Remote Employee Offboarding Checklist: The Security Steps Most Companies Skip

Remote Employee Offboarding Checklist: The Security Steps Most Companies Skip

MixWork Team

·

Updated

·

14 min read

Key takeaways
  • An exit has three parts: the employment, the device and the access. The first two have natural owners. The access granted informally across a remote team has none, which is why it stays open.

  • Offboarding starts on the day notice is given. In Indonesia a resignation needs at least 30 days’ written notice (PP 35/2021, Pasal 36 huruf i). Use that window for handover, ownership transfer and a review of recent activity.

  • Keep an Access Ledger from day one: a per-person record of every system, account, shared credential and device, with who granted it and when. You cannot revoke what you never recorded.

  • Verizon’s 2026 Data Breach Investigations Report found internal actors in 12% of breaches. For people with access to the most sensitive data, it recommends triggering an activity review when they resign or are let go.

  • Eight places exits usually miss: active sessions and tokens, third-party app grants, shared credentials, authenticators and recovery details on personal phones, forwarding rules, client and customer accounts, WhatsApp on personal numbers, and API keys and automations.

  • Lock first, collect second, and keep the wipe certificate. A documented wipe matched to the serial number is evidence; “IT reset it” is not.

  • With MixWork as employer of record, we run the employment exit. Clients who add MixWork Managed IT (from USD 99 per device per month, with no deposit) also hand us the device side: remote lock, certified wipe and redeployment. The access inside the client’s own systems is the client’s to close.

A remote employee offboarding checklist has to close three things: the employment, the device and the access. HR reliably closes the employment, and IT usually gets the laptop back. The access granted informally across a remote team has no natural owner, and that is what stays open after someone leaves. The practical fix is a record of every grant of access kept from the first day, so that an exit means closing a list rather than reconstructing one.

This guide covers one layer of a larger operating standard. For how the exit fits with hiring, onboarding, devices, performance and compliance, see the employer’s guide to professional remote work.

Why the remote offboarding process fails between HR and IT

Remote offboarding fails because nobody owns the access that was granted informally, and remote work produces a great deal of it.

In an office, an exit has a physical shape: the badge comes back and the laptop is handed over at reception. Remotely, the laptop is in a flat in another city, the second factor for half the person’s accounts is an app on their own phone, and the accounts that matter most to the work, in the client’s CRM or a customer’s portal, were often created by a team lead in a few clicks and never passed through IT.

So the three parts of an exit sit with three owners, and only two of them have one:

  • The employment: owned by the employer, or by the employer of record. Final pay, statutory documents, tax and social security all have deadlines, so they get done.

  • The device: owned by IT. It is a physical object with a serial number, so its absence is visible.

  • The access: owned by whoever granted it, which in a remote team is everyone and therefore no one.

The breach data is consistent with this. Verizon’s 2026 Data Breach Investigations Report found internal actors in 12% of breaches and says insiders who leave with proprietary data are often hard to catch without specific offboarding processes. For people with access to the most sensitive data, it recommends triggering a review of their recent activity when they resign or are let go, a control it says has caught numerous breaches in its dataset. Verizon also counts former employees as external actors, so misuse by someone who has already left does not appear in that 12% at all. And in IBM’s Cost of a Data Breach Report 2026, breaches that began with the abuse of valid accounts averaged USD 5.07 million. An account left open after an exit is one more valid account available to abuse.

The security standards set out the same controls. NIST SP 800-53 Revision 5 control PS-4 (Personnel Termination) calls for disabling system access within a defined period and revoking the person’s credentials, and control AC-2 adds a process for changing shared account credentials when someone leaves the group. ISO/IEC 27001:2022 covers the same ground in Annex A controls 5.11 (Return of assets), 5.18 (Access rights) and 6.5 (Responsibilities after termination or change of employment).

The Access Ledger: you cannot revoke what you never recorded

The Access Ledger is a running list, per person, of every system, account, shared credential and device they have been given, with who granted it and when. It starts on the first day as part of onboarding (our remote onboarding guide sets out the provisioning side) and is updated every time access changes. On exit it becomes the checklist.

Reconstructing access at the point of exit reliably misses the same things: the tool someone signed up for on a free trial with their work address, the shared login pasted into a chat three months ago, the automation built under their account that now runs a weekly report. Nobody forgets the email account. Everybody forgets something on that list.

Two records catch most of what a ledger misses, and both are worth checking at every exit. The identity provider shows every application connected through single sign-on. The company’s card and invoice records show every paid tool, including the ones never connected to single sign-on, which are precisely the ones an access review overlooks.

