When someone leaves, the main email account is rarely the problem: everyone remembers that one. The risk sits in the logins nobody wrote down, like the chat workspace, the cloud console and its API keys, the code host, the shared vault, the bank portal, and every SaaS tool with its own password. This is a free, vendor-sourced checklist for revoking access in the right order, with a simple spreadsheet you can build yourself. Everything here is general operational information, not legal advice: notice, final pay and record-keeping rules depend on your country, state and the employment contract.
Before the last day
- Agree the cut-off in writing. Confirm the last working day and the exact access cut-off time, with the time zone, between HR and the manager.
- List every system the person can reach. Keep a simple inventory of every app: login type (single sign-on or its own password), admin owner, billing owner and how to remove a user. Apps with their own password are the ones that get missed, because switching off the main account doesn't touch them.
- Agree the handover: clients, recurring tasks, documents, and any shared logins the person owns.
- Empty the private vault. If you use a business password manager, ask the leaver to move work items from their private or employee vault into a shared company vault first. 1Password's offboarding guidance is not to delete the account until the employee vault has been transferred.
Day 0: the order that matters
Do this at the cut-off time, in one sitting, with whoever holds admin rights.
1. Identity first
- Google Workspace: Google's checklist for a departing employee is to wipe the account from mobile devices, remove the recovery email and phone, change the password, revoke OAuth app tokens, reset sign-in cookies, revoke security keys and app passwords, and finally delete the account once you've moved the data you want. Google notes that a password change revokes only some OAuth tokens, so review authorized apps too. Suspending the user blocks sign-in while you keep the data.
- Microsoft 365: Microsoft's first step is to reset the password and select Sign out of all sessions. Then block sign-in, but Microsoft says blocking "can take up to 24 hours to take effect", so the password reset comes first. You can also turn off email apps for the mailbox in the Exchange admin center.
2. Systems that don't always follow your identity provider
- Slack: deactivate the member. Slack says deactivated people are signed out on all devices and removed from all channels, and their messages and files are kept. An "inactive" member (no use for 28+ days) still has access, so don't rely on inactivity.
- AWS: remove console access (the IAM user, or their assignment in IAM Identity Center) and deactivate their access keys. Keys work without a console password. AWS's guidance for leavers is to find the credentials they used and make sure they no longer work: ideally delete them, and at least change the password or deactivate the keys. The IAM console's "Access key last used" column helps you check. If the person knew the root password or other shared secrets, change those too.
- GitHub: remove them from the organisation. If membership is managed by SCIM, deprovision them in your identity provider instead. Remove them as an outside collaborator too. GitHub notes that removed members lose access to private forks but may still have local copies, so ask in writing for local copies to be deleted. Rotate deploy keys and CI secrets they could read.
- Password manager: suspend (1Password) or revoke (Bitwarden) the member. Delete only after vault items are handled.
- Finance: remove bank, payments and expense-tool logins, and cancel company cards in their name.
3. Everything else
- Every app on your inventory that has its own password: CRM, domain registrar, social media, vendor portals. Each needs its own removal and its own evidence.
- Devices: collect laptops, phones, hardware keys and chargers, and log the asset tags. If a device isn't returned, remote lock or wipe it through your device management tool.
- Building: deactivate the badge or fob, collect keys, then change shared door, alarm and Wi-Fi codes on Day 1.
Day 1, Day 7, Day 30
| When | What |
|---|---|
| Day 1 | Mail forwarding, delegate, auto-reply or shared mailbox, per your policy · hand Drive / OneDrive files to the manager · reassign Slack apps and workflows the person owned · rotate deploy keys, CI secrets and tokens · review cloud activity after the cut-off · announce internally and tell clients and vendors their new contact · payroll confirms the final pay date against the contract and local law |
| Day 7 | Change passwords in shared vaults the person could open (admin, finance and email logins first) · transfer ownership of dashboards, automations and billing-admin roles · back up, wipe and reassign returned devices |
| Day 30 | Delete or archive accounts once you've kept what you need. Google: a deleted user can be restored for up to 20 days. Microsoft 365: check holds first; mail is kept 30 days after the licence is removed. Then delete the password-manager member, cancel freed seats, and sign off the record |
A free tracking sheet you can build in 10 minutes
One row per leaver per task. Columns: Leaver, System, Task, Owner, Due, Done?, Evidence, Status. In the Status column (H2), with Due in E2 and Done? in F2:
=IF(F2="Yes","Done",IF(F2="N/A","N/A",IF(E2="","No date",IF(E2<TODAY(),"OVERDUE","Open"))))
Then add a conditional formatting rule on the whole table with the custom formula =$H2="OVERDUE" and a red fill, and another, =AND($F2="Yes",$G2=""), in amber on the Evidence column, so "done but no proof" stands out. For evidence, record a ticket number, the file name of an admin-console screenshot, or an audit-log export, plus who did it. This works the same in Excel and Google Sheets.
Two things to keep separate
- Involuntary departures. For a dismissal or redundancy, agree the timing of the access cut-off with HR and your legal adviser before the meeting. A checklist can't tell you how to run that conversation.
- Final pay and benefits. Timing, payment for unused leave, deductions (including for unreturned equipment) and benefit continuation differ by country, state and contract. Record the date payroll confirms; don't use an IT checklist to decide what's owed.
If you'd rather not build it: the Offboarding Kit (optional)
We made a ready-made version: the Employee Offboarding + Access-Revocation Kit. Add a leaver and 42 tasks appear (Google Workspace, Microsoft 365, Slack, AWS, GitHub, password managers, SaaS apps, devices, payroll and benefits, building access), each with an owner, a due date for Day 0 to Day 30, a Done?/evidence column and red overdue flags. It also includes a SaaS Access Inventory, an Equipment Log, a Final Pay Log (organiser only), an Audit Summary, and a 60-minute guide. Solo/SMB is $49. Team/MSP is $99 and adds a multi-client workbook for up to 10 client companies and 13 email and announcement templates. It comes with a 14-day money-back guarantee. You don't need it to use the checklist above.
Sources
- Google Workspace Admin Help – Maintain data security after an employee leaves
- Google Workspace Admin Help – Delete or remove a user from your organization
- Microsoft Learn – Remove a former employee (overview)
- Microsoft Learn – Step 1: Prevent user sign-in and block access
- Slack Help Center – Deactivate a member's account
- Slack Help Center – Inactive vs deactivated billing status
- AWS IAM User Guide – Find unused AWS credentials
- GitHub Docs – Removing a member from your organization
- 1Password Support – Offboard a team member
- Bitwarden Help – Temporarily revoke access
- NPSA (UK) – Exit procedures guidance (PDF)
Related guides
Published 2026-10-05 by Karuna Labs. Our tools check file structure and checksums; always review outputs (and payment files in your bank's preview) before relying on them. This is general information, not financial, tax or legal advice.