An offboarding checklist for IT and People Ops
A practical handoff between People Ops and IT: protect access, preserve the work, recover the equipment and close the record.
Published October 10, 2026 · ShiplyTech
Offboarding is a handover, not an account-disable button.
A departure ends an employment relationship, but it does not instantly transfer the work, protect every account or bring a laptop back from a home office. The process crosses People Ops, IT, security, managers, finance and whoever receives the equipment. Most gaps happen at the boundaries between those teams.
A useful checklist makes those boundaries explicit: who decides, who acts, what another team needs first and what evidence makes a task complete. “IT notified” is not the same as access removed. “Return requested” is not the same as equipment recovered.
This guide is an operational starting point, not legal advice or a vendor-specific security procedure. Adapt it to the departure, your systems and local requirements. People Ops and legal should determine employment, final-pay, benefits and record-retention obligations.
The shared offboarding checklist
Use these checkpoints as a starting sequence, not a universal timetable. Some happen in parallel; a sensitive or immediate departure needs a different communication and access plan from a planned resignation.
- People Ops
Confirm the departure date, time zone, last working moment and communication owner.
- Coordinator
Name an owner for each workstream and record dependencies and exceptions.
- Manager
Transfer work, customer context, documentation and approval responsibilities.
- IT + security
Identify identities, applications, privileged access, shared secrets and physical access.
- IT + legal
Resolve retention or legal-hold requirements before deletion, wiping or disposal.
- IT
Reconcile assigned equipment, serials, accessories and where each item is located.
- People Ops
Confirm a suitable return contact method that works after company access ends.
- IT + return owner
Verify the shipping address, destination, packaging and intended device outcome.
- Return owner
Start the ShiplyTech return and make sure the employee receives instructions.
- IT + security
Execute and verify the approved access-removal plan at the agreed time.
- Return owner
Track kit delivery, return shipment and exceptions through ShiplyTech.
- IT + receiving team
Check received equipment against the asset list and record discrepancies.
- People Ops + legal
Handle unresolved returns through the approved internal escalation process.
- Coordinator
Close each workstream with evidence; leave unresolved items assigned, not hidden.
Before the exit: agree on ownership and timing.
People Ops should give the coordinator a confirmed departure event, not a vague “leaving Friday.” Record the last working moment and its time zone, who will speak to the employee, and whether IT actions must happen before, during or after that conversation. Share departure details only with people who need them.
People Ops
Own the employee communication, employment process and approved post-exit contact method. Keep payroll and benefits tasks with their appropriate owners.
IT and security
Own access decisions, records preservation, device-management planning and the asset inventory. Verify outcomes rather than assuming a request succeeded.
Manager and coordinator
Managers own work handover. The coordinator keeps dependencies visible and makes sure open items have a named next step.
ShiplyTech retrieval
Own the packaging, return instructions, shipping coordination, follow-ups and tracking after your team supplies the return details.
For immediate departures, do not assume there will be time for a normal handover. Decide which work can be recovered through approved administrative access, what must be preserved and who may communicate with the former employee.
Transfer the work without transferring the password.
A manager's handover list should cover active projects, customer commitments, upcoming deadlines, recurring tasks and decisions only that person understands. Find documents or processes that live in an individual account rather than a team-owned location.
IT should identify ownership of shared folders, calendars, groups, automations, service accounts and approval queues. Changing the owner of a document is different from leaving the departing person's account active indefinitely. Use approved administrative transfer methods rather than asking for passwords or signing in as the employee.
Watch for orphaned dependencies: an integration registered under one person's identity, a recovery method tied to their phone or a scheduled job that fails when access ends. Give each a replacement owner and verify it still works through your normal change process.
Remove access deliberately — and preserve what must be kept.
Start with an access inventory, not just the identity provider. Include company email, business applications, privileged roles, local or unmanaged accounts, external collaborators, physical badges and shared credentials the employee could access. Your security team should decide which sessions, tokens or secrets need revocation or rotation.
Preservation comes before irreversible action. Resolve legal holds, retention rules and business handover needs with the appropriate owners before deleting an account, wiping a device or sending it for disposal. Document an approved decision; don't make the shipping team infer it.
At the agreed time, execute the access plan and verify the result. Keep failures or systems awaiting manual action open with an owner. A disabled primary login does not by itself prove that every independent application or physical credential has been handled.
Do not make security wait for shipping. A laptop in transit is not a reason to postpone the approved access cutoff. Equally, access removal is not evidence that the laptop has been returned.
