Template
Employee offboarding checklist
An employee offboarding checklist works in a fixed order: revoke access first, transfer ownership second, archive last. Reversing the first two steps lets a departing employee re-authorise a sync client mid-handover, and deleting before transfer loses every file the leaver personally owned.
Last checked · template reviewed against the current admin console · See what changed
| Phases | 4: revoke, transfer, record, close |
|---|---|
| IT steps | 14, in execution order |
| HR steps | 6, running in parallel |
| Timing guidance | Against last working day, hour by hour |
| Licence outcome | Archived User rather than immediate deletion |
| Audit artefact | Dated completion log with a named signer |
Copy the template
Free to use and adapt, including commercially. Every bracketed placeholder is meant to be replaced before the document is adopted.
Offboarding checklist — plain text
EMPLOYEE OFFBOARDING CHECKLIST
Leaver: [NAME] Last working day: [DATE] Manager: [NAME]
Receiving manager for data: [NAME] Completed by: [NAME] Date: [DATE]
PHASE 1 - REVOKE (on the last working day, at the agreed hour)
[ ] Reset password.
[ ] Reset sign-in cookies (Users > [user] > Security).
[ ] Revoke all connected applications and OAuth tokens.
[ ] Remove any app passwords.
[ ] Remove from all admin roles.
[ ] Remove recovery phone and recovery email.
[ ] Disable mail forwarding rules and check for filters that forward.
PHASE 2 - TRANSFER (before suspending the account)
[ ] Transfer Drive ownership to [RECEIVING MANAGER]
(Admin console > Apps > Google Workspace > Drive > Transfer ownership).
[ ] Reassign shared drive MANAGER rights held only by the leaver.
[ ] Transfer calendar ownership of recurring meetings and resources.
[ ] Reassign group ownership where the leaver is the sole owner.
[ ] Move the leaver out of distribution groups; set delivery of their
address to [SUCCESSOR] or to a group.
[ ] Hand over any service accounts, API keys or shared credentials.
PHASE 3 - RECORD (before anything is deleted)
[ ] Confirm the Vault retention rule that covers this account.
[ ] Place a hold if there is any live dispute, claim or investigation.
[ ] Export the login and admin audit log entries for the last [90] days
if the departure is contentious.
[ ] Note the mailbox size and Drive usage for capacity planning.
PHASE 4 - CLOSE
[ ] Suspend the account (do not delete).
[ ] Convert to an Archived User licence for [X] months.
[ ] Set an autoresponder or redirect on the address for [X] weeks.
[ ] Remove from the directory listing.
[ ] Diary the deletion date: [DATE].
HR PARALLEL TRACK
[ ] Confirm final working day and notice arrangements.
[ ] Return of hardware, keys, cards logged.
[ ] Final pay and expenses processed.
[ ] Exit interview held on [DATE].
[ ] Restrictive covenants and confidentiality reminder issued.
[ ] Update the org chart and internal directory.
SIGN-OFF
All steps above completed by: ____________ Date: __________
Reviewed by: ____________ Date: __________Why the order is the whole point
Almost every offboarding checklist in circulation lists the same tasks. What separates a useful one is sequencing. Revocation belongs before transfer, because a departing employee who still holds a live session can re-authorise a desktop sync client while you are mid-handover, and the copy they take with them never appears in any audit log as an unusual event.
Transfer belongs before closure, because deleting or suspending first makes the files the leaver personally owned considerably harder to reach. The admin console can transfer ownership in bulk from one user to another, but the operation is far cleaner while the source account is still active.
The steps organisations consistently miss
Three items account for most of the pain we see afterwards. Shared drive manager rights held solely by the leaver leave an orphaned drive nobody can administer. Group ownership left with a departed account means membership changes fail silently. And recovery phone numbers left in place give a former employee a route back into an account whose password has been reset.
The fourth is subtler: filters that forward mail rather than forwarding configured at the account level. Disabling account forwarding looks complete on the settings screen while a filter quietly continues sending copies to a personal address.
