Employee offboarding: a checklist for returning assets
Offboarding requires several things to come together at the right moment: get the hardware back, check the accessories, handle access, coordinate data handovers, release licences and record exceptions. Without a shared view it is usually not the big task that slips but a small detail — the second power supply, a monitor in someone's home office, or a licence nobody took responsibility for.
This checklist structures the process from the confirmed leaving date to the closed asset record. It is deliberately written as an operational guide. Which retention, deletion, co-determination or documentation obligations apply in your case should be settled by HR, IT, information security and, where relevant, your legal or data-protection advisers, based on your own circumstances.
What a good IT offboarding produces
An offboarding is not finished merely because the user account has been disabled. At the end, four outcomes should be traceable:
- Every company item assigned to the person has been returned or recorded as an open exception.
- Return date, condition and the person who accepted it are documented.
- Technical access, device actions and licences have been handled in the systems responsible for them.
- Every open item has a responsible person and a next date.
This definition prevents the vague status "in progress". A missing laptop may stay open — but only visibly, with an owner and a due date.
Agree roles and responsibility up front
Offboarding is a shared process. One workable split looks like this:
| Role | Typical responsibility |
|---|---|
| People/HR | confirmed leaving date, communication path, organisational handover |
| Line manager | professional handover, need for data and shared resources |
| IT | asset list, collection, device inspection, technical account and MDM actions |
| Information security | rules for edge cases, lost devices or unusual risk |
| Procurement/Finance | open orders, leasing or buy-back processes, chargeable contracts |
| The departing person | returning the specifically confirmed items and accessories |
The exact split may look different. What matters is that the process has one person in the lead. They do not have to carry out every task themselves, but they must see the overall status and be able to escalate.
Phase 1: Record the departure and start the offboarding
Record the case as soon as the leaving date is confirmed internally and released to the roles involved. The checklist should contain at least:
- name and unique internal identifier of the person,
- last working day and, where different, the return date,
- line manager and the responsible HR contact,
- IT owner for collection and technical measures,
- place of work and the planned return route,
- known absences before the last working day,
- special rules for immediate or confidential departures.
Not every departure may be handled with the same lead time or communication. Define a clear path for urgent cases rather than negotiating responsibilities in the middle of one.
Phase 2: Build a complete asset list
Establish every item currently assigned to the person. Start with the central inventory and reconcile further sources where needed.
Depending on the workplace, the check covers:
- laptop, desktop, tablet and phone,
- monitors and docking stations,
- power supplies, adapters, headsets and other peripherals,
- test, spare or loan devices,
- access cards, hardware tokens, keys and specialist equipment,
- storage media or devices handed out temporarily for a project,
- items left in the home office or delivered there directly.
Do not rely on a general statement such as "laptop plus accessories". List serialised items individually. For accessories without a serial number a clear description and, where it exists, an internal marking are enough.
Reconciling with MDM or identity systems helps but does not replace the handout history: a technically enrolled device may have been shared, and accessories usually do not appear there at all.
Phase 3: Organise the return bindingly
Tell the departing person in good time and in plain terms:
- which specific items are expected,
- when and where the return takes place,
- whether accessories, bags or the original power supply are included,
- how to pack and ship,
- who to reach with questions or deviations,
- how to proceed with lost or damaged property.
Remote offboarding needs additional detail. Provide a suitable shipping label or a collection route, explain the packaging and allow for transit time. A return date on the last working day is usually not a dependable arrival date for a shipment.
Use an approved channel for return addresses and contact details. Sensitive offboarding details do not belong in a group thread that can be forwarded freely.
Phase 4: Coordinate access and technical actions
The asset return runs in parallel with access management. Build a separate, system-specific list for it. Typical checkpoints are:
- central identity provider and company email,
- privileged or administrative accounts,
- VPN, password manager and remote access,
- source code, cloud and support systems,
- shared accounts or stored API keys,
- MDM actions for managed endpoints,
- passing on ownership of files, calendars or automations.
The ITAM should make the case and the asset relationship visible but is not automatically the leading system for disabling accounts. Carry out each action in the identity, SaaS or MDM system and record in the offboarding who confirmed it.
