The Offboarding Checklist: Handover, Access, and the Last Day

Offboarding is the only HR process whose completion depends on someone who is leaving. Six things that must happen and who owns each, an hour-by-hour last day, and how to prove a revocation actually happened.

Emily Thompson Emily Thompson 33 min read
The Offboarding Checklist: Handover, Access, and the Last Day

TL;DR

  • Core decision: Who owns the last day before the last day arrives, and what evidence they leave behind.
  • When doing nothing is right: Your joiner-mover-leaver record is current, your manager signs off a handover document, and IT revokes access on a known trigger, not on a remembered request.
  • What has to be true: One person has the authority and the obligation to close the file, and a record exists that someone else can audit a year later.
  • How the options split: Between a checklist that lives in a wiki, a checklist that lives in a system of record, and a checklist that lives in someone's head, with a fourth pattern where ownership is genuinely shared and tolerated as such.
  • Decision rule: If you can't name the owner, the access, and the artefact in one sentence, the process isn't in place.
  • Outcome to expect: A clean exit produces a paper trail; a messy exit produces a question, six months later, about an account nobody can explain.

The email arrives at 4.47pm

The operations lead at a mid-sized professional services firm is closing tickets when the calendar reminder fires. Tomorrow is Sarah's last day. Sarah is a senior analyst in the client reporting team. She has been there four years. She has access to thirty-one systems, three of which aren't on the IT inventory because a former colleague set them up for her years ago. Her manager, who has been busy on a pitch all week, knows Sarah is leaving in the way people know a fact without acting on it. IT has not been told. Payroll has been told, sort of, via a form the HR generalist filed three weeks ago and has not checked since. There's no handover document. There's a Slack channel where Sarah's work lives, and a shared drive where three clients' files sit in folders that only she has permission to edit.

Tomorrow, Sarah's badge will stop working at 6pm. Tomorrow, her laptop will be collected at the door. Tomorrow, the building manager will be the first person to ask the question that should have been asked a week ago: who is taking her clients?

But here's the reframe. The question isn't whether there's a checklist. Every firm in this position has a checklist, usually two of them, usually in different places, usually maintained by people who have left. The real issue is that the person with the strongest reason to complete the process is the person walking out of the building, and everyone else's reason to complete it's weaker, and the failure is invisible until a long-dormant account wakes up at 2am to send spam from a domain you forgot you owned.

When you do not need to act

There's a version of this problem you don't have. It's worth naming it, because pretending every reader is in crisis makes the rest of this piece unreadable, and a checklist written only for the burning building is the same checklist that gets ignored on the calm day. The four stages below are honest about how often doing nothing is the right call.

You genuinely don't need a new offboarding process if your joiner-mover-leaver record is the source of truth for access, not a reconstruction. That's, when access is granted the day someone joins and recorded in the same place, and when the same record is the basis for revocation on the day they leave, then the offboarding problem doesn't exist as a separate problem. It's a column in a table. If this describes you, the only thing you owe yourself is a quarterly check that the table is still being filled in, because the record rots quietly and the first sign of rot is a contractor who left nine months ago and still has a license you're paying for.

You have friction, not failure, if your process works but it's held in a wiki, in a shared drive, or in the head of one person who has been there forever. The thing that doesn't yet work is continuity: the wiki page is two years out of date, the shared drive has three versions, and the person in question is thinking about retirement. You can keep going. The risk is concentrated, and a single departure of that person turns your friction into the scenario in the cold open above. If this is where you sit, the move is to pick a single owner for the wiki page and a single owner for the offboarding process and make them the same person, which is a different decision than the one this article is mostly about.

Free Weekly Briefing Stay ahead of what's changing in HR and people ops.

Join 4,200+ leaders getting practical insights every week — no fluff, just signal.

Join Free →

You have a real risk, not friction, if access is granted informally and revoked by memory. That's, if a manager can hand a contractor a login to a system without IT knowing, and the only way access is revoked is when someone remembers to ask. Most firms are somewhere on this spectrum, and most don't realise it because the access looks fine until the day it doesn't. If this is you, the work is to find the joiner-mover-leaver record you don't have, and the hardest part is that the record has to start being kept now, for grants that happen today, and only becomes useful for the next departure, and only fully useful for the one after that. There's no shortcut that closes the gap in one quarter.

