Employee Offboarding: A Checklist to Revoke All Access
An offboarding checklist for revoking sessions, tokens, Cloud, SaaS, Git, VPN, devices, and transferring business data when an employee leaves.

An employee may leave while email, VPN, CRM, Git, Cloud, or internal application access remains active. That risk can be far greater than the cost of structured offboarding.
The common problem is not one forgotten account. Access is spread across Microsoft 365 or Google Workspace, VPN, password managers, Git, Cloud, CRM, ERP, department-owned SaaS, personal devices, and unmanaged tokens.
The goal of offboarding
Do more than block sign-in. End sessions, revoke direct and inherited access, preserve business data, transfer responsibility, recover devices, remove licences, and produce evidence.
Problem
Why is changing the password not enough?
Sessions, tokens, third-party applications, and inherited access may remain active.
Users may still be signed in on laptops, phones, browsers, and desktop apps. They may also hold OAuth tokens, PATs, SSH keys, API keys, refresh tokens, or group-based access.






