Most small businesses handle hiring and departures the same way: someone in HR sends an email, someone else sets up a laptop, and everyone hopes nothing was missed. It works fine until the week you hire three people at once, or until a salesperson leaves for a competitor and you realize nobody knows what was in their personal file sync folder.
The problem isn’t that these tasks are hard. It’s that they’re spread across HR, operations, and whoever handles IT, with no single list holding them together. Nothing goes wrong on any given Monday; it goes wrong slowly, in the form of accounts that were never closed, licenses you’re still paying for, and a file share that only a former employee had the keys to.
This is a runbook you can copy. Two lists, a handful of decisions to make once, and a rule about timing that matters more than any tool you could buy.
Decide These Four Things Once
Before either checklist is useful, answer these. They’re the questions that stall an offboarding at 4:45 on a Friday.
Who owns the mailbox when someone leaves? Usually a manager, converted to a shared mailbox or delegated for a fixed window. Decide the default now so it isn’t a negotiation each time.
How long do you keep a departed employee’s data? Pick a number, whether 30, 60, or 90 days, and apply it consistently. “Forever, just in case” is how you end up paying for licenses on accounts nobody has touched in three years.
Where does company data actually live? If the honest answer includes “some of it is in people’s personal Google Drives,” fix that before you write any checklist. You cannot offboard data you can’t see.
Who has authority to cut access immediately? For a contentious departure, waiting for a manager to reply to an email is the gap that hurts. Name one person who can act on their own.
The Onboarding Checklist
Work this in order. The sequencing matters: accounts before equipment, because you want to hand someone a laptop that already signs in.
Before Day One
- Create the user account in Microsoft 365 or Google Workspace
- Assign a license that matches the role, not the most expensive one available
- Add them to the right security groups; this is what governs file access, so get it right the first time rather than granting access ad hoc later
- Enroll multi-factor authentication, or set it to enroll on first login
- Order or image the laptop, and enroll it in device management before it leaves your hands
- Set up accounts in line-of-business systems: accounting, customer relationship management (CRM), enterprise resource planning (ERP), shop floor systems, whatever the role touches
- Add to phone system, extension, and any shared voicemail
Day One
- Walk them through MFA setup in person if it wasn’t pre-enrolled
- Show them where files actually belong, the single most valuable ten minutes of onboarding
- Cover the basics: how to spot a phishing email, who to call when something looks wrong, and the rule that nobody from IT will ever ask for their password
- Set expectations on personal device use and what may not be installed
- Have them acknowledge your acceptable use and AI tool policies in writing
First Two Weeks
- Confirm they have everything they need; access gaps surface as workarounds, and workarounds become shadow IT
- Remove any temporary elevated access granted during setup
- Record the account, license, and equipment in your inventory
That last item is the one everyone skips, and it’s the one that makes offboarding possible. If you don’t know what someone was given, you can’t reliably take it back.
The Offboarding Checklist
The rule that matters most: access ends when employment ends, not when IT gets around to it. Not end of week. Not “after we get the laptop back.” The same hour.
The First Hour
- Disable the account, and disable rather than delete. Deleting destroys the mailbox and file ownership you still need.
- Revoke active sessions and sign-in tokens. Disabling an account does not always kick out a session that’s already logged in on a phone or home computer, and this is the step most often missed.
- Reset the password and remove their MFA methods
- Remove from the VPN (virtual private network) and any other remote access
- Change shared credentials they knew: Wi-Fi passwords, shared vendor logins, the alarm code
- Disable their badge and building access
- Forward the phone extension
The First Day
- Convert the mailbox to shared, or delegate to their manager for the retention window you decided on
- Transfer ownership of files, cloud drives, and any documents shared from their account
- Reassign anything they owned in your CRM, ticketing, or project systems
- Remove them from distribution lists, shared mailboxes, and group chats
- Collect the laptop, phone, hardware tokens, and any equipment at their home
The First Week
- Check the accounts your identity system doesn’t manage. This is where the real gaps live: bank and payment portals, state and vendor filing sites, the domain registrar, social media, shipping accounts, freight portals, and any supplier system they logged into directly.
- Reclaim the license and stop paying for it
- Wipe and re-image the returned device before it goes to the next person
- Update your inventory to close the loop
The Part Nobody Plans For
Departures on good terms are the easy case. Two others are worth preparing for specifically.
The employee going to a competitor. Before the account is disabled, check whether there was unusual file activity in the preceding weeks: bulk downloads from a CRM, a sync folder copied to a personal drive, large outbound attachments. Most cloud platforms log this, and the log is far easier to read while the account still exists. If your business has anything genuinely proprietary (customer lists, pricing, drawings, process documentation), decide in advance what you’d want to know and confirm you’re actually capturing it.
The employee who was the only one who knew something. Every small business has at least one system where one person held all the knowledge and, often, the only login. The shipping software. The machine that runs the label printer. The spreadsheet everything depends on. The time to find these is not during someone’s last week. Walk your systems now and mark any where exactly one person has access.
Role Changes Count Too
The transfer nobody offboards is the internal one. Someone moves from the warehouse to the office, or from sales to operations, and gains new access while keeping everything they had before. Do that a few times over a few years and you have people with access to systems they haven’t touched since 2023.
Treat a role change as an offboarding from the old role and an onboarding into the new one. Remove first, then add. It takes ten extra minutes and prevents the slow accumulation that makes a real access review painful later.
Making It Stick
Checklists fail when they live in someone’s head. Three things make the difference:
- One shared list, one owner. Whether it’s a ticket template, a shared document, or a task in your HR system, it needs to exist somewhere other than a person’s memory, and someone needs to be responsible for it being complete.
- HR triggers IT, not the other way around. IT should not be discovering departures through hallway conversation. Whoever processes the paperwork should also open the offboarding checklist, the same day.
- Spot-check quarterly. Pull a list of active accounts and compare it to your current roster. If names appear that shouldn’t, your process has a leak worth finding.
Where a Technology Partner Fits
Onboarding and offboarding are exactly the kind of work that gets done well when things are calm and badly when they aren’t, which is precisely when it matters. Automating provisioning, enforcing consistent group membership, and making offboarding a single repeatable procedure removes the judgment calls from a moment that rarely has time for them.
If you’d like a clear picture of where your accounts, access, and equipment actually stand, our free Technology & Growth Review is a 60-minute session covering cybersecurity, technology, and AI readiness, and you leave with a written action plan you can execute with or without us.