Every Organization Needs a Digital Offboarding Checklist

When an employee, contractor, volunteer, board member or vendor leaves, access must end without taking essential information and relationships with them.

A person leaves an organization, and someone remembers to collect the laptop.

But what about the email account? Cloud files? Shared passwords? Website administration? Social-media access? Recurring meetings? Vendor portals? Authentication applications? Customer relationships?

Digital offboarding is not one action. It is a coordinated process that protects the organization while preserving its ability to operate.

That process should be documented before the next departure occurs.

If You Read Only One Thing

Digital offboarding must accomplish two things at once: close the departing person’s access and preserve the organization’s information, relationships and ability to operate.

Your Action Steps

Create a repeatable offboarding checklist covering:

  1. Accounts and systems

  2. Email and calendars

  3. Files and ownership

  4. Devices and storage media

  5. Password-manager access

  6. Shared credentials and recovery methods

  7. Websites and social media

  8. Financial and vendor portals

  9. Customer and partner relationships

  10. Final review and documentation

Assign a primary owner, an authorized backup and a completion deadline for each responsibility.

Offboarding Begins Before the Last Day

Whenever possible, begin the transfer before the person leaves.

Identify:

  • Current responsibilities

  • Active projects

  • Important files

  • Accounts they administer

  • Meetings they organize

  • Vendors and customers they communicate with

  • Devices they use

  • Software licenses assigned to them

  • Shared credentials they know

  • Recovery methods connected to their phone or email

  • Work that has not been documented

The goal is not to capture every minor action. It is to ensure that important work, access and knowledge have a clear destination.

Block Access—But Do Not Delete Blindly

Removing an account too quickly can destroy information or interrupt operations.

An organization may need to:

  • Block sign-in

  • Revoke active sessions

  • Reset credentials

  • Preserve the mailbox

  • Transfer files

  • Reassign ownership

  • Forward new messages

  • Convert an individual mailbox into a shared mailbox

  • Retain records for legal, regulatory or operational reasons

Microsoft’s offboarding guidance recommends blocking access, preserving mailbox contents, addressing mobile devices, transferring OneDrive and Outlook data and determining how email should be handled before deleting the user or license. Review Microsoft’s former-employee guidance.

Deleting first and asking questions later can create a second crisis.

Transfer File Ownership

Files should not disappear because they were created in an individual employee’s personal workspace.

Before departure:

  1. Identify important files and folders.

  2. Determine who currently owns them.

  3. Transfer ownership where the platform permits it.

  4. Move organizational records into an organization-controlled location.

  5. Confirm that the successor can open and use them.

  6. Preserve required historical versions.

  7. Remove access that is no longer appropriate.

A shortcut or shared view is not always ownership. Confirm what will happen if the original account is suspended or deleted.

Decide What Happens to Email

A departed person’s email address may continue receiving messages from:

  • Customers

  • Donors

  • Vendors

  • Professional partners

  • Government agencies

  • Subscription services

  • People who were never informed about the transition

Depending on the organization’s needs and legal obligations, email may need to be:

  • Preserved

  • Forwarded

  • Converted into a shared mailbox

  • Monitored temporarily

  • Replaced with an automatic reply

  • Eventually deleted

Forwarding handles new messages. It does not automatically transfer the full history, calendar, contacts or institutional knowledge contained in the original account.

Reassign Calendars and Recurring Responsibilities

A departure can leave behind:

  • Recurring meetings

  • Room reservations

  • Webinar ownership

  • Appointment calendars

  • Shared scheduling pages

  • Automated reminders

  • Renewal dates

  • Publication schedules

  • Billing deadlines

Cancel, transfer or recreate these items intentionally.

Do not wait until a customer cannot book, a meeting link fails or a renewal lapses.

Recover Devices and Remove Organizational Data

The checklist should cover:

  • Laptops

  • Phones

  • Tablets

  • Security keys

  • External drives

  • Memory cards

  • Access cards

  • Printers or scanners

  • Home-office equipment

If the person used a personal device, determine how authorized organizational information will be removed without accessing or destroying unrelated personal data.

Organizations should establish this process in advance through policies and agreements rather than improvising after someone leaves.

Rotate Shared Credentials

Removing an individual account does not invalidate every credential the person knew.

Review:

  • Shared passwords

  • Wi-Fi credentials

  • Alarm codes

  • API keys

  • Recovery codes

  • Social-media passwords

  • Website administration

  • Domain registration

  • Financial portals

  • Vendor dashboards

  • Password-manager collections

  • Multifactor-authentication devices

Whenever possible, replace shared accounts with individual accounts and role-based permissions. Individual access is easier to revoke and audit.

Remember Contractors, Volunteers and Vendors

Offboarding is not limited to employees.

Organizations should also plan for departures involving:

  • Independent contractors

  • Consultants

  • Temporary staff

  • Interns

  • Board members

  • Committee members

  • Volunteers

  • Managed service providers

  • Bookkeepers

  • Marketing agencies

  • Website developers

A person can retain significant access without ever appearing on the employee roster.

Document Completion

An offboarding checklist should record:

  • The person leaving

  • Their role

  • Final date

  • Checklist owner

  • Systems reviewed

  • Access removed

  • Information transferred

  • Devices returned

  • Credentials rotated

  • Exceptions requiring follow-up

  • Completion date

The record should avoid containing passwords. It should document that the responsibility was completed.

Integrate Offboarding With Organizational Governance

NIST’s Cybersecurity Framework 2.0 recommends integrating cybersecurity considerations into human-resources processes, including onboarding, role changes and offboarding. Review NIST’s CSF 2.0 implementation examples.

That principle applies even when an organization has no dedicated IT or HR department.

Someone must still own the process.

A five-person business, nonprofit board, professional practice or volunteer organization may have fewer accounts than a corporation—but the departure of one essential person can have a greater proportional effect.

Prepare Before the Next Departure

Do not wait until someone resigns, retires, becomes ill or must be removed urgently.

Build the checklist now.

The organization should know:

  • What must be secured

  • What must be preserved

  • Who performs each action

  • Who verifies completion

  • What cannot be deleted immediately

  • What happens when circumstances are urgent

Effective offboarding is not merely an administrative conclusion. It is part of organizational security, continuity and resilience.

Resources Outside Haven Smith & Company

Haven Smith & Company Resources

Haven Smith & Company provides education, organization and practical planning guidance. Organizations should consult their IT, cybersecurity, human-resources and legal professionals when appropriate.

Previous
Previous

Before You Accept Another School App: Seven Questions to Ask About Your Child’s Data

Next
Next

Your Gmail, Google Photos, and Drive Need an Inactivity Plan