The edge case, which deserves its own paragraph, is the firm that has a process on paper, has a system that enforces it, and still gets caught out. This happens when the process is well-designed for a normal departure and the next departure isn't normal: a long illness, a dispute, a redundancy programme, a senior leader who negotiated a six-month garden leave. The offboarding machinery works for the median case. The tails are where the harm lives, and the only defence is to make sure the person with the authority to depart from the standard process has been told, in writing, what the standard process is, so that the deviation is a deviation rather than a guess.

The 11pm questions

Five questions this reader is asking themselves, late, in a tab they will close without answering.

Who actually owns this. The honest answer is that ownership is split between HR, IT, the line manager, and the departing employee, and the question is which of those has the obligation to drive the others, not which of them is involved. The reasoning is that "involved" isn't "responsible", and a process that names three owners has none. If you get this wrong, you get a scenario in which HR files a form, IT waits for an email, the manager assumes IT was told, and the form never gets sent.

When should access be revoked. The answer is that physical access and digital access are different decisions, and the right time for each depends on what you're protecting against. Cut the badge at the end of the last day. Cut high-privilege system access at the start of the last day, or earlier, depending on whether the person is in a notice period or a garden leave. The reasoning is that the longer the window between "they have decided to leave" and "they no longer have access", the larger the surface for an action that's later regretted. If you get this wrong, you either lock someone out a month early and damage goodwill, or you leave an account open a year too long and pay for it later.

What about the personal device. The right answer is that you can't inventory what you don't know about, and the first step is to ask, in writing, before the last day, with a clear statement of what the company will and won't do with the device. The reasoning is that asking on the last day is too late to act on the answer, and not asking leaves the question open. If you get this wrong, a sync you forgot about keeps a feed of company mail on a phone you no longer control, or a backup you can't wipe keeps a copy of a file you didn't know was there.

What about their email. The honest answer is that you keep the mailbox, redirect incoming mail for a defined period, and tell senders once. The reasoning is that deletion is irreversible, that people who never told the leaver anything in writing will now tell their replacement, and that you want that flow to land somewhere you can see. If you get this wrong, you either keep a mailbox that becomes a legal hold by accident, or you delete one that turns out to contain the only copy of a contract that matters.

What if the exit goes wrong. The right answer is to separate the person from the process before the conversation, not after. The reasoning is that the legal exposure of a sloppy offboarding is much higher after a dispute than after an amicable departure, and the documentation you wish you had is the documentation you should have built before you knew you would need it. If you get this wrong, you discover, a year later, that a phrase in a leaver's exit notes is the only record of why a decision was made, and the person who wrote it's now a witness you can't locate.

Three ways the approaches split

The patterns for offboarding cluster into three families, and the right one for a given firm depends on its size, its system sprawl, and how much of the work is done by people who will still be there in eighteen months.

The first family is the wiki checklist. A page in the company knowledge base lists the steps, the owners, and the order, and a human follows it. This is right for a firm under roughly fifty people, with a handful of systems, and a single person in HR or operations who has been there long enough to know which steps are still real. It fails when the page stops being read, which happens around the time the third person leaves who knew where the page was. The illustrative picture: a thirty-person agency, one operations lead, a Notion page, a Slack channel for questions, and a clean record until the operations lead goes on holiday and the next departure lands on a Monday.

The second family is the system-driven workflow. The HRIS or the identity provider is the source of truth, and the offboarding steps are tasks attached to a status change. This is right for a firm with enough system sprawl that no human can hold the access list in their head, and where the same system that hires can revoke. It fails when the systems that matter aren't in the system, which is most of them, and when the workflow is a workflow in name only, with a person still required to remember to press the button. The illustrative picture: a four-hundred-person SaaS company, an identity provider doing the heavy lifting for SSO, a dozen SaaS apps outside SSO that are tracked in a spreadsheet, and a quiet assumption that someone is looking after the spreadsheet.

The third family is the manager-led process with a paper trail. The line manager is the owner, with a documented handover template, a checklist they sign, and an HR or IT partner who reviews. This is right where the work is project-shaped, where the handover is the heart of the offboarding, and where a system would be more friction than the manager's own attention. It fails when the manager is the one leaving, or when the manager is overloaded, or when the paper trail isn't actually a paper trail but a chat thread. The illustrative picture: a consulting firm where every engagement has its own handover document, signed by the manager and counter-signed by the incoming lead, and the offboarding is in the shape of the engagement, not in the shape of the access list.