The remote employee offboarding checklist

The employee offboarding checklist below runs in five stages and starts on the day notice is given. In Indonesia a resignation requires at least 30 days’ written notice (Government Regulation No. 35 of 2021, Pasal 36 huruf i). That notice period is the best offboarding window you will get, because the person is still working and still able to hand things over.

When

Step

Owner

From notice

Start a review of the person’s recent activity: downloads, external shares, forwarding rules and new app grants

IT

From notice

Open the person’s Access Ledger and reconcile it against the identity provider and the company’s billing records

Line manager with IT

From notice

Agree a written handover: open work, customer relationships, recurring meetings and where each now sits

Line manager

From notice

Transfer ownership of documents, shared folders, code repositories, dashboards and automations the person created

Line manager with IT

From notice

Move admin and owner roles to a named successor and stop granting new access

IT

From notice

Ask the person to move any personal files off the laptop before the last day

Line manager

From notice

Confirm the last working day in writing and start the final pay calculation

Employer (or employer of record)

From notice

Arrange the device’s return for the day after the last working day

IT (or managed IT provider)

Last day, at an agreed hour

Disable the identity account and revoke active sessions, in the identity provider and in any app that keeps its own

IT

Last day, at an agreed hour

Revoke third-party app grants authorised by the account

IT

Last day, at an agreed hour

Remove the person from every system on the ledger that sits outside single sign-on

Line manager with IT

Last day, at an agreed hour

Replace recovery phone numbers and emails, and remove authenticators, on shared or role-based accounts

IT

Last day, at an agreed hour

Rotate every shared credential, service-account password and API key the person could see

IT

Last day, at an agreed hour

Remove mail forwarding rules and delegated access; route the mailbox to the manager with an auto-reply

IT

Last day, at an agreed hour

Remove the person from chat workspaces and customer-facing groups; move any business WhatsApp number to a company-held one

Line manager

Last day, at an agreed hour

Remote-lock the laptop so it is inert until it is back

IT (or managed IT provider)

First week

Receive the device, run a certified wipe, and record the serial number against the wipe certificate

IT (or managed IT provider)

First week

Close the activity review, covering the notice period and the last day, and record the outcome; reassign or cancel licences

IT

By the end of the month after departure

Pay the final entitlements, issue the withholding slip, and issue the resignation letter the employee needs to claim JHT

Employer (or employer of record)

30 to 90 days

Reconcile billing again for any account still charging; archive or delete records per the retention schedule

IT with finance

30 to 90 days

Add anything this exit surfaced to the ledger template, so the next one catches it at onboarding

IT

The agreed hour on the last day is deliberate. Cutting access at 9am on someone’s final day wastes a day of handover and tells a loyal employee they were never trusted. Cutting it at midnight three days later leaves a window nobody is watching. Agree the time with the person, run every last-day step in that hour, and tell them it is standard, because it should be.

The IT offboarding checklist: eight places most exits miss

The items that stay open after a remote exit are almost always the same eight, and disabling an email account closes none of them on its own.

  1. Active sessions and tokens. Disabling an account or resetting a password does not always end sessions that are already signed in, particularly on mobile apps. Revoke sessions in the identity provider, then check the session lists of high-risk apps that keep their own, since not every app is deprovisioned automatically.

  2. Third-party app grants. Apps a person connected to their work account (a scheduling tool, a browser extension, an AI assistant reading their mailbox) hold their own authorisation. Review and revoke those grants as a separate step.

  3. Shared credentials. Team logins kept in a password manager, a spreadsheet or a chat thread. If the person could see a credential, rotate it. A password manager that records who opened which item turns this from a guess into a short job.

  4. Authenticators and recovery details on a personal phone. A company account whose recovery number is the leaver’s personal mobile can, in principle, be recovered by the leaver. Replace recovery details and remove registered authenticators on every shared or role-based account.

  5. Forwarding rules and delegations. A rule set up to “keep an eye on things while travelling” will keep sending company mail to a personal address long after the person has gone. Check for rules and for delegated access to shared mailboxes and calendars.

  6. Accounts in client and customer systems. In an outsourced or employer-of-record arrangement, much of the access that matters lives in the client’s own tools, and some in the end customer’s portals. The employer of record cannot see those accounts, so the client has to close them. Put them on the ledger the moment they are created.

  7. WhatsApp and personal numbers. In our experience running Indonesian teams, a great deal of day-to-day customer and supplier communication happens on WhatsApp. When a business conversation lives on an employee’s personal number, the relationship leaves with the number. The fix belongs at onboarding: customer-facing roles use a company-held WhatsApp Business number, never a personal SIM.

  8. API keys, personal access tokens and automations. Keys issued to a developer, tokens used by scripts, and no-code automations built under the person’s account. These are an operational gap as well as a security one: delete the account without transferring them and the weekly report, the data sync or the deployment pipeline quietly stops.

