Exit Access Checklist: What Employers Need to Know
August 18, 2026
An exit access checklist is the documented list of systems, accounts, credentials, and physical assets that must be revoked or collected when someone leaves an organization. Its purpose is to remove reliance on memory at exactly the moment memory is least reliable — during a departure that is often abrupt, emotionally charged, or handled by someone unfamiliar with what the person had.
Most organizations have some version of this. The ones that work share a specific property: the list is built per role in advance, not assembled from recollection at the moment of departure.
Why memory fails here
The employee's manager knows the core systems the person used daily. They usually do not know about the vendor account the employee created directly, the departmental tool provisioned outside IT, the shared credential they were given two years ago, the mailbox rule forwarding messages, or the building access at a secondary location.
Access accrues quietly. A person who joins in one role, moves to another, covers for a colleague on leave, and joins a cross-functional project accumulates permissions at each step and almost never sheds them. By separation, the sum of what they hold is not documented anywhere and is not known to any single person — including the employee.
A checklist built from a per-role access inventory, updated when access is granted rather than reconstructed at exit, closes that gap.
What belongs on it
- Identity and network accounts — the primary directory account, email, and single sign-on
- HR and payroll systems — HRIS, payroll platform, benefits administration, time and attendance
- Vendor-managed accounts — any external platform where the person registered with a work address, since disabling email may not disable the account
- Departmentally provisioned tools — anything a team adopted without central provisioning
- Shared credentials — which must be rotated, not merely noted, since revoking one person's knowledge of a shared password is impossible
- Administrative and elevated access — reviewed specifically, as these are the highest consequence
- Financial access — banking portals, corporate cards, expense systems, payment origination
- Mailbox rules, forwarding, and delegated access — frequently missed, and a route for data to keep flowing after the account is closed
- Physical assets and access — laptop, phone, badge, keys, secondary locations, parking
- Remote access — VPN, remote desktop, and any personally configured connection
- Mobile devices — company data removed from personal phones under whatever the policy permits
- Distribution lists and group memberships — including external groups and chat workspaces
Shared credentials deserve emphasis. Where a departing person knew a shared password, the only meaningful action is rotating it. Organizations routinely skip this because rotation inconveniences everyone still using it, which is also the reason shared credentials should be eliminated rather than managed.
Sequencing for involuntary separations
In a voluntary departure with notice, access can be wound down over the notice period. In an involuntary separation, the interval between the person learning of the decision and losing access is the entire window of risk.
That argues for preparing revocation in advance and executing it in coordination with the notification conversation rather than starting afterward. It also argues for consistency: an employer that revokes aggressively for some departing employees and casually for others creates a disparate-treatment exposure alongside the security one. A standard process applied to everyone is both more defensible and easier to execute correctly under pressure.
The verification step
The most commonly skipped item is confirming that revocation actually happened. A checklist marked complete is a record of intent, not of outcome. Requests get missed, tickets sit unprocessed, and vendor accounts persist because nobody at the vendor was told.
Two practices address this. First, verify the high-consequence items directly — attempt to confirm the account is disabled rather than assuming the request was fulfilled. Second, run a periodic reconciliation comparing active accounts across systems against the current employee roster. That reconciliation reliably surfaces accounts that should have closed months earlier, and each one it finds indicates a checklist step that silently failed.
What to preserve before revoking
Revocation and preservation pull against each other. Business records in the departing person's mailbox and files often need to be retained or transferred, and deleting an account can destroy them. Where litigation is anticipated, preservation obligations may attach and deleting data becomes a serious problem in its own right.
The sequence that avoids both failures is to preserve first — export or transfer what the business needs, place a hold where litigation is reasonably anticipated — and revoke second. Doing it in the other order is difficult to undo.
Pre-departure review
For roles with access to sensitive material, reviewing access logs for the weeks preceding a departure is a modest effort with real return. Data taken by departing employees has a recognizable signature: unusual download volumes, bulk exports, or large transfers to personal accounts shortly before a resignation. The obstacle is not detection difficulty; it is that nobody looks.
Employer's Guardian helps employers build and operate consistent separation processes, including access inventories and verification practices, through outsourced HR services.
This article provides general educational information, not legal advice. Separation requirements vary by jurisdiction. Consult qualified counsel regarding final pay, notices, and record retention.

