Blog

The Employee Offboarding Checklist Most Companies Get Wrong

Written by Marketing Lenet | Aug 18, 2026, 12:10:22 PM

Onboarding gets careful attention at most companies. New hires receive equipment, credentials, and access on their first day, following a defined process. Offboarding rarely receives the same discipline. An employee leaves, and access removal often happens informally, incompletely, or days later than it should. That gap is a common and avoidable source of security exposure.

Why Offboarding Fails in Practice

Offboarding touches more systems than most people realize. A single employee accumulates access to email, file storage, internal applications, third-party SaaS tools, physical badge systems, and sometimes shared credentials for accounts without individual logins. Removing all of this access requires coordination across IT, HR, and often individual department managers who granted access informally over time.

This coordination breaks down for predictable reasons. HR knows the employee is leaving but may not have a complete picture of every system that person can access. IT may only know about centrally managed accounts, missing tools that individual teams adopted independently. When a departure is sudden or contentious, the process moves even faster than usual, increasing the odds something gets missed.

The result is access that outlives the employment relationship. A departed employee with lingering access to email or file storage is not always a malicious risk. It is, at minimum, an account nobody is actively securing, sitting available for compromise long after anyone is monitoring it.

What Gets Missed Most Often

Shared accounts and shared credentials rarely appear on a standard offboarding checklist, because no individual account ties clearly to the departing employee. A social media login shared among a marketing team, or a vendor portal with one login used by several people, often does not get its password changed after someone with access leaves.

Third-party SaaS tools adopted outside a central IT process are easy to miss entirely. If nobody maintains a full inventory of connected applications, an employee's individual login to a tool IT does not know exists simply continues working after departure.

Physical access frequently lags behind digital access removal. A badge or key fob can remain active well after system credentials are revoked, particularly if physical security and IT security are managed by different people without a shared checklist.

Forwarding rules and mobile device access are also commonly overlooked. An employee who set up email forwarding to a personal account, or who has company email configured on a personal phone, may retain access to communications even after their primary account is disabled.

Building a Process That Actually Closes the Gap

Maintain a current access inventory for every employee, not just a list of centrally managed accounts. This inventory should be updated whenever new access is granted, not reconstructed from memory when someone leaves.

Set a firm timeline for access removal, ideally same-day for standard departures and immediate for involuntary ones. A ticket that sits open for a week defeats the purpose of having a process at all.

Assign clear ownership for each category of access: IT for core systems, department managers for team-specific tools, facilities for physical access. A checklist without an owner for each line item tends to leave gaps at exactly the items nobody feels responsible for.

Review and rotate shared credentials as a standard part of any departure involving someone who had access to them. Treat shared accounts as a known gap requiring deliberate attention, not an exception the process can skip.

Conduct periodic access audits independent of any specific departure. This catches accounts that offboarding missed, whether from a past departure or from access that was never properly tracked in the first place.

Include offboarding review in the incident response plan. If a company later investigates unusual account activity, confirming a departed employee's access was fully removed should be one of the first checks performed.

A Small Process With Outsized Consequences

Offboarding rarely gets the attention onboarding does, in part because it feels like an administrative afterthought rather than a security function. Treating it with the same rigor closes a gap that costs little to fix and, left open, can persist quietly for months without anyone noticing.