Patronum Logo
00%
Patronum Logo
menu-icon

Employee Onboarding and Offboarding: A Combined IT Checklist

By Patronum

July 15, 2026

Read Time: 5 mins

The cleanest way to run onboarding and offboarding is to treat them as mirror images: every access you grant on day one is something you remove on the last day. Onboarding provisions the account, license, organizational unit, groups, and security. Offboarding reverses each of those in a safe order, plus transfers data and wipes devices. Keep the two lists paired and nothing gets left open when someone leaves. Here is the combined checklist.

Most access leaks happen because onboarding and offboarding are owned by different people, tracked in different places, and never reconciled. Someone grants ten things when a person joins; at exit, eight get removed and two are forgotten. Pairing the lists fixes that by design: if a grant does not have a matching removal, it stands out.

The mirror principle

Think of each onboarding action as creating a debt that offboarding has to pay back. Grant a license, reclaim it. Add to groups, remove from groups. Enroll a device, wipe it. When the two checklists mirror each other line for line, the exit review becomes simple, because you already have the list of everything that was granted.

To make the mirror actionable, keep a simple access register and review it at every stage, not just the ends:

Access itemGranted at onboarding?Still needed after role change?Removed at offboarding?
Google Workspace licenseYesReviewYes
GroupsYesReviewYes
Shared drivesYesReviewYes
Admin rolesIf neededReview tightlyYes
Third-party appsIf approvedReviewRevoke
DevicesEnrollReviewWipe or remove account
Onboarding grants…Offboarding must remove…
Account and licenseSuspend, then archive or delete the account
Organizational unit placementMove to a leavers or archive OU if retained, or remove when the account is deleted
Group and shared-drive membershipRemove from every group and shared drive
Admin roles or delegated accessRemove all roles and delegation
Third-party app accessRevoke connected app access
Mailbox and routing accessSet handover, reroute mail, remove delegation, and preserve the mailbox per policy
Devices enrolledWipe or remove the corporate account from devices
Files, calendars, and shared resourcesTransfer or reassign ownership where supported, review sharing, and remove delegated access
Security credentials and sessionsRevoke sessions, security keys, app passwords, and connected app access

Onboarding checklist

  • Get manager approval for the role and its access before you provision anything, so access is requested and signed off rather than assumed.
  • Create the account in the Admin console, individually, in bulk, or via automated provisioning (Google Admin Help).
  • Assign a license, ideally with automatic licensing for the organizational unit so it scales (Google Admin Help).
  • Place them in the right organizational unit so they inherit the correct settings (Google Admin Help).
  • Add them to the groups their role needs, rather than sharing files individually (Google Admin Help).
  • Record approved third-party app access so the connected apps a person is given are documented and can be revoked later.
  • Confirm 2-Step Verification applies, with a new-user enrollment period (Google Admin Help).
  • Hand over the basics: secure sign-in details, shared drives, calendars, and the apps they will use.

Offboarding checklist

The order depends on how the person is leaving. For planned exits, arrange handover before suspension. For urgent or high-risk exits, suspend and revoke access first, then recover handover through admin-controlled routing and retention processes.

  • Arrange mail and data handover first, before suspension, since new mail and calendar invitations are blocked for a suspended account. For planned departures, set any auto-reply, alias, routing rule, or shared-inbox handover before suspension, and test that the routing works before the person’s final day (Google Admin Help).
  • Suspend the account to block sign-in while preserving data (Google Admin Help).
  • Reset credentials and revoke access: sign out all sessions, delete app-specific passwords, remove security keys, revoke connected apps, and end any third-party SSO session.
  • Transfer My Drive files owned by the leaver to another active internal user, then review sharing. Move long-lived team content into the appropriate shared drive before deletion where needed. Note that transferring ownership does not change who already has access (Google Admin Help).
  • Remove group, shared-drive, and role assignments.
  • Wipe managed devices, or remove the corporate account where endpoint management supports it. For unmanaged BYOD devices, rely on account suspension, credential revocation, and your BYOD policy rather than assuming a full remote wipe is available.
  • Choose an end state after suspension: archive or delete based on your retention policy (Google Admin Help).

Do not forget movers

Onboarding and offboarding get the attention, but the biggest access drift usually happens in between, when someone changes role, department, location, or seniority. When that happens, review their groups, shared drives, admin roles, third-party app access, devices, and licenses against the new role. Most over-permissioning comes from access added for a new role while old-role access quietly stays in place. Treat a role change as its own mini offboarding-and-onboarding, using the access register above.

Why pairing the lists matters

When onboarding and offboarding live as separate, unmatched processes, the offboarding side is always guessing what was granted. Pairing them turns the exit into a subtraction problem with a known starting list. It also exposes the middle of the lifecycle, the role changes, where access is added but rarely removed. For that stage, see our explainer on user lifecycle management.

Automate both ends

Two checklists owned by busy people are two checklists that eventually get half-run. Patronum automates Google Workspace onboarding and offboarding as paired policies: new hires get the right license, organizational unit, groups, and security, and leavers have the same set removed in a safe order, with data transferred and devices wiped. Consistency across both ends is what keeps access matched to reality. For each side in depth, see our guides on user onboarding and Google Workspace offboarding.

FAQ

What should be on an onboarding and offboarding checklist?
Onboarding: account, license, organizational unit, groups, 2-Step Verification, and handover. Offboarding: mail handover, suspension, credential and session revocation, data transfer, role removal, device wipe, and an archive-or-delete decision.

Why pair onboarding and offboarding?
Because everything granted at onboarding has to be removed at offboarding. Pairing the lists makes sure nothing is forgotten at exit.

Who should own these checklists?
Ideally one process owns both, so grants and removals are reconciled rather than tracked separately by different teams.

What is the most commonly missed offboarding step?
Revoking sessions and connected apps, and removing leftover group or role memberships, which can keep access alive after the account looks closed.

What should IT do when someone changes role?
Treat a role change as a mini offboarding and onboarding: remove old-role access, add new-role access, and update the access register. Most over-permissioning comes from new-role access being added while old-role access stays in place.

Can onboarding and offboarding be automated together?
Yes. Patronum runs both as paired policies so access granted at onboarding is removed at offboarding in the right order.

Grant and remove access with one consistent process

Onboarding and offboarding are the same job from opposite ends. See how Patronum automates both so access always matches who is actually on your team.

Sources

  • Google Admin Help, “Options for adding users”: https://support.google.com/a/answer/179832
  • Google Admin Help, “Set automatic licensing for organizational units”: https://support.google.com/a/answer/7610656
  • Google Admin Help, “How the organizational structure works”: https://support.google.com/a/answer/4352075
  • Google Admin Help, “Create a group in your organization”: https://support.google.com/a/answer/9400082
  • Google Admin Help, “Deploy 2-Step Verification”: https://support.google.com/a/answer/9176657
  • Google Admin Help, “Redirect or forward Gmail messages to another user”: https://support.google.com/a/answer/4524505
  • Google Admin Help, “Delete or suspend a user”: https://support.google.com/a/answer/33314
  • Google Admin Help, “Transfer Drive files to a new owner”: https://support.google.com/a/answer/1247799
  • Google Admin Help, “Options to preserve former employee data”: https://support.google.com/a/answer/11524030