Helia HR

Guide

The offboarding checklist for IT companies: clean exits, every time

Updated 2026-07-23 · Notice period → last day → wrap-up — with owners, and the client-comms track most templates skip

Offboarding is a security event, not paperwork

At an IT company, the person leaving on Friday holds keys most templates never mention: repo access, cloud consoles, client VPNs, a production password in a personal note. HR tradition treats offboarding as paperwork — return the badge, sign the form. The real risks live elsewhere:

  • Orphaned accounts. An email login nobody disabled, an SSO seat still active, an API token that outlives its owner — every breach investigation's least favorite ending.
  • Unreturned equipment. A laptop with a logged-in session and a cached repo is not a hardware cost — it's an uncontrolled copy of your company.
  • Knowledge loss. The deploy process that lives in one head, the client quirk nobody wrote down. This one surfaces weeks later — and costs the most.

The fix is the same as onboarding's: a checklist with an owner and a due date on every line, created the moment a departure is confirmed — while the person is still there to help.

The five tracks of a clean exit

Every offboarding runs the same five tracks in parallel — different owners, different clocks:

  1. Access (owner: IT). Everything granted since day one gets revoked — from the same access matrix you grant from, not from memory.
  2. Assets (owner: IT/ops). Laptop, monitors, phone, licenses. You can only reclaim what you tracked — an asset register with who-holds-what turns a shrug into a checklist item.
  3. Knowledge (owner: manager). A written handover — ongoing work, decisions in flight, client context — plus reassignment of the actual work: tickets, code ownership, on-call.
  4. Money (owner: finance). Stop the next payroll run, end benefits, settle expenses, pay out unused leave. Late here means clawing back an overpaid salary.
  5. The exit conversation (owner: HR). A structured interview while the feedback is fresh — its own section below.

One person, usually HR, coordinates all five. But every line has exactly one owner, because "the team will handle it" is how laptops go unreturned.

The timeline: notice period → last day → wrap-up

Anchor every task to the last working day — negative offsets fall in the notice period, day 0 is the exit itself, positive offsets are the wrap-up:

Notice period

  • Day −14 (HR): confirm the last working day and notice terms in writing; open the offboarding checklist
  • Day −7 (manager): knowledge transfer and handover document — ongoing work, credential locations, client context
  • Day −7 (manager): reassign open projects, tickets and client work to named people — not "the team"
  • Day −3 (HR): schedule the exit interview

Last day (day 0)

  • IT: collect company equipment — laptop, devices, badge — against the asset register
  • IT: revoke system access — email, SSO, repos, cloud, internal tools — at end of day, not mid-morning
  • HR: conduct the exit interview

Wrap-up

  • Day +1 (finance): remove from payroll and end benefits
  • Day +3 (finance): final pay — salary, expenses, unused-leave payout
  • Day +7 (HR): archive the employee record per your retention policy

Client-facing roles need a sixth track: client comms

For services and outsourcing teams, the standard five tracks miss the one that can cost real revenue — the client:

  • The client hears it from you, on your schedule. Never from the departing engineer's farewell message. Agree who tells the client and when — usually the delivery manager, early enough to manage the reaction.
  • The successor is introduced before the departure, not after. Even one week of overlap on calls changes how the transition lands. No successor yet? Name an interim owner — a client hearing "we'll get back to you" is a client updating their vendor shortlist.
  • The handover covers the relationship, not just the code. Stakeholders, promises made, sensitivities — the written handover gets a client-specific section.
  • Capacity plans update the same day. The person's allocations move to real replacements — otherwise next month's plan quietly counts hours nobody will work.
  • Credentials belong to the company. Client VPNs, staging access, dashboards — owned and rotated by you, not carried in one person's password manager.

Exit interview questions that actually get honest answers

Most exit interviews produce polite fiction because the setup is wrong: run by the direct manager (the person half the feedback is about), with no promise about where the answers go. Fix the setup — HR or a founder conducts it, on or near the last day after the handover is done, and says explicitly that themes are shared while the verbatim stays with HR. Write it in a structured form: one interview is an anecdote; ten in the same format are a pattern.

Questions that earn honesty:

  • What made you start looking? (The trigger, not the rationalization.)
  • What would have had to change for you to stay?
  • When were you closest to leaving before this — and what kept you?
  • What should the next person in your role know that nobody told you?
  • What worked here that we should protect?
  • On a 0–10 — would you recommend working here, and why that number?
  • Would you come back some day?

How Helia HR does this

Offboarding ships in the Onboarding & offboarding pack ($1/employee/mo — see [pricing](/pricing)), so the exit checklist lives next to the entry one:

  • Start an offboarding on any employee — pick the reason (voluntary, involuntary, end of contract, retirement) and the last working day, and a checklist is instantiated from a standard exit template. Every task carries an owner role (HR, manager, IT, finance) and a due date computed from the last working day — negative offsets in the notice period, day-0 tasks on the exit day, positive offsets in the wrap-up. Add, remove or skip tasks per person.
  • Access revocation is an explicit IT-owned checklist item due on the last day — email, SSO, repos, cloud, internal tools — not a hope.
  • Equipment to reclaim, from the asset register: the offboarding page lists every asset still issued to the person — with asset tags and serial numbers — and each is marked returned in one click.
  • A structured exit interview on the same page: recommend score, overall satisfaction, would-they-return, primary reason, what worked, what didn't, one suggestion. HR-only by default, with an explicit toggle to share the summary with the person's manager.
  • Exit reasons feed the turnover report — joiners, leavers and a reasons breakdown over the last 12 months, so patterns surface.
  • Every step is written to the audit log, like all PII changes in Helia.
Lifecycle templates in Helia — department checklists that drive onboarding and exits

FAQ

Should voluntary and involuntary exits use the same checklist?

Same five tracks, different clock. A resignation runs on the notice-period timeline above. An involuntary exit compresses it: access and equipment are handled the moment the conversation ends, and the exit interview usually becomes a shorter, documented conversation.

When exactly should access be revoked?

At the end of the last working day — not when notice is given. The person is still doing real work through the notice period; cutting access early mostly punishes the handover. Exceptions: involuntary exits, and narrowing high-risk rights (prod admin) early. Revoke from the same matrix you grant from — see the onboarding checklist.

Who owns offboarding?

One coordinator — usually HR — plus exactly one owner per line: the manager owns knowledge, IT owns access and assets, finance owns money. The coordinator watches due dates, not every task.

Is an exit interview worth it at a 15-person company?

Yes — precisely because every exit is a bigger share of the company. Twenty minutes and the questions above. The first one tells you a story; the fifth, collected in the same format, tells you a pattern.

Run HR and delivery ops in one system

Helia HR combines the HR basics with the capacity matrix, bench view, timesheets and client invoicing IT services teams actually run on. Start free, no card. GDPR-grade security, role-gated PII, audit-logged access.