The Complete Employee Offboarding Checklist & Legal Guide
Most companies find out their offboarding is broken months later, by accident. A routine access review turns up an SSO account that kept working for three weeks after its owner's last day. Nobody did anything wrong, exactly: the laptop came back, the farewell card got signed, and everyone assumed someone else had clicked revoke. Onboarding fails loudly, with a new hire sitting in reception with nothing to do. Offboarding fails silently, and you learn about it at the audit or the incident, whichever arrives first.
That's the case for running departures from a checklist instead of memory. Offboarding is onboarding run backwards under time pressure, with two extra masters: security, which cares about the hours around the last day, and data law, which cares about the years after it. This is the pair to our onboarding checklist: what goes on the list, who owns each line, when the clock starts, and what you must keep once the person is gone.
The four workstreams
Every departure, resignation or termination, friendly or not, breaks into the same four streams.
Knowledge handover. The only stream that must start before the last day, because it needs the departing person's cooperation while they can still give it. Open projects, the undocumented deploy pipeline, the client who only deals with them: all of it has to land somewhere in writing while questions can still be answered.
Access and equipment. The security-critical path, and it belongs to the day itself. SSO, email, repositories, admin panels, API keys, the badge, the laptop. This is the stream where "we'll get to it next week" becomes an incident report.
The people side. The announcement (before the rumor mill writes its own version), the farewell, and the exit conversation. Departing employees are the most honest interview subjects you'll ever get.
Records. Coordinating final pay and any unused-leave payout with whoever runs payroll, then deciding what happens to the person's data: what you must keep, for how long, and what they can ask you to delete.
The checklist
Ten lines, four owners, every due date an offset from the last day. Trim it to your reality:
| Item | Assignee | Due |
|---|---|---|
| Hand over ongoing work, document open projects and contacts | Departing employee | last − 15d |
| Announce the departure and transition plan | Manager | last − 10d |
| Reassign owned systems, on-call and recurring duties | Manager | last − 5d |
| Confirm final pay and unused-leave payout with payroll | HR/admin | last − 5d |
| Schedule the exit conversation | HR/admin | last − 3d |
| Collect laptop, badge and equipment | IT owner (named person) | day 0 |
| Revoke SSO, email and all system access | IT owner (named person) | day 0 |
| Exit conversation | HR/admin | day 0 |
| Thank-you and farewell | Manager | day 0 |
| Record what was kept, what was deleted, and why | HR/admin | last + 5d |
The timing trap
The most common offboarding mistake is starting the checklist at the exit itself. Look at the first line of the table: "hand over ongoing work" is the departing person's task, and it's only actionable by them while they can still sign in. Start the checklist on the last day and that item, plus every other line assigned to them, immediately becomes their manager's problem, minus the one person who knew the answers.
Worked example. Aleksandra hands in her notice at Northlake on 2 September; her last day is 30 September. Marta starts the offboarding checklist the same day with 30 September as the anchor, so Aleksandra's handover document comes due on 15 September. That leaves two full weeks in which "where does the staging database password live?" still has someone to answer it. Start the checklist on the 30th instead and the identical question lands on Tomasz, her manager, who doesn't know either.
Their open work doesn't leave with them
Two cleanup rules a good tool handles automatically (do them manually if yours doesn't).
First, items assigned to the leaver on other people's checklists must be handed over. If Aleksandra owned "tools and workspace tour" on every new hire's onboarding, that line is now waiting on someone who can't see it, and the next hire's day one quietly breaks. It should move to her manager or an admin the moment she's gone.
Second, the leaver's own unfinished onboarding is moot and should cancel itself. Someone who resigns during probation shouldn't leave a checklist nagging their manager about a 30-day check-in that will never happen.
What you keep, what you erase
A departing employee, or one long gone, can ask you to delete their personal data; under GDPR that's their right. But "delete everything about me" and "delete everything the law lets you delete" are different requests, and the gap between them is where offboarding records live. Retention periods for payroll and tax records vary by country, so confirm yours with an accountant or counsel; this isn't legal advice. The shape, though, is consistent:
- Financial history stays. Leave balances and their ledger are part of your accounts. The person's name can become a placeholder; the numbers must still add up.
- Compliance evidence stays. A signed policy acknowledgment is your proof the policy was rolled out. Keep the record that the signature happened; strip the personal details from it.
- Personal data goes. Name, contact details, free-text notes, uploaded files: erasable on request, and the erasure itself should be documented.
The practical requirement: your system makes this split precisely, instead of you improvising it against a database at 6pm.
Where this lives in SquadBear
Checklists live under People → Checklists. The built-in Offboarding template starts itself the moment someone is offboarded, but the better move is the early start: open the person's profile, Checklists tab, Start checklist, anchored on their last day, while they can still sign in and clear their own items. Starting early never creates a duplicate; the automatic start simply does nothing if a checklist is already running. And if it does only start at the exit, items assigned to the leaver are handed straight to their manager or an admin rather than stranding.
The cleanup rules above are built in: on departure, the person's open items on other people's checklists move to their manager or the first active admin, and their own unfinished onboarding cancels itself. The Templates tab offers a one-click suggested Equipment return template, and any item can be pinned to a specific named person, so "collect laptop and badge" goes to whoever actually keeps the hardware, with a fallback to an admin if that person ever leaves too.
For the records half: erasure is admin-only, from the person's profile under Data rights → Erase personal data. It clears names, contact details and sensitive free text, deletes their files and login, and keeps exactly what the section above says it should: the balance ledger under a placeholder, the audit trail minus the wording that named them, and acknowledgment signatures with the typed name replaced. Anyone can request their own data export first from My settings.
Your AI assistant can run the sequence end to end:
"Start the offboarding checklist for Aleksandra with 30 September as the anchor, and list every open item currently assigned to her on other people's checklists."
"Before I erase Aleksandra's account, explain exactly what personal data that removes and what stays in SquadBear afterward."
Start free and the offboarding template is ready before you need it, or ask the demo to walk you through a departure.
Related reading: the employee onboarding checklist, the other half of this pair, for the day the next person joins.