confirmed, IT should be notified of the leave date and begin documentation of all devices assigned to the employee, including asset tags, serial numbers, and current condition. Review and document all application access and permissions, and identify any admin or elevated access that requires immediate attention.
In the final week, schedule account deprovisioning for the last working day and transfer ownership of critical files, emails, and shared drives. Revoke access to all SaaS applications — using an identity provider where available — and change passwords on any shared accounts. Disable VPN credentials and remote access certificates.
Dispatch a ReturnKits return kit 5–7 days before the employee's last day. Confirm kit receipt by the employee and track the device return via the ReturnKits portal. On receipt, update the asset register with the return date and device condition, then queue the device for secure wipe and redeployment assessment.
Confirm all application access is revoked, ideally via an automated audit. Archive email and messaging accounts per your retention policy and issue a signed asset return confirmation to HR. Close the offboarding record in your ITSM tool.
Experience shows that hardware recovery is consistently the most delayed and most likely to fail step in the offboarding process. It requires coordination between IT, HR, and the departing employee — often under time pressure and across geographic distances. By making hardware recovery a structured, logistics-managed step rather than an informal request, you protect your assets and your compliance position simultaneously.
IT should be notified of the leave date immediately, begin documenting all assigned devices (asset tags, serial numbers, condition), and review the employee's application access and any elevated permissions.
5–7 days before the employee's last working day — not on or after it — so the device is already in transit or returned before the employment relationship ends.
The average employee has access to around 11 different SaaS applications plus 2–3 physical devices and various shared resources at the point of departure.
It requires coordination between IT, HR, and the departing employee, often under time pressure and across distance — which is why treating it as a structured, logistics-managed step rather than an informal request matters.