Employee IT Onboarding and Offboarding: The Checklist That Prevents the Horror Stories

Updated September 1, 2026

A small team in discussion around a table

Every business collects one of these stories eventually. The salesperson who left in March and was still reading the sales inbox in June. The new hire who spent three days watching orientation videos because nobody ordered her a laptop. The contractor whose login outlived his contract by a year. None of them involve a villain. They happen because arrivals and departures get handled from memory, and memory is the first thing to go in a busy week.

The fix is not software — or at least not first. It is a short written checklist that named people follow every time, in both directions. Here is what belongs on it, and why each line is there.

Onboarding starts the week before day one

The goal fits in one sentence: the new hire signs in at nine on day one and does actual work. Everything below serves that.

  1. Create the accounts when the offer is signed. Email, the identity account everything else hangs off — Microsoft 365 or Google Workspace for most small businesses — and membership in the groups the role needs. Do it the week before, not the night before. A new hire improvising with a personal Gmail because IT wasn’t ready is exactly how shadow IT starts.
  2. Grant the least access the job needs. The role’s permissions, not the whole department’s. Every extra permission handed out on day one is one that somebody has to remember to take away later, and later rarely comes. If the person needs more in week three, granting it takes five minutes.
  3. Write the hardware down. Laptop, phone, monitors, keys, access card — serial number, who has it, date issued, on one sheet everyone can find. You cannot collect what you never recorded.
  4. Give them a password-manager seat. With a business password manager from day one, credentials live in shared collections the company controls instead of a browser profile or a spreadsheet named passwords-FINAL. It is also what makes departure-day rotation a ten-minute job instead of an archaeology dig.
  5. Enroll two-factor authentication on day one, while you are already standing there. A fresh account with a fresh password and no second factor is what phishing kits are built for, and the whole job takes about twenty minutes.

That is the entire template. Put a name next to each line — IT creates the accounts, the manager requests access, whoever handles HR books the hardware handover — and most day-one chaos simply never happens.

Offboarding is a security event, not paperwork

Onboarding failures cost a few awkward days. Offboarding failures are where the horror stories come from, and the numbers say they are routine. In a 2022 Beyond Identity survey, 83% of former employees admitted they could still get into at least one account belonging to an old employer, and 74% of business leaders said their company had been harmed by a former employee getting in. Wing Security’s 2024 State of SaaS Security report found signs of former employees still holding access to company data at 63% of the organizations it analyzed. Payroll never forgets to stop a salary. Accounts are somehow harder.

The habit that matters most: when a departure is anything less than friendly, access is disabled during the exit conversation, not after it. Have IT briefed and ready, and flip the switch while the meeting is happening. The gap between “knows they are leaving” and “can no longer sign in” is the window in which customer lists walk out the door. For a resignation on good terms, the end of the last day is fine — but it happens that day, on a schedule, not “when someone gets to it.”

The offboarding checklist

  1. Disable the identity account first. Suspend sign-in at the Microsoft 365 or Google Workspace level. One switch cuts email, files, chat and every app connected through single sign-on — which is the argument for connecting apps through it in the first place.
  2. End the sessions. Disabling an account does not always log out devices that are already signed in. Force sign-out everywhere from the admin console, and wipe the work profile if you manage the person’s phone.
  3. Audit forwarding rules, delegates and connected apps. A quiet auto-forward to a personal address keeps mail leaking for months after the account dies — the same trick intruders use, which is why this check mirrors the first-hour checklist for a hacked mailbox. Review third-party app grants too: tools the person authorized against their account keep that access until you revoke it.
  4. Rotate every shared credential they knew. Wi-Fi password, alarm code, door code, the social media logins, anything in a shared vault they could see. If you gave them a password-manager seat on day one, this is a list you read, not a mystery you solve.
  5. Collect the hardware against the sheet. The one you wrote during onboarding. A company laptop in a drawer at an ex-employee’s house is company data waiting for a burglary.
  6. Transfer, then archive — do not delete. Hand the mailbox and files to the manager; in Microsoft 365 a shared mailbox does this without an extra license. Keep the disabled account for 30 to 90 days, because the question of where the contracts were kept always arrives about a month later.
  7. Sweep the apps that live outside single sign-on. The design tool, the mailing-list service, the accounting software — anything signed up for with a company card and an email address. This is the leak the SaaS statistic above is measuring.
  8. Record the date and who did each step. A checklist nobody signs is a suggestion.

Who owns the checklist

The standard small-business failure is not malice, it is diffusion: HR knew the person left, IT was never told, and the manager assumed accounts expire on their own. They do not. Give the checklist one named owner. Whoever runs payroll triggers it, because they always know about a departure. IT executes the technical steps. The manager confirms nothing business-critical was orphaned. The owner signs it and files it. Then put a quarterly access review on the calendar to catch whatever slipped through — walk every account and ask whether it still needs to exist. It slots naturally into the broader small-business security checklist, and it is the part most often skipped.

When the checklist should be someone else’s job

Managed IT turns all of this into routine. “New hire starts Monday” becomes a ticket; “departure Friday at 2 p.m.” triggers the disable-rotate-collect sequence with nobody improvising. Koadi provides managed IT for small offices — ongoing support, remote and on-site — with onboarding and offboarding handled as standard work; what that costs is covered honestly here. If you only need the pieces set up once, post the job free: vetted, identity-verified technicians pick it up, you set a fixed price or take bids, and payment sits in escrow until you approve the work. Remote help covers every US state; on-site visits come through local techs.

Frequently asked questions

How fast should you disable a terminated employee's accounts?
For a termination or any departure that isn't friendly, disable access during the exit conversation itself — have IT ready before the meeting starts. For a normal resignation, the end of the last working day is fine. Either way it happens on a schedule, and remember that disabling an account doesn't always end sessions already signed in; force a sign-out everywhere.
Should you delete a former employee's email account or keep it?
Keep it, disabled, for 30 to 90 days. Transfer the mailbox to the manager first — in Microsoft 365 a shared mailbox does this without an extra license. Deleting on day one feels tidy right up until someone asks where the contracts were kept. Delete only after the retention window passes quietly.
What should an IT offboarding checklist include?
Disable the identity account, force sign-out of all active sessions, audit mailbox forwarding rules and connected third-party apps, rotate every shared password the person knew, collect hardware against the record made at onboarding, transfer files and email to a manager, sweep apps that sit outside single sign-on, and record who completed each step and when.
Who should be responsible for employee IT onboarding and offboarding?
One named owner, with the work split three ways: whoever runs payroll triggers the checklist because they always know about departures, IT executes the technical steps, and the manager confirms nothing critical was orphaned. In very small businesses the owner is often the office manager — or a managed IT provider, who runs the same checklist as routine.

Still stuck?

Post this problem on Koadi — a vetted technician picks it up in minutes, and you don't pay until it's fixed.

Get a tech on it
← All fix-it guides