Free checklistNo email gate
What to check when an employee or contractor leaves
Most teams disable the email account and stop there. This checklist covers everything else. It is the same departure checklist VXSec works from, published in full, because gating a checklist helps nobody.
The short version: when someone leaves, check their identity account and sessions, email rules and delegation, files they own, shares they created, group and admin memberships, SaaS seats, client-side access, OAuth grants and API keys, automations they own, AI tools they connected, MFA devices, and every shared credential they knew. Transfer ownership before removing anything, and write down what you did.
1. Identity account
3 checks- Disable sign-in in Google Workspace or Microsoft 365. Do not delete the account yet; deletion destroys files, mail, and audit history you may need.
- Revoke all active sessions and app passwords, then reset the password.
- Remove the account from any SSO groups that grant downstream access.
2. Email rules and delegation
3 checks- Check forwarding rules and auto-replies; route mail to a role inbox with a dated note instead of a person.
- Review delegates, Send As, and Send on Behalf permissions on their mailbox and on shared mailboxes.
- Decide the mailbox end state: convert to shared, archive, or retain per policy, before any deletion.
3. Files and drives
3 checks- Transfer ownership of their files and any shared drives they own before the account is removed.
- Review shares they created, especially anything shared externally or to anyone with the link.
- Check personal-account syncing: Drive for desktop, OneDrive, or Dropbox clients on personal devices.
4. Groups, chat, and internal tools
3 checks- Remove them from groups and distribution lists, and reassign any groups they owned.
- Deactivate Slack, Teams, Notion, ClickUp, Asana, and other collaboration seats. Reassign owned pages, boards, and integrations.
- Check project tools for tasks, docs, or automations only they could edit.
5. SaaS seats and billing
3 checks- Work from your SSO or password manager list, not from memory. Every SaaS tool they used needs a decision.
- Reassign seats where their account owns data; cancel where it does not.
- Check whether they are the billing owner or admin anywhere. Billing owners are found the hard way when a card expires.
6. Client and external access
3 checks- List every client system they could reach: ad accounts, stores, CMSs, CRMs, analytics, hosting, repos.
- Remove their access from client systems, and notify the client where your agreement requires it.
- Check partner-granted access: Meta Business Manager roles, Shopify collaborator accounts, GitHub org membership.
7. OAuth grants, API keys, and automations
3 checks- Review third-party apps authorized under their account; revoking sign-in does not always revoke tokens, so revoke grants explicitly.
- Rotate API keys they created or knew, especially any keys in scripts, automations, or shared docs.
- List Zapier, Make, and n8n workflows running under their account. Recreate them under a service account before disabling anything, or workflows fail silently.
8. AI tools
3 checks- Check which AI assistants, agents, or meeting bots they connected to company email, drives, or CRMs.
- Remove their seats in AI tools and revoke connectors they authorized.
- Check for personal AI accounts used with company data; you cannot revoke those, but you can record the exposure.
9. Devices, MFA, and shared credentials
3 checks- Collect or wipe company devices, and remove company accounts from personal devices where policy allows.
- Remove their MFA devices and phone numbers from any shared or system accounts.
- Rotate every shared credential they knew: wifi, root accounts, social media, registrar, hosting. If it was in the password vault, assume they saw it.
10. Write it down
2 checks- Record what was checked, what was found, what was removed, and what was deliberately kept, with dates.
- Keep the record. It answers client, insurance, and legal questions months later.
Why offboarding fails: not because teams do not care, but because the list above lives in nobody's job description. The fix is a written checklist owned by one person and run the same way every time. If you want your version built from your actual stack, that is part of every Systems and Access Cleanup.
Dealing with a departure that already happened?
An Urgent IT Rescue sweeps all of the above fast, documents what was found, and closes access in an order that will not break your operations.