ShiplyTech does not access or administer your MDM, Apple Business Manager or Windows Autopilot systems. Keep those decisions with your IT team. See the device-release planning guide before making changes that affect reuse, preservation or disposal.
Give the employee one clear, usable return plan.
Before work email stops working, confirm an appropriate contact method for the return and verify the current shipping address. Follow your privacy policy and applicable requirements when collecting personal contact details. A return instruction sitting in a disabled inbox is not a workable handover.
Tell the employee what equipment is expected, how packaging will arrive, where it is going, any company-defined deadline and whom to contact if the address changes or they cannot follow the plan. Make return communication factual and respectful; don't mix logistical instructions with threats or uncertain legal consequences.
A remote employee may have moved, be traveling or have a monitor as well as a laptop. Confirm the actual situation before choosing packaging. The return method should fit the equipment and location, not the assumptions in an old asset record.
Make ShiplyTech the equipment-retrieval workstream.
Retrieval is often the offboarding task that stays open longest because nobody owns the box, the label or the next reminder. Put ShiplyTech into the checklist as a defined handoff, not a link someone might use later: return owner confirms the details → starts the return → monitors exceptions → reconciles receipt.
1. Your team defines what comes back and where it goes.
Reconcile the laptop and accessories against the assigned-asset record. Confirm the employee contact and shipping address, choose appropriate packaging, and decide the order outcome: Return to your company, Warehouse with ShiplyTech, or Disposal. Check retention and device-management decisions before approving the last option.
2. ShiplyTech runs the physical return process.
Start the return in the ShiplyTech app. The laptop-return process includes padded packaging, a printed instruction sheet and tape, emailed instructions with a personal return link, prepaid shipping for the kit and prepaid return shipping for the laptop. ShiplyTech handles follow-ups and tracking so your IT team does not have to assemble that process from separate messages and carrier pages.
For a multi-box order, each box has its own labels and tracking within the same order and payment. Check every box, not only the first shipment. Device and geographic eligibility still matter; check supported equipment and current coverage before committing to a return plan.
Track both ways

3. Your return owner stays accountable for exceptions.
Use ShiplyTech's tracking to distinguish a kit on the way to the employee from equipment on the way back. If a return stalls, check whether the kit arrived, instructions reached the right contact and the address is correct. Carrier timelines are estimates, not an employee deadline or a guaranteed completion date.
4. Your team closes the asset record.
For an office return, carrier delivery is the shipping milestone; your receiving team handles physical inspection and asset check-in. If you choose Warehouse, ShiplyTech receives, checks in and stores the device, with redeployment available for stored equipment. Disposal includes a BitRaser wipe and destruction; your team still owns the authorization and preservation decisions.
ShiplyTech handles retrieval logistics, not employment decisions, account shutdown or enforcement. It cannot force someone to return equipment. That distinction lets you outsource the coordination without losing internal accountability.
Treat exceptions as separate cases, not unchecked boxes.
A device that was sent, a device that was delivered and a device that was checked in are three different facts. Record missing accessories, unexpected contents, damage or a mismatched serial against the expected asset list. Assign a person to investigate each discrepancy.
If equipment never enters the return shipment, keep a concise record of the request, packaging, instructions, shipment events and contact attempts. Use the approved People Ops or legal escalation path once ordinary logistics no longer resolves the issue. The next action depends on company policy, agreements, applicable law and the circumstances.
Do not turn a checklist into an automatic permission to deduct wages, charge an employee, withhold final pay or make a theft allegation. Those questions require appropriate review. For a practical next-step sequence, read what to do when a laptop is not returned.
Close the case with evidence, not a reassuring status.
The coordinator should finish with a short, auditable record: who confirmed the departure, who verified access removal, where work ownership moved, what equipment was expected, what arrived and which exceptions remain. Limit sensitive information to those who need it.
- People Ops: employment tasks and employee communication have an appropriate completion record.
- Manager: essential work and responsibilities have a new owner.
- IT: approved access actions are verified and preservation decisions recorded.
- Retrieval: each expected shipment and asset is reconciled, or an unresolved item has an owner and next action.
Review recurring friction after the case closes. Wrong addresses suggest an intake problem. Missing chargers suggest an equipment-list problem. Repeated manual chasing suggests an ownership or retrieval-process problem. Improve the handoff rather than simply adding more reminders.
The best offboarding checklist leaves neither IT nor People Ops guessing. It protects the business, gives the departing employee a clear experience and makes equipment recovery a managed process — with ShiplyTech running the retrieval piece.