Start with an authorized trigger and effective time
This checklist begins only after authorized internal leadership supplies a planned or unplanned departure trigger and an effective access-end time with a timezone. It does not decide whether someone should leave, why they are leaving, whether the decision is lawful, or when employment legally ends. Do not record a departure reason in this artifact.
Same-day is PlainFort operational framing around that supplied time—not a universal legal deadline, employment rule, certification, or promise that every access path can be revoked immediately.
NCSC identity and access guidance says an access-management policy typically covers when access is granted or revoked, commonly through a joiners, movers, and leavers process, and which actions should be recorded. The NCSC Cyber Assessment Framework says access rights should be reviewed and technically removed when no longer required, including when someone changes role or leaves.
Those sources support access lifecycle, review, and revocation objectives. They do not establish a universal same-day legal deadline, prescribe the three time bands, seven stages, 18 fields, or closure test, determine employment handling, validate a completion claim, or authorize a destructive action. Those elements are PlainFort editorial choices.
Keep eight concepts separate
- Authorized trigger — the instruction that offboarding must occur; no departure reason.
- Effective access-end time — supplied by authorized leadership, never inferred by the checklist.
- Target access path — a non-secret identity, authenticator, session, privilege, shared-access, automation, or device-handoff reference.
- Action owner and authority — who coordinates or later executes; naming a role does not create competence or authority.
- Expected action and dependency — the bounded result plus AA-06/07/08/10 or provider dependencies, not a command.
- Completion evidence and location — non-secret evidence actually inspected, separate from a report that work occurred.
- Result, exception, and residual risk — completed, blocked, deferred, exception, or unknown, with reason and escalation.
- Closure and review trigger — who accepts residual risk, what remains open, and when the record reopens.
Completed — evidence inspected is different from Reported complete — evidence pending. Provider confirmation, an administrator’s report, and independently inspected state are different evidence types. A message that says done is not automatically completion evidence.
Use exactly three time bands
The bands and their order are PlainFort editorial judgment, not NCSC requirements or a universal technical sequence.
Before the effective time
Confirm authority and timing; assemble non-secret inventory and AA-06/07/08/10 references; assign owners, backup, escalation, communication boundary, and evidence locations; identify last-administrator, root, financial, production, recovery, shared-access, automation, personal-device, legal-hold, records, privacy, and incident concerns; and stop unresolved destructive actions. For an unplanned departure, record when this band is compressed or unavailable rather than fabricating preparation.
At the effective time
Coordinate separately authorized actions in dependency-safe order: attributable accounts and access paths, administrative privilege, relevant authenticators and recovery authority, sessions where supported, shared-access membership or the AA-10 pattern, and approved automation or delegation paths. This guide describes what must be accounted for; it supplies no platform commands and executes nothing.
After immediate revocation
Inspect non-secret evidence; reconcile blocked, deferred, and unknown items; confirm a surviving authorized administrator and continuity path; preserve provider delays and offline sessions as open; route device handoff without device-loss procedures; record exceptions and residual risk; communicate closure to authorized roles; and schedule follow-up.
Apply seven stages inside the bands
1. Validate trigger and authority
Confirm the authorized request, effective time and timezone, scope, confidentiality boundary, coordinator, executor roles, backup, closure authority, and escalation. Do not record the departure reason.
2. Build the access-action set
Consume existing non-secret inventory and AA-06/07/08/10 references. Include identities, authenticators, sessions, privileges, shared paths, automation, delegation, integrations, and device handoff as categories. Mark unknown SaaS and incomplete inputs visibly.
3. Sequence by dependency and continuity
Preserve a surviving authorized path. Stop before last-administrator lockout, loss of recovery authority, interruption of financial or production work, or an action whose ownership is unclear.
4. Prepare the before-time handoff
Record owners, backup, authorized communication channel, evidence locations, exception authority, provider dependencies, and stop conditions. Preparation is not execution.
5. Coordinate at-time revocation
Record the expected authorized result for each path without commands, secrets, hands-on claims, or destructive instructions. Keep unsupported session, token, automation, and provider behavior explicit.