Five diagnostic questions

The questions below aren't a quiz. They're a way of locating yourself on the map, and the way to answer them is to walk to the place in your own firm where the answer should be visible and see whether it's.

Is the joiner-mover-leaver record the source of truth for access, or is access granted informally and audited later? The way to answer this is to pick three people who left in the last year, and for each one, list every system they could reach on the day they were told they were leaving. Then check that list against the access record. If the two lists match, the record is the source of truth. If they don't, the record is a memory aid and the actual source of truth is your assumptions, which were correct often enough to fool you.

Can you name, in one sentence, the person who owns the offboarding file from resignation to last-day-plus-thirty? The way to answer this is to ask five people in your firm, separately, who owns the offboarding of a person who resigned this morning, and to compare the answers. If the five answers name the same person, you've an owner. If they name three people, or name a function without a person, you've a committee, which is a polite word for nobody.

For the last three leavers, is there a signed handover document that names the incoming owner of every recurring task? The way to answer this is to ask for the documents. If they exist, the next question is whether the incoming owners were copied, whether they agreed, and whether the tasks still exist. If the documents don't exist, the question is what you would find if you asked the people who took over, and the answer is usually "I worked it out".

When access was revoked for the last leaver, who did it, and how was it evidenced? The way to answer this is to ask IT, or the equivalent, for the ticket, the log entry, the system report. If they can produce it within an hour, the revocation is evidenced. If they have to reconstruct it from memory, the revocation is a story, and a story isn't evidence in the year the question gets asked again.

If a leaver's manager is unavailable, who steps in to drive the offboarding, and do they know it? The way to answer this is to check whether the answer is written down, or whether it's a person who would only find out on the day. The first version is a process. The second is luck.

Six Things That Have to Happen, and Who Owns Each

Knowledge handover

What it is: a documented transfer of the recurring work, the in-flight work, the relationships, and the unwritten rules, from the person leaving to the person staying. The minimum useful version is a one-page handover per major responsibility, naming the work, the cadence, the counterparty, the next deadline, and the thing that would break if it were missed. Why it earns a place: the handover is the only offboarding output that the firm will feel inside a week. The access revocation is invisible until it isn't, but the handover is the daily pain the team absorbs from day one. Where it falls short: a handover document is a snapshot, and the things that break first are the things that were not written down because they felt too small. A signed handover also creates a false sense that the work has been transferred, when in practice the new owner is still learning, and the realistic ask is a two-to-four-week overlap of questions, not a clean handoff. The owner is the line manager, with the leaver as a contributor and a peer as a recipient, and HR as the party that confirms a signed handover exists before the last day.

System and building access revocation

What it is: the act of removing the departing employee's ability to reach systems, data, and physical spaces, on a schedule and in a sequence, with a record of what was removed. Why it earns a place: this is the offboarding task that carries the security and the legal exposure, and it's also the one most often left to memory. Where it falls short: revocation is only as complete as the access list, and the access list is almost never complete on the day the person leaves, because access has been granted piecemeal over years. The honest answer is that some access will be missed, and the only way to find it's to revoke what is known, then wait, then look for the rest. A related shortcoming is that high-privilege access is sometimes revoked on the same day as ordinary access, when the prudent sequence is to revoke the high-privilege first. The owner is IT, with the line manager as the source of "what does this person actually have", and HR as the party that triggers the workflow.

Equipment and asset return

What it is: the recovery of the laptop, the phone, the monitors, the access cards, the security tokens, the YubiKeys, the company credit cards, the company car, the office keys, the uniforms, the library books, and anything else the firm handed out and forgot to track. Why it earns a place: equipment is a recoverable cost, an information liability, and a data-protection question, and the value of the equipment is small compared to the value of what is stored on it. Where it falls short: the list of what was issued is rarely complete, and the people who issued the equipment have often moved on. The other shortcoming is that personal data on the device is treated as company data until someone asks, and the moment someone asks is usually the moment after the device has been wiped. The owner is IT for the tech, facilities for the physical, and the line manager for the items the manager handed out personally, with HR holding the consolidated checklist.

