An exit access checklist is the documented list of systems, accounts, credentials, and physical assets that must be revoked or collected when someone leaves an organization. Its purpose is to remove reliance on memory at exactly the moment memory is least reliable — during a departure that is often abrupt, emotionally charged, or handled by someone unfamiliar with what the person had.
Most organizations have some version of this. The ones that work share a specific property: the list is built per role in advance, not assembled from recollection at the moment of departure.
The employee's manager knows the core systems the person used daily. They usually do not know about the vendor account the employee created directly, the departmental tool provisioned outside IT, the shared credential they were given two years ago, the mailbox rule forwarding messages, or the building access at a secondary location.
Access accrues quietly. A person who joins in one role, moves to another, covers for a colleague on leave, and joins a cross-functional project accumulates permissions at each step and almost never sheds them. By separation, the sum of what they hold is not documented anywhere and is not known to any single person — including the employee.
A checklist built from a per-role access inventory, updated when access is granted rather than reconstructed at exit, closes that gap.
Shared credentials deserve emphasis. Where a departing person knew a shared password, the only meaningful action is rotating it. Organizations routinely skip this because rotation inconveniences everyone still using it, which is also the reason shared credentials should be eliminated rather than managed.
In a voluntary departure with notice, access can be wound down over the notice period. In an involuntary separation, the interval between the person learning of the decision and losing access is the entire window of risk.
That argues for preparing revocation in advance and executing it in coordination with the notification conversation rather than starting afterward. It also argues for consistency: an employer that revokes aggressively for some departing employees and casually for others creates a disparate-treatment exposure alongside the security one. A standard process applied to everyone is both more defensible and easier to execute correctly under pressure.
The most commonly skipped item is confirming that revocation actually happened. A checklist marked complete is a record of intent, not of outcome. Requests get missed, tickets sit unprocessed, and vendor accounts persist because nobody at the vendor was told.
Two practices address this. First, verify the high-consequence items directly — attempt to confirm the account is disabled rather than assuming the request was fulfilled. Second, run a periodic reconciliation comparing active accounts across systems against the current employee roster. That reconciliation reliably surfaces accounts that should have closed months earlier, and each one it finds indicates a checklist step that silently failed.
Revocation and preservation pull against each other. Business records in the departing person's mailbox and files often need to be retained or transferred, and deleting an account can destroy them. Where litigation is anticipated, preservation obligations may attach and deleting data becomes a serious problem in its own right.
The sequence that avoids both failures is to preserve first — export or transfer what the business needs, place a hold where litigation is reasonably anticipated — and revoke second. Doing it in the other order is difficult to undo.
For roles with access to sensitive material, reviewing access logs for the weeks preceding a departure is a modest effort with real return. Data taken by departing employees has a recognizable signature: unusual download volumes, bulk exports, or large transfers to personal accounts shortly before a resignation. The obstacle is not detection difficulty; it is that nobody looks.
Employer's Guardian helps employers build and operate consistent separation processes, including access inventories and verification practices, through outsourced HR services.
This article provides general educational information, not legal advice. Separation requirements vary by jurisdiction. Consult qualified counsel regarding final pay, notices, and record retention.