Getting the laptop back from a home office

Lock first, collect second. Remote-lock the laptop at the agreed hour on the last day, so the device is inert whatever happens to the return date, and ask the person to move their personal files off it beforehand. When it comes back, check it against the provisioning record (charger, peripherals, serial number) and run a certified wipe before it is reassigned.

The wipe certificate is the part employers skip, and it is the part that matters if a regulator, an auditor or a client ever asks what happened to the data on that machine. A documented wipe matched to the serial number is evidence. “IT reset it” is not.

If a device is not returned, the lawful route in Indonesia is narrower than many foreign employers assume. Government Regulation No. 36 of 2021 on Wages allows a deduction for compensation for loss (ganti rugi) only where the employment contract, company regulations or collective agreement provide for it, and caps all deductions at 50% of each wage payment (Pasal 63 and 65). Put the return obligation and its consequence into the employment documents at the start, and take advice before making any deduction from final pay.

On a fleet managed through MDM, most of this is routine. Our guide to remote work device security and MDM covers the controls that make remote lock and wipe possible in the first place: without enrolment, the device is only as secure as the person holding it.

The employment exit in Indonesia runs alongside the security steps

The employment side of an Indonesian exit has statutory steps with their own deadlines, and they should run in parallel with the security steps rather than after the laptop is back. The points below are indicative, read from the regulations on 24 September 2026; confirm them with Indonesian legal counsel for any real case.

  • Notice. A resigning employee must submit a written request at least 30 days before the resignation date, must not be bound by a service bond (ikatan dinas), and must keep working until that date (PP 35/2021, Pasal 36 huruf i).

  • Final entitlements. A voluntary resignation carries no severance (pesangon) and no long-service payment (UPMK). The employee receives compensation for rights (uang penggantian hak), covering untaken annual leave, the cost of returning to the place of hire and anything else set in the employment documents, plus a separation payment (uang pisah) whose amount PP 35/2021 leaves to the contract, company regulations or collective agreement (Pasal 40 ayat (4) and Pasal 50). Set the uang pisah before the first resignation, not during it.

  • Tax. PPh 21 is recalculated in the month the employee stops working, which Minister of Finance Regulation No. 168 of 2023 treats as their last tax period (Pasal 1 angka 18), and the employer must give them a withholding slip (bukti potong) (Pasal 20 ayat (1) huruf b). The regulation’s worked example, and Pasal 21 where tax was over-withheld, put that by the end of the following month.

  • Old-age savings (JHT). A resigning employee can claim JHT in cash and in full after a one-month waiting period that runs from the date of the employer’s letter confirming the resignation, and the claim must attach that letter (Minister of Manpower Regulation No. 4 of 2022, Pasal 8 and 9). A late letter delays the employee’s money, so issue it promptly. Resignation does not qualify for the job-loss benefit, JKP (PP 37/2021, Pasal 20, as amended by PP 6/2025).

  • Employment certificate. As we read the Civil Code (Pasal 1602z), when employment ends the employer must, if the employee asks, provide a signed statement of the nature of the work and how long it lasted, and, on a specific request, of how they performed and why the employment ended.

  • Personnel records. Under Law No. 27 of 2022 on Personal Data Protection, a controller must end processing when the retention period is reached or the purpose is achieved, delete or destroy data it no longer needs, and tell the person it has done so (Pasal 42 to 45). Personnel records therefore need a written retention period, set with tax, social security and dispute rules in mind, and a recorded deletion at the end of it. An implementing Government Regulation has reportedly been issued (PP 33/2026, effective 16 January 2027). Where a client outside Indonesia also holds the records, the cross-border rules in our data protection primer for remote teams apply too.

A dismissal is a different process. Termination (PHK) in Indonesia needs a lawful ground and a defined procedure, set out in our guide to employee termination in Indonesia. For the security side the difference is timing: agree the access plan with the employer of record before the conversation happens, and treat any question of relieving someone of duties during the process as a matter for counsel.

When to cut access: by type of exit

The checklist stays the same across exits. What changes is how early the access steps run.

Type of exit

When access is removed

What to watch

Resignation, amicable

Privileges reduced during notice; full removal at the agreed hour on the last day

Handover quality; ownership transfer of documents and automations

Resignation to a competitor, or to a client’s competitor

Earlier where possible. The employee must keep working through the notice period, so whether to relieve them of duties is a question for counsel, raised through the employer of record

Unusual download or sharing activity during notice

Dismissal (PHK)

Plan agreed before the conversation; timing follows the process counsel advises

Keep the process lawful and record every access decision

Internal move to another team

Old access removed on the day of the move

Access that accumulates across roles and never gets removed

The last row is the one most companies never treat as offboarding at all. Someone who has moved through three teams in two years often still holds the access of all three. NIST gives it a control of its own (PS-5, Personnel Transfer), which specifies reviewing and modifying access when a person is reassigned instead of adding the new role on top of the old one.