Payroll and benefits closure

What it is: the final pay calculation, the payment of any accrued leave, the cessation of pension contributions, the closure of benefit enrolments, the issue of the final payslip, and the resolution of any outstanding advances or deductions. Why it earns a place: this is the part of offboarding that, if handled badly, produces a written complaint, a regulator letter, or a small-claims action. It's also the part that touches the most other functions, from finance to legal to the benefit providers. Where it falls short: payroll works on a cycle, and a last day that doesn't align with the cycle produces a delay, and a delay produces a question, and the question is usually asked by someone who has a new employer and a new payroll to coordinate with. The owner is payroll, with HR as the source of the dates and the entitlements, and the line manager as the confirmer of the final working day. The honest gap is that local rules on timing, deductions, and record retention differ, and the right move is to describe the shape of the exposure and confirm it locally.

The final reference and record position

What it is: the decision about what the firm will say about the leaver in the future, who will say it, in what form, and on what basis. It's also the decision about what the firm keeps: the personnel file, the right-to-work documents, the training records, the performance notes, the exit notes. Why it earns a place: a reference given carelessly is a liability, a reference withheld is a different liability, and the personnel file is the record that the firm has to produce if a question is asked years later. Where it falls short: most firms have no written reference policy, and the reference that's given is given by the most senior person available, who has the least context. The record position is weaker than the reference: most firms keep what they're required to keep, and throw out the rest, which means that the documentation that would have helped a future question was discarded to free up a filing cabinet. The owner is HR for the record and the policy, with the line manager as the source of the substantive content of the reference, and the senior leader as the gatekeeper for anything that goes beyond the factual.

The alumni relationship you either keep or lose

What it is: the choice, made on the last day or in the week after, about whether the firm stays in contact with the leaver, and on what terms. Why it earns a place: the leaver is, on their last day, the most expensive person the firm will ever lose. They have institutional memory, client relationships, and a network that the firm doesn't have a separate way to reach. The choice to keep the relationship is also the choice to maintain the firm's ability to ask the leaver a question six months later, which turns out to matter more often than the firm expects. Where it falls short: most alumni relationships are kept by accident, through a personal email and a LinkedIn connection, and the people who leave the firm and the people who are good at staying in touch aren't the same people. The other shortcoming is that the relationship needs a reason, and the reason is usually the next job, the next referral, the next client, and a programme that doesn't have a reason is a programme that will be quietly dropped within a year. The owner is the line manager, with HR holding a light-touch alumni list, and the leaver as the party who decides whether to stay in touch.

The Decision Table

Situation Scale Setup Primary Pain Recommended Starting Point
Under fifty people, one HR generalist, fewer than ten systems Small Wiki checklist, one owner Continuity if the owner leaves Single-owner wiki with a quarterly review and a named backup
Two hundred to a thousand people, mixed systems, SSO in place Mid Workflow in the HRIS, IT partner SaaS sprawl outside SSO System-driven workflow for the SSO estate and a tracked list for the rest
More than a thousand people, regulated, audit pressure Large Identity-led workflow, mature JML Coverage of edge cases and tails Identity-led workflow with a documented exception process for garden leave, illness, dispute
Project-based work, knowledge is the asset Project Manager-led, paper trail Handover depth and sign-off Manager-led with a signed handover template per project
Long-tenured workforce, low churn Stable Anything that has not rotted Quiet rot of the access record JML record as the source of truth, regardless of the offboarding tool
High churn, contractor-heavy Volatile System-driven, but contractor offboarding lags Time-to-revoke for contractors A separate contractor path with a shorter revocation window
Senior leader leaving, garden leave, or negotiated exit Edge Standard process plus deviation Coverage of access, communications, and references Named owner of the deviation, written deviation memo, dual sign-off
Hostile exit or dispute in progress Adverse Standard process plus legal review Evidence and timing Separate the person from the process before the conversation, written record of every step

The Last Day, Hour by Hour

The last day isn't a single event. It's a sequence, and the sequence has dependencies, and the dependencies break in predictable ways. The table below is a worked version of a typical last day for a non-manual, non-senior leaver in an office-based firm. Adjust the times to your building, your shift patterns, and your local rules, but keep the order.

