← All posts · 2026-07-24
The IT offboarding checklist that survives an audit
Offboarding is the access control that fails silently. Nothing breaks when a leaver keeps their accounts; the cost only appears months later, in an audit finding or an incident report. The fix is a checklist that treats offboarding like a deploy: defined steps, an owner, and a record.
Same day: identity first
- Disable the identity provider account (Entra, Okta, Google). This kills SSO sessions and most downstream access in one move.
- Revoke active sessions and refresh tokens; disabling alone does not end sessions everywhere.
- Collect or wipe managed devices, and rotate any shared credentials the person knew.
Same week: the long tail
- Remove direct logins that bypass SSO: source control, production databases, cloud consoles, payment and banking portals.
- Reassign ownership: mailboxes, shared drives, scheduled reports, domain registrations, and any automation running under their account.
- Remove them from vendor systems and third-party tools that bill or grant access per seat.
Record it or it did not happen
For each step: who did it and when. The printable completion record is what turns offboarding from a memory into evidence. It is also what your SOC 2 auditor means when they ask how leavers lose access.
The test that finds the gaps
Take your last three leavers and check today whether any account still works. If the answer is yes even once, the checklist is not real yet. Run that test quarterly alongside your access review and the two controls reinforce each other.
AccessKit runs your access reviews from a CSV import and produces printable evidence, no tenant access required. Start free or see the live demo.