How MixWork handles the exit

MixWork is the legal employer for the teams we place in Indonesia, so the employment exit is ours to run: the final entitlements, the tax and social security steps, the statutory documents, and the PHK procedure where a termination applies. Your HR manager, backed by our HR team under Total Care 360, is the point of contact for timing, so the employment steps and your security steps can be scheduled together.

Where a client adds MixWork Managed IT, a priced add-on, the device side is ours too. Managed laptops are encrypted and enrolled from the day they are issued and can be remotely locked and wiped, and every returned device gets a certified wipe documented for your records before it is redeployed. Managed IT costs from USD 99 per device per month, with no deposit and no upfront hardware cost, on a three-month minimum term. Current rates for every service are on our pricing page.

The access inside your own systems is the part only you can close, which is why we suggest keeping an Access Ledger for your side of the team from the first day. With twelve-month retention across our placements running above 90%, most client teams will run this checklist rarely, and a process that runs rarely is exactly the one worth writing down. If you want the employment and device side of every exit run by one accountable partner, talk to us.

Note: Statutory references reflect Indonesian regulations as read on 24 September 2026 and are indicative. Indonesian employment law is changing: Constitutional Court Decision No. 168/PUU-XXI/2023 requires a new Manpower Law, and regulations are amended between statutes. Confirm current requirements with qualified Indonesian legal counsel before acting on them. Security statistics are attributed to their reports above. This article is general guidance, not legal advice.

Frequently asked questions

It should close three things: the employment, the device and the access. The employment side covers notice, final pay, tax and social security documents. The device side is a remote lock, the device’s return and a certified wipe matched to the serial number. The access side is the one most checklists miss: active sessions and tokens, third-party app grants, shared credentials, authenticators and recovery details on personal phones, mail forwarding rules, accounts in client and customer systems, business WhatsApp numbers and API keys. Keeping a per-person Access Ledger from the first day turns that list into something you close rather than reconstruct.
Start on the day notice is given, not on the last day. Reduce admin roles, transfer ownership of documents and automations, and begin a review of recent activity during the notice period. Remove all remaining access in one agreed hour on the last working day. For a dismissal, agree the access plan with the employer of record before the conversation. For people with access to the most sensitive data, Verizon’s 2026 Data Breach Investigations Report recommends triggering an activity review when they resign or are let go.
Lock first, collect second. Remote-lock the laptop at the agreed hour on the last day so it is inert whatever the return date, then, once it is back, check it against the provisioning record, and run a certified wipe documented against the serial number. In Indonesia, a deduction from wages for an unreturned device is only lawful where the employment contract, company regulations or collective agreement provide for it, and all deductions are capped at 50% of each wage payment (PP 36/2021, Pasal 63 and 65). This is indicative; confirm with Indonesian legal counsel before making any deduction.
At least 30 days. Under Government Regulation No. 35 of 2021, Pasal 36 huruf i, a resigning employee must submit a written request at least 30 days before the resignation date, must not be bound by a service bond, and must keep working until that date. This is indicative; confirm current requirements with Indonesian legal counsel.
No severance (pesangon) and no long-service payment (UPMK). The employee receives compensation for rights, covering untaken annual leave, the cost of returning to the place of hire and anything else in the employment documents, plus a separation payment (uang pisah) set by the contract, company regulations or collective agreement (PP 35/2021, Pasal 40 ayat (4) and Pasal 50). The employer also recalculates PPh 21 in the month of departure and gives the employee a withholding slip, by the end of the following month in the regulation’s worked example (PMK 168/2023), and issues the resignation letter the employee needs to claim JHT. This is indicative; confirm with Indonesian legal counsel.
The work splits by what each party controls. With MixWork as employer of record, MixWork runs the employment exit: final entitlements, tax and social security steps, statutory documents and, where a termination applies, the PHK procedure. Where the client adds MixWork Managed IT, a priced add-on, MixWork also handles the device: remote lock, certified wipe on return and redeployment. The client closes the access inside its own systems and its customers’ systems, which the employer of record cannot see.
BG Image

Let's find you some great hires

Ready to scale with a professional team?

Avatar
+

You

Quick 15-minute call

Pick a time that works for you.

Vector
Vector
Element Image
BG Image

Let's find you some great hires

Ready to scale with a professional team?

Avatar
+

You

Quick 15-minute call

Pick a time that works for you.

Vector
Vector
Element Image
BG Image

Let's find you some great hires

Ready to scale with a professional team?

Avatar
+

You

Quick 15-minute call

Pick a time that works for you.

Element Image