The offboarding checklist that covers Workspace and devices
Most access leaks are not movie-plot hacks. They are incomplete offboarding. Use this checklist to close email, Drive, SaaS, and laptops on the last day.
When someone leaves, the business should feel it as a people event, not a security incident six months later. Incomplete offboarding is one of the most common and fixable failures in growing companies.
This checklist assumes Google Workspace as the identity hub and company-managed devices under MDM. Adapt names if you run Microsoft 365. The discipline is the same.
Before the last day
- Confirm last working day and whether access ends at end of day or immediately
- Identify systems outside SSO (payroll, banking, social accounts, domain registrar, cloud consoles)
- Decide mailbox and Drive disposition: transfer, share with manager, or legal hold
- Schedule collection of laptop, keys, badges, and hardware tokens
- Assign an owner for the checklist (not “whoever remembers”)
Identity and Google Workspace
- Suspend or delete the user per policy (suspend first if you may need a clean recovery window)
- Remove from all groups, including nested groups that gate tools
- Transfer Drive files and shared drive memberships
- Reassign calendar events and room ownership if needed
- Reset or remove mailbox delegates and vacation responders intentionally
- Revoke application-specific passwords and third-party OAuth apps
- Remove as admin from Workspace and any connected admin roles
- Check shared mailboxes and Google Groups moderation rights
SaaS and cloud beyond Google
Walk the app inventory, not your memory:
- SSO apps (confirm deprovisioning actually removed access)
- Apps with separate logins (finance, marketing automation, code hosts)
- Cloud providers (AWS, GCP, Azure) and root account contacts
- Password vault entries owned by the leaver
- Vendor portals and customer systems where they were a named admin
If you lack an inventory, build one during this offboarding. Pain is a good teacher.
Devices and endpoint protection
- Confirm device inventory record and serial number
- Collect hardware or ship a label for return
- Use MDM to lock, wipe, or release depending on whether the device returns
- Verify antivirus / EDR agent is uninstalled or the seat is retired after wipe
- Remove device from MFA methods (phone prompts should not go to a former employee)
- Rotate any Wi-Fi PSKs or shared secrets the person knew if your network still uses them
Personal phones with company email need a defined path: remove the account, container wipe, or full enterprise wipe based on policy you published before hiring them, not during the exit meeting.
Communication and business continuity
- Update org charts, on-call rotations, and escalation lists
- Redirect customers and vendors if this person was a primary contact
- Change shared meeting host accounts and webinar licenses
- Review open tickets or projects for orphaned ownership
Aftercare (the next 7 days)
- Spot-check that login attempts fail for critical systems
- Confirm billing seats reduced where licenses are named
- Store the completed checklist with HR records retention rules
- Note process gaps for the next revision of the runbook
Why this belongs in managed IT scope
Offboarding is a process problem, not a heroics problem. Companies that only handle it when someone resigns will keep making expensive exceptions. Building the checklist, wiring it to Workspace and MDM, and training managers is classic stabilization work.
If you want a runbook tailored to your stack, contact us. Bring a rough list of tools and whether devices are already under management. We can turn this into a one-page procedure your team will actually use.
Need security-first IT management?
We help growing businesses run cloud, endpoints, infrastructure, and support with security built in.
Talk to us