Every time someone leaves your company, a small window of risk opens. Their laptop is still logged in, their software seats are still billed, and their access to email, cloud drives and internal tools is still live. A solid IT offboarding checklist closes that window quickly and predictably. Get it wrong and you leak money through unused licences and unrecovered hardware, and you leave doors open for data loss. This guide walks through the employee offboarding IT steps that actually matter, gives you a checklist you can copy, and shows how to automate the whole thing so nothing slips.
Why offboarding gaps cost money and create security risk
Departures are messy. HR knows the leaving date, the manager knows what the person worked on, and IT is often told last - sometimes after the person has already gone. In that gap, three things quietly go wrong.
Money leaks. A misplaced laptop, monitor or phone is pure lost capital, and it is surprisingly common when nobody formally reclaims hardware. Software is worse: paid seats for design tools, IDEs, CRMs and collaboration suites keep renewing month after month for people who left last quarter. Nobody notices because the invoice total barely moves.
Security exposure grows. An account that is still active is still a target. Former employees, or an attacker who phished their credentials, can reach data long after the last day. Personal devices that were never wiped keep a copy of company data indefinitely. Without an IT offboarding process that revokes access on the day, you are trusting goodwill to protect your systems.
You lose the record. When an auditor, a security review or a departing employee dispute asks "what did this person have, and when was it removed?", you need an answer. Ad-hoc offboarding done over chat leaves no trail.
The IT offboarding checklist
Here is the core employee offboarding IT sequence. Work top to bottom - access first, because that is the security-critical part, then hardware, licences and records.
- Revoke access and deprovision SSO. Disable the account in your identity provider first. With SSO and SCIM in place, one action cascades to every connected app. Kill active sessions, revoke API tokens and app passwords, and remove the person from privileged groups and shared vaults.
- Reclaim or account for every device. List everything assigned to the person - laptop, phone, monitors, docks, security keys, peripherals. Check each item back into stock, or record what happened to it: kept by the employee, sold, gifted or written off. Anything you cannot physically recover needs a disposal record with a value against it, not a shrug.
- Wipe or lock devices via MDM. For any device you cannot collect in person, trigger a remote lock or wipe through your MDM (Jamf, Intune, Mosyle or Kandji). For BYOD, do a selective wipe that removes company data without touching personal files. Confirm the command actually completed.
- Reclaim software licences and seats. Remove the person from every paid tool and free the seat so it can be reassigned or the subscription downsized. This is where the recurring savings live. See our guide to software licence management for how to track seats properly year-round.
- Transfer data and ownership. Reassign owned documents, shared drives, code repositories, calendars and customer records to a manager or successor before the account is closed. Set up mail forwarding or an auto-reply if clients still write to that address.
- Close out accounts. Once data is transferred, deactivate or delete the mailbox and remaining accounts per your retention policy. Cancel or reassign any personal corporate cards, phone plans and vendor logins tied to the individual.
- Keep an audit record. Log every step with a timestamp and who performed it: access revoked, devices returned or disposed, licences freed, data transferred. This closes the loop and is your evidence if anyone ever asks.
The copy-and-keep version
Paste this shorter list into your ticket template or wiki and tick each item on the leaving date:
- Disable identity provider account and end all sessions (SSO/SCIM)
- Revoke tokens, app passwords and privileged group membership
- Reclaim laptop, phone, monitors, keys and peripherals
- Record disposal for anything not returned (kept / sold / gifted, with value and approver)
- Remote lock or wipe any uncollected or personal device via MDM
- Free every paid software seat and note the saving
- Transfer documents, drives, repos and mailbox ownership
- Set mail forwarding or auto-reply
- Close or delete remaining accounts per retention policy
- Confirm the full audit record is complete and timestamped
How to automate the IT offboarding process
A checklist is only as reliable as the person remembering to run it. The way to make offboarding foolproof is to trigger the whole sequence from one place and let your systems do the work.
SimpleAMS turns the list above into one-click offboarding from the person's profile. In a single action it deactivates the account, reclaims every assigned device - checking each one back into stock or recording it as kept, sold or gifted with a full disposal record (type, price and approver) - frees the software licence seats, preserves the complete checkout history, and writes it all to the activity log. Nothing depends on someone remembering step seven.
It also connects to the rest of your stack. Our Finch HR connector means offboarding can be HR-triggered: when someone is marked as leaving in your HR system, the workflow starts automatically. MDM sync with Jamf, Intune, Mosyle and Kandji lets you fire a remote lock or wipe from the same screen. SSO and SCIM deprovisioning cuts access across connected apps, and every action lands in an audit trail you can hand to a security reviewer without apology.
If you are still doing this by hand, or wrestling with a self-hosted tool, our IT asset management guide covers the fundamentals, and our SimpleAMS versus Snipe-IT comparison shows what a hosted, offboarding-first approach changes day to day.
You can see the full workflow on the features page, and plans start from EUR 29 per month - explore them on pricing. Recover every device, licence and seat, every time someone leaves.