Timing and order depend on the departure scenario and internal rules. A blanket rule such as "always delete all accounts immediately" can undercut necessary handovers or defined retention processes. Use approved runbooks for each kind of system.
Phase 5: Document collection and condition
On acceptance, a second person or a clearly named IT role should check the return against the asset list. Document per item:
- asset tag or serial number,
- actual date of receipt,
- return route and the person accepting it,
- externally visible condition,
- accessories included,
- missing or deviating parts,
- the next intended status.
Separate facts from judgements. "Display cracked at the top left" is more useful than "poor condition". Photos can make sense under internal policy, particularly for shipping or damage cases. Decide in advance where such evidence is stored and who may access it.
Do not mark a device as available the moment it physically arrives. Until inspection, data handling and technical preparation are complete, it needs a suitable interim status.
Phase 6: Inspect the device and prepare it for the next use
After collection comes a standardised technical sequence. Depending on device and policy it can include:
- reconciling serial number and MDM relationship,
- carrying out a functional and visual inspection,
- handing over required company data by the approved process,
- checking device locks or activation locks,
- performing a reset or wipe through the responsible tool,
- deciding on repair, storage, reissue or disposal,
- updating status and location in the inventory.
Document not only that a measure was planned but its completion or the specific exception. A device with an outstanding inspection must not appear as "available" in the inventory by accident.
In the event of loss, suspected tampering or an unreachable device, the normal sequence should hand over to a defined security process. There, MDM measures, internal reporting, assessment and further steps are decided by the roles responsible for them.
Phase 7: Check licences, contracts and running costs
Besides devices, review licences tied to or assigned to the person:
- Is the licence deactivated, returned to a pool or transferred?
- Are there running subscriptions outside the central identity provider?
- Does the person own an integration, a bot or an automation?
- Do billing or administrative contacts need changing?
- Are there leasing, mobile or other contracts with a separate process?
"Account disabled" does not necessarily mean "licence available again". Confirm both separately in the respective system. For rarely used SaaS products the offboarding is a good checkpoint but does not replace regular licence management.
Phase 8: Manage open exceptions and close the case
A case can also continue in a controlled way with an open return. In that event record:
- the missing item,
- the last known place or status,
- the steps already taken,
- the responsible person,
- the next review date,
- the agreed escalation.
Only close the offboarding once every task is either done or handed over as a separately tracked exception. The closure should contain a short summary: assets returned, items missing, technical measures completed and remaining responsibilities.
The compact offboarding checklist
Before the last working day
- Leaving and return dates confirmed
- Owners named in HR, management and IT
- Complete asset and accessory list built
- Remote or on-site return organised
- System-specific access tasks scheduled
- File, calendar and process ownership handed over
At the return
- Asset tag or serial number reconciled
- Accessories checked individually
- Date of receipt and accepting person documented
- Condition and deviations recorded factually
- Device set to an inspection or refurbishment status
After the return
- Approved data and device actions completed
- MDM and identity measures confirmed
- Licences and running contracts reviewed
- Target status and location of every asset updated
- Open exceptions given an owner and a date
- Offboarding summarised and closed
Edge cases a standard process should catch
Remote work: shipping and arrival must be separate dates. Plan packaging, tracking and a contact for missing accessories.
A long absence before departure: bring the handover and return forward if the person will no longer be reachable on the last working day.
Shared devices: clarify whether only the user relationship changes or the device has to be physically collected and inspected.
BYOD: personal property is not reclaimed like company hardware. Remove company access and managed data by the BYOD process approved for it.
Loss or damage: switch to the defined incident or damage process. Questions of fault or cost should not be improvised by whoever happens to accept the device.
Immediate departure: use a prepared, confidential sequence with a clear order of access removal and a return arrangement that follows afterwards.
Modelling offboarding in AssetNode
In AssetNode you see the assets assigned to a person together with serial numbers, status and further inventory data. Returns and new assignments can be documented on the item itself. Workflows, notifications and integrations can support defined follow-up tasks; actions in identity and MDM systems deliberately stay with the tools responsible for them and with your internal rules.
Start with a verifiable standard sequence and add edge cases only where they actually occur. The managed AssetNode cloud is free for up to 100 assets. For internal use the fair-code, source-available version can be self-hosted with no limit on the number of assets.