The Employee Offboarding Checklist: 24 Hours to Prevent a Data Breach

When employees leave, they take access with them. Here's how to revoke everything before they walk out.

By The StackMatch Research Team

A 20-person business typically has an employee logged into 15-25 separate tools by the time they leave

15-25Tools an average employee can access
24 hrsTarget window to revoke all access
0Systems safe to skip 'just this once'

Illustrative figures for a small business — actual tool count depends on your stack size.

The risk in offboarding isn't the employee you're worried about — it's the account nobody remembers exists. A departing salesperson's CRM access gets revoked same-day almost every time; the shared bank-login they were added to eighteen months ago for a one-off vendor payment is the one still active three months later, because nobody owns a master list of every login an employee was ever handed.

Offboarding is a security event that happens to be scheduled by HR — treat the timeline accordingly.

Before the exit conversation

Preparation — do this before the employee is told

  • Pull a full access inventory from your identity provider or password manager, not from memory
  • Flag anything with financial authority: bank signer rights, payment-processor admin, payroll approval
  • Name who inherits each account and client relationship before the transition, not after
  • Schedule a specific person to run the revocation checklist on exit day — 'IT will handle it' is how steps get skipped
  • Export or back up their email, files, and CRM notes before the account is disabled
24
hours — the target window to revoke all access
Critical financial and admin access should be gone in under 2 hours; everything else by end of day.

Hours 0-2: financial and admin access

Revoke first — highest actual risk

  • Bank account signer rights and payment-processor admin logins
  • Password manager vault membership (removes cascading access to everything stored there)
  • Email account (disable, then forward to their manager for a defined window)
  • Any super-admin or owner-level role on core business systems

The bank-signer trap: an employee with signer rights can still initiate a wire the day after they leave if nobody calls the bank. Revoke same-day and get written confirmation from the bank, not just a checked box internally.

Hours 2-8: day-to-day systems

Secondary access — revoke same day

  • CRM and customer-communication tools (reassign owned accounts before disabling the user)
  • Team chat and video (Slack, Teams) — removing them stops both messaging and file access
  • Payroll/HR system access, separate from their own employee record
  • Cloud storage and shared drives
  • Code repositories and any tool with API keys issued in their name

Where offboarding time actually goes

Hours 8-24: cleanup and hardware

Final steps

  • Collect hardware — laptop, phone, badge, keys
  • Wipe or reset any personal devices enrolled in mobile device management
  • Update the org chart, directory, and any 'who to contact' documentation clients might see
  • Notify clients of the account transition with a named point of contact
  • Write down what was missed this time — the checklist should get more specific after every offboarding, not stay static

Set a firm end date for email forwarding — 30 days is common. Past that, a live forward to a manager becomes a live account nobody's actively watching.

The bottom line

The tools most likely to get missed aren't the ones IT set up — they're the ones a manager added someone to directly, off the books. A written access inventory, reviewed at least twice a year, is what actually closes that gap, not a faster checklist run on exit day.

Run the free StackMatch audit to map how many tools your team currently has standing access to — most owners are surprised by the number.

Run your own audit
More from the blog