Step Owner Timing What breaks if it slips
Confirm final working day, in writing HR Day before The rest of the day is built on a date that may be wrong
Final handover document signed and counter-signed Line manager Start of last day The new owner starts the next week with undocumented work
High-privilege system access reviewed and reduced if appropriate IT Start of last day The window for an action that would later be regretted stays open
Personal device, personal accounts, and personal data discussed and, where possible, removed Line manager, IT Start of last day A sync or a backup keeps a copy of company data on a personal device
Client and counterparty communications sent, naming the new owner Line manager Midday Clients and counterparties spend the next month emailing the leaver's address
Exit conversation held, in person, with notes taken and shared HR or line manager Midday The firm has no record of why the leaver is leaving, and the leaver has no record of what was said
Final pay and benefits position explained, in writing Payroll End of day The first question the leaver asks their new employer is about money, and the firm is the second call
Building access, badge, parking, and physical keys recovered Facilities End of day A badge that should have been deactivatied works for the rest of the week
System access revoked for all systems in the agreed scope IT Within one hour of building exit An account that should have been closed sends a message at 11pm
Equipment, devices, and tokens collected at the door or shipped IT, facilities End of day The next attempt to recover the laptop is a courier and a conversation
Personnel file closed, with the documents that have to be kept HR End of week The firm cannot answer a question that arrives in three months
Final reference position recorded, with a named spokesperson HR, line manager End of week The first reference request goes to the wrong person, with no fallback

The hour-by-hour picture isn't the process. It's the surface of the process. The process is the joiner-mover-leaver record that made the day possible, the workflow that triggered the steps, the owner who drove them, and the evidence that each step happened. If those aren't in place, the last day is improvised, and improvised last days are how the scenario in the cold open happens.

Proving It Was Done

The difference between an offboarding process and an offboarding story is evidence. The evidence doesn't need to be heavy. It needs to be findable, by someone who was not in the room, a year from now, in the middle of a question they didn't expect.

The minimum evidence trail, for a normal departure, is six artefacts. A written confirmation of the last working day, held in the personnel file. A signed handover document, counter-signed by the incoming owner, with a list of recurring tasks and a date for each. A revocation log, showing which systems were closed, when, and by whom, with the systems not in the log explicitly listed as out of scope. A return receipt for the equipment, with serial numbers, signed at the door. A final pay statement, with a line for accrued leave, deductions, and the date of payment, sent to the leaver and held in the file. A reference position note, naming the spokesperson and the form of the reference, with a copy of the reference if one is given.

The artefacts aren't the work. The work is the conversation, the handover, the access list, the equipment, the pay calculation, the relationship. The artefacts are what is left when the work is done, and they're the only thing that turns "I revoked the access" into "the access was revoked, on this date, by this person, in this system, and here's the log entry".

The unevidenced revocation is the same as no revocation. If a system was closed, but there's no log entry, the system was not provably closed, and a question that arrives later has no answer. If a laptop was returned, but there's no receipt, the laptop was not provably returned, and the data on it's still a question the firm can't answer. The work to build the evidence trail is small, and the cost of not building it's paid by the next person who has to find the answer.

The other reason to keep the evidence is that the leaver has rights over the record. In most places, the leaver can ask to see what was written about them, and the firm has to produce it, and the difference between a record the firm is comfortable showing and a record it isn't is the difference between an offboarding the firm designed and an offboarding the firm stumbled through.

What to Put in Writing

The table below is the writing the offboarding process owes to itself. The artefacts aren't optional. Each one is the answer to a question that's going to be asked, by someone who isn't in the room, in a year when the people in the room have moved on.

Artefact Who owns it When it is written What it prevents
Resignation letter or written confirmation of the decision to leave HR Day of resignation A dispute about whether the leaver resigned, was dismissed, or was pushed
Last working day confirmation, in writing, to the leaver HR Day of resignation, revisited on any change A dispute about the final date, and the cascade of pay, access, and notice calculations that depend on it
Handover document, signed by leaver and incoming owner, counter-signed by line manager Line manager Before the last day A dispute about who owns the work, and a gap in coverage on a client, a system, or a recurring task
Access list as at the start of the last day, reconciled to the JML record IT, with line manager as confirmer Start of last day An unevidenced revocation and a surprise when an account the firm did not know about is used months later
Revocation log, with system, timestamp, actor, and method IT End of last day and the day after A question about whether access was actually removed, on a date the firm can stand behind
Equipment return receipt, with serial numbers, signed by the firm and the leaver IT, facilities End of last day A question about whether the laptop, the phone, the token, or the card was returned, and a data-protection question about the device
Final pay statement and benefits position, sent to the leaver Payroll End of last day or in the cycle that follows A complaint about the final pay, a regulator question, and a question from the leaver's new employer that the firm would rather not be the second call on
Exit notes, written and shared with the leaver, held in the personnel file HR or line manager End of last day or the day after A one-sided record of why the leaver left, and a leaver who disagrees with the version on file
Reference position note, with named spokesperson and form of reference HR End of last week A reference given by the wrong person, in the wrong form, with the wrong content, and a leaver who finds out about it from a third party
Record retention schedule, with the artefacts kept, the artefacts destroyed, and the dates HR As part of the file closure A firm that keeps what it should have destroyed and destroys what it should have kept

