Employee Offboarding + Access-Revocation Kit

Excel / Google Sheets · 60-minute guide · Solo/SMB $49 · Team/MSP $99 · 14-day money-back guarantee

Employee Offboarding + Access-Revocation Kit: spreadsheet with overdue Slack and AWS revocation rows in red (fictional example data)

He left three weeks ago. Is he still in Slack and AWS? Most offboarding checklists stop at "disable email". This kit lists every login to revoke when someone leaves, with an owner, a due date and evidence for each, and turns anything overdue red.

Excel / Google Sheets workbook + a 60-minute offboarding guide (PDF + Markdown). No macros. Example data is fictional.

Read the free offboarding checklist first (the order to revoke access, with the vendor help pages).

Solo/SMB

$49

  • Offboarding Tracker workbook (blank + fictional example)
  • 42 revocation tasks across 11 areas, Day 0 to Day 30
  • SaaS Access Inventory, Equipment Log, Final Pay Log, Handover, Audit Summary
  • "Employee offboarding in 60 minutes" guide (PDF + Markdown)
  • One organisation, any number of its own staff

Buy Solo/SMB – $49

Team/MSP

$99

  • Everything in Solo/SMB
  • Multi-client workbook: Clients, Client Summary, printable Client Report
  • Up to 10 client organisations
  • 13 editable email & announcement templates (DOCX + TXT): IT request, access revoked, team announcement, client and vendor notices, equipment return, MSP intake and completion report

Buy Team/MSP – $99

14-day money-back guarantee: email labskaruna@gmail.com within 14 days of purchase for a full refund, no questions asked. (refund policy) · or buy on Gumroad

What the workbook tracks

Access Checklist sheet: one row per revocation task with owner, due date, done, evidence and status; overdue rows in red
SheetWhat it does
DeparturesOne row per leaver: last working day, access cut-off time, days since leaving, open and overdue tasks, equipment out, final-pay status.
Access ChecklistAn automatic block of 42 tasks per leaver: owner, due date, Done? (Yes / No / N/A), done date, evidence. Overdue rows turn red; done without evidence turns amber.
Extra Access ItemsOne row per app-specific account: CRM, domain registrar, social media, bank portal.
SaaS Access InventoryEvery app, login type, admin and billing owner, seats, cost, renewal date, how to remove a user. Apps outside single sign-on are flagged "YES - by hand".
Equipment Log · Final Pay LogEach laptop, phone, token and badge and its return; the final-pay due date your payroll team confirms (organiser only, no pay calculations).
Audit SummaryOpen, overdue, oldest overdue, done-without-evidence, equipment out, final pay overdue, a chart by category, per-leaver sign-off and a still-open list.
Audit Summary sheet with overdue counts highlighted (fictional example data)

The 11 areas covered

Each task cites the vendor help page it comes from (Google Workspace Admin Help, Microsoft Learn, Slack Help Center, AWS IAM User Guide, GitHub Docs, 1Password and Bitwarden support), checked 5 Oct 2026.

The 60-minute offboarding, in short

  1. Before the last day: confirm the cut-off time in writing, list every system on the SaaS Inventory, agree the handover, get work items out of the leaver's private vault.
  2. Minutes 0–20, identity first: Google Workspace (suspend, reset sign-in cookies, revoke app tokens, remove recovery details) or Microsoft 365 (reset password, sign out all sessions, block sign-in).
  3. Minutes 20–35, high-risk systems: deactivate Slack, remove AWS console access and deactivate access keys, remove from GitHub, suspend the password manager, remove finance logins.
  4. Minutes 35–55: every app outside SSO, then devices, badge and keys.
  5. Minutes 55–60: evidence, the "access revoked" note, Day 1 and Day 30 checkpoints.

Then Day 1 (mail, files, rotating secrets, notices), Day 7 (shared-vault passwords, ownership transfers, device wipes) and Day 30 (delete or archive accounts once data is kept, cancel seats, sign off).

For MSPs and IT providers

Team/MSP Client Report sheet listing one client's leavers and still-open access items (fictional example data)

The Team/MSP edition adds a client code to every sheet, a Client Summary across all clients and a Client Report you can print or export to PDF and attach to the completion email. Licence: up to 10 client organisations.

FAQ

Does it work in Google Sheets?

Yes. In Google Sheets use File > Import > Upload. No macros or scripts; formulas, dropdowns, filters and the red/amber flags carry over. Excel and LibreOffice work too.

Does it remove access for me?

No. It lists what to remove, who owns each step and by when, and records the evidence. You or your IT provider do the removal in each admin console, using the steps in the guide.

Is this legal advice? Does it cover final pay?

No. Final pay timing, unused leave, deductions and benefits differ by country and state. The Final Pay Log only records the due date your payroll team confirms. Check your local employment law.

Solo/SMB or Team/MSP?

Solo/SMB ($49) covers one organisation. Team/MSP ($99) is for IT providers, MSPs and consultants offboarding for up to 10 client organisations, and adds the multi-client workbook with per-client reports plus 13 editable email and announcement templates.

We don't use AWS (or we use Microsoft 365, not Google).

Mark those rows N/A or remove them from the Checklist Library. Every task is editable, and spare rows let you add your own systems.

Can I get a refund?

14-day money-back guarantee: email labskaruna@gmail.com within 14 days of purchase for a full refund, no questions asked.

Please read: Template and organiser only. Not legal, HR, payroll or security advice. Employment law (notice, final pay timing, deductions, benefits, references, record retention) differs by country and state: check your local employment law and take professional advice. Vendor steps were checked on 5 Oct 2026 and can change. Example data is fictional. Using the kit doesn't make your systems secure or compliant with any law or standard; it organises the work and records evidence. Not affiliated with Google, Microsoft, Slack, AWS, GitHub, 1Password or Bitwarden.