Employee Offboarding Automation: Access Revoked on Time, Nothing Deleted by Accident
How HR and IT automate offboarding: the leaver's access map, revocation tickets with deadlines, equipment return, handover and a confirmed close.
· Updated
Written by Max Zeshut
Founder at Agentmelt
Onboarding gets the attention: the welcome email, the laptop on the desk, the first-week calendar. Offboarding gets a checklist in a shared drive that someone last updated two years ago. The result is predictable — a contractor whose Google Workspace account is still active a month after they left, a laptop nobody asked for, a Slack workspace with forty deactivated-but-not-removed users, and a knowledge transfer that consisted of one meeting.
Buildable version: the employee offboarding automation workflow — what arrives, what happens, who approves, a free template, and the price to have it run for you.
Offboarding is more mechanical than onboarding, which makes it easier to automate well — and the cost of doing it badly is a security finding, not a bad first day. This post follows the employee offboarding blueprint, the second blueprint in the HR team package.
The eight steps
- Receive the termination record from the HRIS — BambooHR, Rippling or Workday — with the last day, the manager, and whether the exit is voluntary.
- Assemble the leaver's access map. Every system they hold an account in: the identity provider (Okta, Entra ID, Google Workspace), the SaaS tools behind it, and the ones outside SSO that HR keeps a list of. The map is the artefact everything else works from.
- Open revocation tickets with deadlines. One ticket per system owner in Jira Service Management or ServiceNow, each with the last day as the deadline and the specific accounts to disable. The workflow requests; IT executes.
- Schedule the equipment return. A message to the leaver with what to return, how, and by when — prepaid label or a desk drop — and a task for whoever receives it.
- Generate the knowledge-transfer checklist. From the leaver's role, their recurring meetings, the documents they own and the systems they administer: a list of what to hand over and to whom, drafted for the manager to edit.
- Hand off to finance and payroll. Final pay date, expense claims still open, any equipment not yet returned, benefits end date — one summary to the people who close those loops.
- Send the exit survey on the last day, from HR, with the answers going only to HR.
- Confirm closure. A scheduled check after the last day: every revocation ticket closed, equipment received, survey sent. Anything open is chased with its owner and the manager copied; nothing is marked done by assumption.
Requests, not actions
The workflow never disables or deletes anything itself. It opens tickets with deadlines and it checks that they were closed. That is a deliberate design choice, not a limitation: automated deprovisioning that removes an account on a date is how a mistaken termination record turns into a live employee locked out, or a shared mailbox lost with a leaver's account. IT executes each revocation, with a person's name on the ticket. The automation's job is to make sure none of them are forgotten and all of them are on time. Automated provisioning and deprovisioning through your SSO is a custom build done together with IT, once the request flow has run for a while.
Involuntary exits
A termination the person did not choose skips the welcome-style messaging. No "thank you for your time with us" from a bot, no exit survey by default, and the equipment message goes to the manager to deliver. The HRIS record carries the flag; the workflow reads it and switches the tone or the recipient.
What confirmed closure looks like
Two weeks after the last day, HR gets one message: nine of nine access tickets closed, laptop received on the 14th, survey completed, one expense claim still open with finance. Before the automation, that message did not exist; the answer to "is everything closed?" was "probably".
Where it stops
One country's documents and one identity provider. Several entities with different notice periods and equipment rules, or SSO-executed deprovisioning, are custom builds; the blueprint page lists the triggers.
For the HR team
Offboarding is the second blueprint in the HR team package, after new-hire onboarding and before interview scheduling. The kit ($49) and the install ($249) cover onboarding first; the package ($490) adds this and scheduling, installed in the HRIS, the identity provider and the IT desk you already run. As a company-side subscription it runs as a managed automation.
See also AI agents for employee onboarding and AI HR agents.
Sources and further reading
- Okta, API reference — the user lifecycle endpoints (deactivate, suspend) IT uses to execute the tickets: https://developer.okta.com/docs/reference/
- Google, Workspace Admin SDK — suspending users and transferring data for Google Workspace leavers: https://developers.google.com/workspace/admin
- Atlassian, Jira Service Management Cloud REST API — creating the revocation requests with due dates: https://developer.atlassian.com/cloud/jira/service-desk/rest/