Questions to Ask Before You Commit

The single owner. Who, by name, owns the offboarding file for a person who resigned this morning, and what is the evidence that they know it? A bad answer names a function, names a team, or says "everyone", and a worse answer is the silence that follows the question.

The access list. Can you produce, today, a complete list of the systems a named employee can reach, drawn from the joiner-mover-leaver record rather than from a reconstruction? A bad answer says the list is "mostly" complete, or that the record is held in a spreadsheet that has not been updated in a while.

The revocation evidence. For the last three leavers, can you produce the revocation log within an hour, with system, timestamp, and actor? A bad answer says the log is in the engineer's head, or that the engineer is on holiday.

The handover sign-off. For the last three leavers, is there a signed handover document, counter-signed by the incoming owner, naming the recurring work? A bad answer is a draft, a chat thread, or a memory.

The deviation path. For a leaver on garden leave, a leaver on long-term sickness, a leaver in a dispute, and a leaver who is a senior leader with a negotiated exit, what is the named process and who is the named owner of the deviation? A bad answer says "we would handle it case by case", which is a polite way of saying "we would improvise".

The final pay timing. How long from the last working day to the final payslip, and where is the timing set out, and who confirms it for each local rule? A bad answer is a guess, a habit, or a rule that someone read once.

The record retention. What is kept, what is destroyed, on what schedule, and where is the schedule? A bad answer is "we keep everything" or "we keep what we are told to keep", because both of those are true and neither is a process.

The reference policy. Who can give a reference, in what form, with what content, and on what basis? A bad answer is "the manager" or "HR", with no written policy, because the first reference request will land in the inbox of the person who is least able to answer it.

The contractor path. Is the contractor offboarding path the same as the employee path, and if not, what is the difference, and why? A bad answer is silence, because contractors are the group most often missed, and the reason they're most often missed is that the question was never asked.

The evidence audit. When did someone last audit the offboarding file of a leaver from a year ago, and what did they find? A bad answer is "we've never done that", because the first time the audit is run is the first time the gaps are visible.

What getting it wrong costs

The cost of a bad offboarding isn't the line item. The line item is the recovered laptop, the unpaid final week, the closed SaaS subscription. The cost is the question that arrives six months later, from a person who has just discovered an account the firm forgot to close, or from a client who has just discovered that the contract they thought was signed isn't, or from a regulator who has just discovered that a personnel file is missing a document that should have been there. None of these costs are visible in advance, and all of them are paid in time, in attention, and in the credibility of the firm with the party that finds the gap.

So the second-order cost is the firm's standing with the next person who leaves. A leaver who was treated well on the last day is a future source of referrals, of alumni goodwill, of a reference that's generous because it can be. A leaver who was treated badly is a future source of a question, a complaint, a regulatory letter, and a story that the next candidate will hear before they sign. The cost of getting the last day wrong is paid in the next hire, in the next negotiation, in the next conversation that the firm would rather not have.

The question to ask, before the next offboarding, isn't "what does the checklist say". It's "what does the file look like, a year from now, if a question arrives". If the answer is that the file is complete, evidenced, and findable, the process is working. If the answer is that the file is a wiki page, a Slack thread, and a memory, the process isn't a process, and the next question the firm gets will be the one it was not ready for.

When you are ready to go further

If the diagnostics in this piece point at a process you don't yet have, or a record you can't yet produce, the next step is to see how the published comparison work treats the tools and approaches that close the gap. HROpsLab is a review publication. It doesn't sell software, it doesn't run payroll, and it doesn't give legal or financial advice. The work it does is independent: a working definition of the problem, a worked evaluation of the options, and a written record of what each option is good at and where it falls short.

