ISMO / Insights

Offboarding in ten steps

The riskiest day in an employee's life cycle is usually not the first one. It is the last. Access that nobody switches off, a laptop that never comes back, a client list that leaves in a personal cloud. Here is the order we use.

  1. Decide the date and the ownerOne named person runs the exit. Not HR and IT separately — one owner with a checklist.
  2. List every account before the conversationEmail, CRM, finance, cloud storage, code, admin panels, messengers, shared passwords. If you cannot list it, you cannot close it.
  3. Close access at the moment of the talkNot the next morning. Accounts are suspended while the conversation is happening.
  4. Rotate what was sharedShared passwords, API keys, door codes, card PINs the person knew.
  5. Take back the hardwareLaptop, phone, tokens, keys, cards. Check that the device is the one that was issued.
  6. Move the chatsClient and supplier conversations in personal messengers are handed over to a company account.
  7. Check the last thirty daysUnusual exports, forwarding rules, large downloads, new devices on the account.
  8. Hold a short exit briefingWhat remains confidential, for how long, and what was signed. Put it on record.
  9. Tell those who need to knowClients and suppliers who dealt with the person — briefly and factually.
  10. Review in a weekConfirm nothing is still live. Most leftovers are found on day seven, not day one.

If you cannot complete step two for your own company today, that is the place to start.