Skip to main content
株式会社オブライト
Business DX2026-08-1311 min read

Employee Offboarding IT Checklist for Small Business (2026)

A leftover ex-employee account is a common breach entry point. This guide covers device recovery, data safeguards, handovers, and SaaS cost cuts on departure.


Offboarding is the set of procedures a company follows when an employee leaves through resignation, transfer, or the end of a contract: recovering loaned equipment, disabling accounts, and handing over data without gaps. The most common entry point for a data leak or account misuse at a small business is not a sophisticated attack — it is simply a former employee's login that was left active. This guide lays out a before, day-of, and one-week-after timeline with a checklist, built for companies with no dedicated IT staff.

Why offboarding gets neglected

Onboarding is about making things work, so a mistake shows up immediately. Offboarding is about making things stop working, and a missed step causes no visible problem — until it does. That asymmetry is the main reason offboarding slips down the priority list. At small companies the gap between a resignation decision and the last working day is often short, and IT tasks are typically the last thing handled while everyone focuses on handover documents.

- Accounts left active: email and cloud storage remain reachable after the person leaves
- Unreturned equipment: customer data and stored credentials sit on a laptop or phone that is now treated as personal property
- Knowledge locked in one person: SaaS subscriptions and passwords set up under an individual account are never handed over
- SaaS charges that keep running: the account stays active and the monthly bill goes unnoticed

The fundamentals of account management itself are covered in Account, password and MFA management for small businesses, which is worth reviewing alongside this guide as a baseline. For the cloud-access side specifically, see Have you disabled departed employees cloud accounts?.

What to recover: equipment and building access

The items most often missed are the ones that are not part of daily routine. Without an inventory of what has been loaned out, there is no way to know what should come back in the first place. Tying this list into your regular IT asset management ledger removes the need to rebuild it from scratch every time someone leaves.

CategoryItems to recoverCommon blind spots
PC and peripheralsLaptop, monitor, mouse, power adapterSpare units kept at home; remote-work equipment
MobileCompany phone, tablet, mobile Wi-Fi routerSwitching a work number off a personally contracted SIM
SIM and line contractsCompany SIM cards, corporate line cancellationLeaving a line uncancelled just keeps billing monthly
Building accessEntry cards, staff ID, office or warehouse keysAccess cards for other sites at multi-location companies
OtherCorporate credit card, company seal, parking passCard details stored inside an expense-reporting app

Reissuing recovered equipment without wiping it first hands the previous employee's data straight to the next person. Always follow the order recover, wipe, test, store or reissue, and log the wipe date in the asset ledger.

Preventing data walkout, and keeping a record

The window between a resignation decision and the last working day is when the risk of data walking out the door is highest. Rather than relying purely on trust, pair prevention with a minimal amount of logging.

- Review external sharing links: list any external share links the departing employee created in cloud storage, and disable any not needed for handover
- Check for unusual download or print activity: review admin console and file-server logs for abnormal activity after the resignation was decided
- Restrict personal USB drives and personal cloud accounts: temporarily limit connecting external storage or uploading to personal cloud accounts from company devices once resignation is confirmed
- Put the confidentiality reminder in writing: confirm what may not be taken, in a signed document rather than a verbal conversation, with both parties' signatures on file

Simply being able to review these logs acts as a deterrent on its own. The goal is not heavier surveillance but making it clear that activity is visible — apply this only to employees who are actually leaving, and avoid going further than necessary, since overreach damages trust with the rest of the team.

Handing over work data and email

Deleting an account immediately can also delete ownership of in-progress emails with clients or files on a shared drive. Make handover before disabling a strict rule rather than deleting first.

ItemHow to hand it overWatch for
EmailForward to the successor, or set a timed auto-reply plus read accessPersonal messages are mixed in — avoid handing over the full mailbox verbatim
Cloud storageTransfer file and folder ownership to a shared account or successorFiles tied to a personal account are the ones most often missed
Business systemsReassign in-progress tasks and projects with a named successorCheck whether approval workflows still list the departing employee as approver
Client contactsConsolidate business cards and contact lists into a shared toolFix cases where a contact exists only on someone's personal phone

For email, a period of suspension is usually more practical than immediate deletion. Block logins during the suspension period while keeping the mailbox readable to the successor, then delete once the handover has been confirmed — this avoids the risk of losing data outright.

Cancelling SaaS licences and cutting cost

Offboarding is also one of the few moments that naturally cuts spend. SaaS licences tied to an individual often auto-renew the month after they leave without anyone noticing. At companies without a full inventory of active subscriptions, these missed cancellations can quietly add up to hundreds of thousands of yen a year.

- List every SaaS licence the departing employee used, and decide for each: cancel, downgrade, or transfer to another team member
- For annual contracts, check the cancellation deadline in advance — how many days before renewal a request must be filed
- For per-seat billed team tools, revisit the seat count whenever a role changes hands
- Include guest accounts issued to contractors in the same inventory pass

If you do not already keep an ongoing inventory of active SaaS subscriptions, working through Reviewing your SaaS subscription costs once removes the need to scramble every time someone leaves.