The path that most readers in this position take is to read the comparison work with a specific question in mind, then to take the question to the firm that built the offboarding in the first place. The HROpsLab side of that conversation is the published evaluation, the editorial position, and the answer to the question you've not yet been able to ask. The starting point, if you would like it, is the comparison and evaluation work on the site, written for the reader who owns the offboarding file and would like to own it with more confidence.


Frequently Asked Questions

Who owns the offboarding process in a typical firm

Ownership is split between HR, IT, the line manager, payroll, and the leaver, and the question that matters is which of those has the obligation to drive the others, not which of them is involved. In practice, the answer is usually HR or operations, with a named person, and the other parties are contributors. The risk in a multi-owner model is that "involved" isn't "responsible", and a process that names three owners has none. A useful test is to ask five people in the firm, separately, who owns the offboarding of a person who resigned this morning, and to compare the answers. If the five answers name the same person, you've an owner. If they name three people, or name a function without a person, you've a committee.

When should system access be revoked

The honest answer is that physical access and digital access are different decisions, and the right time for each depends on what you're protecting against. The badge should stop working at the end of the last day. High-privilege digital access should be reviewed at the start of the last day, or earlier, depending on the notice period and the relationship. Ordinary digital access is revoked on a defined schedule within hours of the last day. The longer the window between the decision to leave and the removal of access, the larger the surface for an action that's later regretted, and the right window is the one the firm can evidence a year later.

What do we do about personal devices used for work

The first step is to ask, in writing, before the last day, with a clear statement of what the firm will and won't do with the device. Asking on the last day is too late to act on the answer, and not asking leaves the question open. A reasonable position is to ask the leaver to remove company mail, company data, and company-issued accounts from the device, and to confirm in writing that they have done so. A more cautious position is to offer a remote wipe of the firm-managed profile, where one exists, and to accept that a full inventory of what is on a personal device isn't something the firm can do unilaterally.

How long should offboarding records be kept

Local rules on record retention differ, and the right answer is to confirm it for the relevant jurisdiction rather than to guess. The general shape is that payroll, benefits, and right-to-work records are kept for the period the local rule requires, that performance and disciplinary records are kept for a defined period, and that exit notes are kept for as long as the firm has a reason to keep them. A retention schedule, written down and reviewed, is what turns a pile of paper into a defensible file, and the cost of writing the schedule is small compared to the cost of the question that arrives when the schedule doesn't exist.

What happens to the leaver's email after they leave

The standard pattern is to keep the mailbox, redirect incoming mail to a named owner for a defined period, and tell senders once. Deletion is irreversible, and the leaver's mailbox is often the only place a particular thread, a particular contract, or a particular decision is recorded. The leaver has, in most places, a right to know what is kept and why, and a right to ask for the data to be corrected, and the firm has an obligation to be able to answer both questions. A practical move is to set an auto-responder that names the new contact and points senders at the right address, and to keep the mailbox for the period the local rule requires.

How do we handle a hostile exit

The right move is to separate the person from the process before the conversation, not after. The legal exposure of a sloppy offboarding is much higher after a dispute than after an amicable departure, and the documentation the firm wishes it had is the documentation it should have built before it knew it would need it. A pragmatic sequence is to confirm the decision in writing, set the last working day, suspend high-privilege access on a defined schedule, and have a single point of contact for the leaver so that the conversation has a shape. The temptation in a hostile exit is to act fast and to improvise, and the right move is the opposite: to slow down, to write things down, and to make sure the deviation from the standard process is itself documented.

Should we disable or delete accounts when someone leaves

The right answer is to disable first, and to delete later, and to keep the disabled account for the period the local rule requires. Disabling is reversible and is enough to remove the leaver's ability to act. Deletion is irreversible and removes the firm's ability to retrieve, and the leaver's mailbox in particular is often the only place a particular record sits. A related decision is what to do with the data the account can reach, and the right answer is that the data is more important than the account, and the data has its own retention schedule. Confirm the local rules on retention and on the leaver's right of access before the decision is made, because the right answer is local, not generic.

HROpsLab is an independent review publication for HR and operations leaders. We don't sell software, we don't provide payroll or legal services, and we don't act for vendors. Our work is editorial.

Share on X Share on LinkedIn

What to do next?

Explore More Articles

Dig deeper into HR Ops strategy, tools, and workflows built for real teams.

Browse the blog →
Join the HROpsLab Community

Connect with People Ops practitioners sharing real workflows, tools, and challenges.

Join now →