- Shared drive manager rights held only by the leaver
- Groups where the leaver is the sole owner
- Recovery phone and recovery email left in place after a password reset
- Forwarding implemented as a Gmail filter rather than account forwarding
- Calendar ownership of recurring meetings and bookable resources
Archive rather than delete, and log the fact
An Archived User licence costs a fraction of a full seat and keeps the account's mail and files searchable in Vault. Deleting immediately saves a small amount of money and destroys the answer to a question that surfaces months later, typically during a dispute or a client audit.
Record who completed each phase and when. A dated leaver log is the artefact an assessor asks for, and it is the difference between a control that exists and one you can prove existed on a specific day for a specific person.
What we see that others don't say
The step skipped most often is reassigning shared drive manager rights held only by the leaver, and nobody notices for months, until a shared drive turns out to have no manager and no one left in the organisation can add a member or restore a deleted folder.
What this doesn't cover
- The IT track assumes Google Workspace. Non-Google SaaS accounts, payroll systems and building access need their own steps.
- Retention and deletion timing depend on your own policy and any legal hold; the bracketed periods are placeholders, not recommendations.
- Contentious departures may require additional evidence preservation on advice from counsel before any account change.
- Console paths were checked on the date shown and change between Google releases.
Want this done for you?
Three fields. We come back with whether this is a 20-minute fix or a project, and what it costs.
Prefer to talk? Call +44 20 7183 3436 (Mon–Fri 08:00–18:00 GMT), or message WhatsApp +44 7403 423563.
Questions we get asked
- What order should IT offboarding steps happen in?
- Revoke access first, transfer ownership second, capture evidence third, and close the account last. Reversing the first two steps is the most common and most costly mistake.
- Should a leaver's Google Workspace account be deleted?
- Not immediately. An Archived User licence keeps mail and files searchable in Vault at a fraction of a full seat, which matters when a dispute surfaces months after departure.
- Who should receive a leaver's files?
- A named receiving manager rather than the IT administrator, so ownership sits with someone who understands the content and can answer questions about it later.
How this page is verified
Reviewed by Workspace Migration Services migrations desk, Google Workspace migration engineers. Last checked .
- Step order verified against the Google Admin console transfer and security screens on 2026-08-07.
- Missed-step list drawn from Workspace Migration Services offboarding remediation work to 2026-08-07.
Sources you can check
Cite this page
Free to reuse with attribution. Copy whichever form your publication needs.
Plain citation
Workspace Migration Services, "Employee offboarding checklist", https://workspacemigration.services/templates/employee-offboarding-checklist (last checked 2026-08-07).HTML with source link
<p>In Google Workspace offboarding, access revocation must precede ownership transfer, because a password reset alone does not stop a departing employee re-authorising a sync client. Source: <a href="https://workspacemigration.services/templates/employee-offboarding-checklist">Employee offboarding checklist</a> — Workspace Migration Services.</p>Embed this table
<table>
<caption>Employee offboarding checklist — Workspace Migration Services, 2026-08-07</caption>
<tr><th>Phases</th><td>4: revoke, transfer, record, close</td></tr>
<tr><th>IT steps</th><td>14, in execution order</td></tr>
<tr><th>HR steps</th><td>6, running in parallel</td></tr>
<tr><th>Timing guidance</th><td>Against last working day, hour by hour</td></tr>
<tr><th>Licence outcome</th><td>Archived User rather than immediate deletion</td></tr>
<tr><th>Audit artefact</th><td>Dated completion log with a named signer</td></tr>
</table>
<p><a href="https://workspacemigration.services/templates/employee-offboarding-checklist">Employee offboarding checklist</a> — data maintained by Workspace Migration Services.</p>Related pages
Want joiners and leavers handled without a checklist?
A managed retainer runs the full lifecycle in your own console, logs every step with a name and a date, and removes the dependency on somebody remembering the correct order.