Skip to content

TCR-IT-012: Offboarding Process

The IT-specific steps for offboarding a departing TCR employee: access revocation, equipment retrieval, and data handling.

A departing employee who still has access after their last day is a real, common security gap. This process exists so access revocation and equipment retrieval happen reliably and promptly, tied to Populi as the source of truth for credential deactivation, rather than depending on a manual step someone might forget.

  • Collect information: end date, outstanding IT tasks or projects.
  • Coordinate with HR and the employee’s manager on what access to revoke and when.
  • Back up important data and transfer it to a designated person/location; set up email forwarding or out-of-office replies if needed.
  • Revoke access: disable accounts in Active Directory, Google Workspace, and other systems, primarily Populi, since it drives credential deactivation in most other relevant systems. Revoke shared drive, VPN, and other network resource access. Collect keys, ID badges, and access cards.
  • Retrieve equipment: collect all IT equipment (laptops, peripherals, mobile devices); document and inspect for damage or missing items.
  • Data wipe: securely wipe data from returned devices and reset to factory settings for re-use.
  • Update the IT inventory to reflect returned equipment and assignment changes.
  • Audit to confirm all access has been revoked and no data was left behind; verify backups/transfers completed successfully.
  • Document the process and any issues encountered; follow up with HR and the manager to confirm all IT tasks are complete.
  • Collect offboarding information
  • Communicate with HR and management
  • Backup and data transfer
  • Revoke access
  • Retrieve equipment
  • Data wipe
  • Update inventory
  • Review and audit
  • Conduct exit interview
  • Document process and follow-up

Digitized from TCR-IT-012 - Offboarding Process [Rev 1.0].docx; the original is kept under source/policies/ in this repo.

Owner: IT Systems Coordinator · Revision 1 · Last reviewed Aug 18, 2026 · Next review due Aug 18, 2027