6. Inspect evidence and reconcile exceptions
Separate reported completion from inspected evidence. Keep provider delays, offline sessions, shared-credential uncertainty, missing inventory, personal-device dependencies, and unresolved automation open with owners and escalation.
7. Close or schedule follow-up
Record accepted residual risk, surviving ownership, unresolved items, closure authority, and next review. Do not close the checklist merely because the effective time has passed.
Keep every access path visible
Use generic categories only: individual work identities; password-manager membership; MFA authenticator and recovery-authority references; administrative identities and privilege; shared, delegated, brokered, or controlled-shared access; sessions and provider-dependent tokens without values; automation, integrations, forwarding, delegation, and ownership transfers; and business-owned device handoff as a reference only.
Unknown SaaS, personal devices, offline sessions, cached access, provider delays, undiscovered automation, retained copies, and data ownership remain residual risks. Known rows being complete does not prove complete discovery.
Stop before continuity loss or destructive handling
Stop and escalate when:
- authority or effective time is unclear or contradictory;
- an action may remove the last administrator, recovery authority, financial approver, production operator, root access, or essential business path;
- a personal device, disputed ownership, legal hold, records retention, privacy, surveillance, employee communication, or data-ownership question is involved;
- the departure is contentious, evidence is missing, compromise is suspected, or an incident is active;
- an action may delete data, transfer ownership, wipe a device, rotate a shared secret, invalidate recovery, or interrupt production;
- provider behavior, offline sessions, automation, or revocation evidence cannot be established safely.
Use Blocked — authority unclear, Blocked — last administrator, Blocked — legal or records review, Blocked — incident path required, Deferred — provider delay, or Unknown — follow up. Do not replace a blocked high-risk item with an easier task and then declare completion.
Break-glass is only a dependency here. This checklist does not create, configure, reveal, test, remove, or rotate an emergency-access path.
Preserve sibling ownership
AA-06 owns password-manager rollout, ordinary credential migration, recovery readiness, adoption, and legacy-storage decisions. AA-09 may coordinate authorized membership removal or transfer under the approved pattern; it does not run a rollout, move credentials, export a vault, execute recovery, or delete legacy material.
AA-07 owns MFA-method properties, fallback, accessibility, replacement, and recovery tradeoffs. AA-09 may reference separately authorized authenticator removal or recovery-authority change; it does not choose a method, perform recovery, reveal material, or improvise replacement.
AA-08 owns everyday/administrator separation, privilege, elevation, backup, and steady-state exceptions. AA-09 consumes that map; it does not redesign roles, rescore privilege, or create an administrator without separate authority and continuity review.
AA-10 owns whether sharing is eliminated, individualized, delegated, brokered, controlled, or exceptionally retained. AA-09 applies that pattern; it does not reveal or rotate a shared secret or rerun the six outcomes. Do not claim a person’s access is removed when the shared credential remains usable through an unresolved path.
Route device loss and incidents by trigger
Device-loss guidance is triggered by loss or theft and owns containment, remote-management decisions, evidence preservation, and recovery for that trigger. AA-09 records only an authorized device-handoff dependency. A missing device changes the trigger and routes to device-loss or incident guidance; do not wipe, inspect, search, or recover it here.
Incident roles and trigger-specific runbooks own incident-wide accountability, communications, evidence preservation, containment, and recovery. Suspected compromise, malicious activity, missing evidence, or an active incident stops routine offboarding. AA-09 is not an incident playbook.
Use an 18-field vertical checklist record
Use one block per target access path, not a wide table.
- Authorized departure trigger reference — a controlled non-secret reference; no departure reason.
- Effective access-end time and timezone — supplied by authority; never inferred.
- Confidentiality and communication boundary — authorized roles and channel category; no message content.
- Internal coordinator and closure authority — roles accountable for coordination and residual-risk acceptance.
- Authorized executor and backup/escalation role — authority and coverage; naming is not proof of competence.
- Non-secret person-role and target access reference — role plus invented or controlled reference; no identity or account ID.
- Access-path category and privilege/business impact — generic category and interruption consequence.
- Source inventory and AA-06/07/08/10 dependency references — non-secret references and any missing input.
- Time band — before, at, or after the effective time.
- Expected bounded action or handoff — outcome category only; no platform instruction.