Ending contracts with freelancers and temp staff

Access granted to contractors and temporary staff is missed just as often as — or more often than — a full-time employee's departure. Even with a clear contract end date, system-level account suspension is a separate task that does not happen automatically.

- Add the contract end date to IT's own calendar, not only HR or admin's
- Change passwords or suspend server and admin console credentials shared with a vendor at contract end
- If a temp worker used a personal device, confirm they have been removed from shared files and work chat channels
- For counterparts who may renew, consider temporary restriction (read-only, for example) instead of full suspension

Contractor accounts do not appear on the employee roster, so they are easy to miss during a review. Adding an "external collaborator" category to your IT asset ledger removes the need to go hunting every time a contract ends.

Timeline: before departure, departure day, and the week after

TimingActions
From resignation decision to one week before the last dayList loaned equipment and accounts; decide who takes over each item; set up log monitoring for unusual activity
The day before the last working dayConfirm handover documents are complete; prepare notices for changed contacts; check SaaS cancellation deadlines
Departure dayRecover equipment, access cards, keys; force password changes or block logins on key accounts; set up email forwarding
One to three days afterWipe recovered equipment; review permissions in business systems; suspend lower-priority accounts
One week afterReconcile against the full account inventory; confirm SaaS cancellations completed; update the ledger

The key point is: do not rush full account deletion on the day itself. Blocking logins and changing passwords is enough to make the account unusable on day one; deleting or cancelling in stages over the following week, after handover has been confirmed, avoids the risk of losing data by accident.

Typical cost of IDaaS and MDM

At companies whose accounts are spread across many services, disabling a single departing employee can mean touching ten or more separate systems. IDaaS (a system that centralises login across multiple services) and MDM (mobile device management) can cut this workload substantially.

SystemWhat it doesRough cost
IDaaS (centralised identity)Disable logins to multiple SaaS tools from a single actionRoughly USD 2–4 per user per month
MDM (mobile device management)Remote lock and wipe, plus a live inventory of loaned devicesRoughly USD 2–6 per device per month
Integrated security management toolCombined visibility across accounts, devices and access logsRoughly USD 3–10 per user per month
Manual process (no tooling)Checklist and ledger onlyEffectively free (labour only)

Companies with few employees and only a handful of cloud services can usually run entirely on a checklist and ledger without buying a tool. A reasonable trigger for considering IDaaS is once you pass roughly ten active SaaS contracts, or once disabling a single departing employee routinely takes half a day or more.

Offboarding checklist

- Do you have an inventory of loaned PCs, phones, SIMs, access cards and keys?
- Once a resignation is confirmed, is there a process to check external sharing links and unusual activity logs?
- Is email and cloud storage data handed over to a successor before any account is deleted?
- Have you checked that approval workflows and system ownership no longer list the departing employee?
- Has every SaaS licence the employee used been sorted into cancel, downgrade, or transfer?
- Are contractor and temp-staff accounts run through the same inventory process?
- Were logins blocked and passwords changed on the day of departure?
- Is recovered equipment wiped before it is reissued or put into storage?
- Was account suspension reconciled against the full inventory within a week?
- Have gaps found this time been fed back into the procedure for next time?

FAQ

Should every account be deleted on the day someone leaves?

Blocking logins and forcing a password change on the day is usually enough. Deleting accounts before handover of in-progress email and files is complete risks losing correspondence with clients or the data itself. It is safer to delete or cancel in stages over the following week, once handover has been confirmed.

Do we still need data-walkout precautions for an amicable resignation?

Even a fully amicable departure can involve unintentional data walkout — moving files to a personal cloud account and simply forgetting about them, for example. Checking sharing links and download logs is not about suspicion; it is a standard step applied uniformly regardless of how the departure went, protecting both sides.

Can a company with no IT staff actually run this checklist?

Yes — and it matters more, not less, when nobody is dedicated to IT. Writing the checklist down on paper or in a spreadsheet, rather than relying on verbal confirmation, is the key step. Adding one line to your existing offboarding process — 'complete the IT checklist' — and having one named person fill it in on the last day closes most of the gaps.

Does the same checklist apply when a contractor's engagement ends?

The underlying approach is the same, but because contractors do not appear on the employee roster, you need a separate trigger to remember them — adding the contract end date to IT's own calendar, for instance. Where server or admin console credentials were shared, changing the password or suspending the account at contract end is standard practice.

Is IDaaS or MDM worth it for a small company?

With a handful of employees and only a few cloud services, a checklist and ledger run manually is usually sufficient. It becomes worth considering once SaaS contracts pass roughly ten, or once disabling a single departing employee's access routinely eats up half a day or more.

Summary

Offboarding is not a procedure built on suspicion of departing employees. It is a mechanism for guaranteeing that no matter who leaves, the same steps reliably shut everything down. Recovering equipment, handing over data, staging account suspension, and cancelling SaaS licences — laid out as a checklist across the before, day-of, and one-week-after timeline — can be run without a dedicated IT staff member. For the wider picture on prioritizing security work, see The complete guide to IT risk for small businesses.

Feel free to contact us

Contact Us