Home / Security / Create an employee or contractor offboarding security checklist
Advanced Operational · Security Ring

Create an employee or contractor offboarding security checklist

1 hr to create, then ongoing use Impact: medium Effort: medium ✓ Manual completion

A documented employee or contractor offboarding security checklist ensures that when someone with access leaves, every account, credential, and API key they had is genuinely and immediately revoked, rather than depending on someone remembering to do it.

Old access that lingers after someone leaves is a real, common security gap, without a checklist this depends entirely on memory, which is exactly how forgotten access persists for months or years.

The full picture

An employee or contractor offboarding security checklist ensures that when someone's relationship with your business ends, their access to your systems ends promptly and comprehensively alongside it — without this systematic process, access revocation can be incomplete or delayed, leaving genuine security gaps from former team members retaining unnecessary access.

The genuine comprehensiveness this checklist requires deserves real attention — a departing team member may have accumulated access across numerous systems over their tenure, including systems that might not be immediately obvious or top-of-mind during the departure process, making a genuinely comprehensive, systematic checklist more reliable than attempting to remember and address each access point from memory alone.

This connects directly to the unused admin account risk discussed elsewhere throughout this broader security work — proper offboarding process is precisely what prevents this specific risk category from accumulating in the first place, making prevention through systematic offboarding meaningfully more efficient than periodic audits attempting to catch accumulated gaps after the fact.

A genuinely useful checklist should address every category of access a departing team member might have held — system logins, physical access if applicable, any administrative permissions, and access to any third-party tools or services used in their role, ensuring comprehensive, prompt revocation across this complete access footprint rather than addressing only the most obvious, immediately visible access points.

How to do it

  1. 1
    List every system and account someone with access might have
    CMS, hosting, email, shared documents, any tool with meaningful access.
  2. 2
    Create a real checklist covering all of it
    Something to actually work through item by item when someone leaves, not rely on memory.
  3. 3
    Assign clear ownership for executing it
    Someone specifically responsible for running through the checklist promptly.
  4. 4
    Use it for real the next time someone actually leaves
    The value of this mission comes from genuine use, not just having the document exist.

Common mistakes

How you will know it is done

A documented offboarding checklist exists and has been used for at least one real departure.

Track this in your hive

The Security Ring turns this into a real, permanent mission — mark it complete once you have genuinely done it.

Open this mission in H.I.V.E. →