- Continuity, surviving administrator, and interruption check — surviving authority, backup, and stop threshold.
- Provider, offline-session, automation, device, or recovery dependency — unknowns remain visible.
- Non-secret evidence required and evidence location — what will be inspected and where its controlled reference exists.
- Observed result and evidence strength — inspected, reported, pending, unknown, or contradicted.
- Exception, blocked, deferred, or unknown reason, and residual risk — reason, owner, expiry or retry where applicable.
- Escalation destination and required decision — role or qualified-help category, not personal contact data.
- Closure state and unresolved follow-up owner — truthful closure or named role for open work.
- Next review, retry, or exit trigger — provider response, evidence result, discovered access, returned/missing device, role change, incident, or contradiction.
States include Prepared — not yet effective, Completed — evidence inspected, Reported complete — evidence pending, Blocked — authority unclear, Blocked — last administrator, Blocked — incident path required, Deferred — provider delay, Unknown access — follow up, Exception — owner and expiry required, and Closed with residual risk accepted. They are workflow labels, not proof of complete discovery or revocation.
Fictional example — do not copy as a completed offboarding record
Example Co. is preparing for an invented departing support role with the synthetic effective time Day 0, 17:00, Example Time. No person, account, employment fact, provider, device, credential, incident, or real timestamp is represented.
- Authorized departure trigger reference:
Synthetic authorization A-01; reason not recorded. - Effective access-end time and timezone:
Day 0, 17:00, Example Time; invented and supplied, not inferred. - Confidentiality and communication boundary:
Authorized operations and leadership roles — controlled channel category. - Internal coordinator and closure authority:
Operations leadcoordinates;Business owneraccepts residual risk. - Authorized executor and backup/escalation role:
System administrator role; backup coverage is incomplete. - Non-secret person-role and target access reference:
Departing support role — ExampleDesk membership S-01; no identity. - Access-path category and privilege/business impact:
Individual support membership — business-hours continuity; privileges remain bounded by AA-08. - Source inventory and AA-06/07/08/10 dependency references:
Inventory incomplete; AA-06 membership, AA-07 authenticator, AA-08 privilege, and AA-10 shared-path references remain visible. - Time band:
At effective time; related preparation and evidence checks also appear in the before/after bands. - Expected bounded action or handoff:
Separately authorized membership removal expected; no command or action occurs here. - Continuity, surviving administrator, and interruption check:
Blocked — last administratorfor an invented administration path until backup is confirmed. - Provider, offline-session, automation, device, or recovery dependency:
Deferred — provider delayfor session confirmation; device handoff recorded without device-loss procedures. - Non-secret evidence required and evidence location:
Membership-state evidence — controlled reference E-01; no screenshot or identifier appears. - Observed result and evidence strength:
Completed — evidence inspectedfor the fictional individual membership only; shared and offline paths remain unproven. - Exception, blocked, deferred, or unknown reason, and residual risk:
Unknown access — follow up; incomplete SaaS input and shared-path uncertainty remain. - Escalation destination and required decision:
Business owner and qualified administrator; determine continuity before the blocked path changes. - Closure state and unresolved follow-up owner:
Open — operations lead; provider delay, AA-10 dependency, and inventory reconciliation remain. - Next review, retry, or exit trigger: provider response, backup confirmation, discovered SaaS, returned or missing device, evidence contradiction, or suspected compromise.
The example exercises all three bands: preparation before Day 0, the expected at-time membership result, and after-time evidence reconciliation. Its closure remains open. It performs no offboarding and does not claim the provider, shared path, session, device, or inventory is resolved.
Know what completion means
A row is complete only when authority, timing, target, dependency, expected action, evidence, observed result, continuity, exception/escalation, and follow-up are truthful. The overall checklist closes only when every in-scope row is complete or visibly blocked, deferred, or excepted with an owner and next trigger; a surviving authorized path exists; and closure authority accepts the recorded residual risk.
Closure does not prove complete discovery, provider-side revocation, session invalidation, device return, absence of retained data, successful recovery, evidence preservation, legal compliance, or security. Reopen on discovered access, provider response, failed evidence, a returned or missing device, ownership change, suspected compromise, or contradiction.