A remote employee offboarding checklist has to close three things: the employment, the device and the access. HR reliably closes the employment, and IT usually gets the laptop back. The access granted informally across a remote team has no natural owner, and that is what stays open after someone leaves. The practical fix is a record of every grant of access kept from the first day, so that an exit means closing a list rather than reconstructing one.
This guide covers one layer of a larger operating standard. For how the exit fits with hiring, onboarding, devices, performance and compliance, see the employer’s guide to professional remote work.
Why the remote offboarding process fails between HR and IT
Remote offboarding fails because nobody owns the access that was granted informally, and remote work produces a great deal of it.
In an office, an exit has a physical shape: the badge comes back and the laptop is handed over at reception. Remotely, the laptop is in a flat in another city, the second factor for half the person’s accounts is an app on their own phone, and the accounts that matter most to the work, in the client’s CRM or a customer’s portal, were often created by a team lead in a few clicks and never passed through IT.
So the three parts of an exit sit with three owners, and only two of them have one:
The employment: owned by the employer, or by the employer of record. Final pay, statutory documents, tax and social security all have deadlines, so they get done.
The device: owned by IT. It is a physical object with a serial number, so its absence is visible.
The access: owned by whoever granted it, which in a remote team is everyone and therefore no one.
The breach data is consistent with this. Verizon’s 2026 Data Breach Investigations Report found internal actors in 12% of breaches and says insiders who leave with proprietary data are often hard to catch without specific offboarding processes. For people with access to the most sensitive data, it recommends triggering a review of their recent activity when they resign or are let go, a control it says has caught numerous breaches in its dataset. Verizon also counts former employees as external actors, so misuse by someone who has already left does not appear in that 12% at all. And in IBM’s Cost of a Data Breach Report 2026, breaches that began with the abuse of valid accounts averaged USD 5.07 million. An account left open after an exit is one more valid account available to abuse.
The security standards set out the same controls. NIST SP 800-53 Revision 5 control PS-4 (Personnel Termination) calls for disabling system access within a defined period and revoking the person’s credentials, and control AC-2 adds a process for changing shared account credentials when someone leaves the group. ISO/IEC 27001:2022 covers the same ground in Annex A controls 5.11 (Return of assets), 5.18 (Access rights) and 6.5 (Responsibilities after termination or change of employment).
The Access Ledger: you cannot revoke what you never recorded
The Access Ledger is a running list, per person, of every system, account, shared credential and device they have been given, with who granted it and when. It starts on the first day as part of onboarding (our remote onboarding guide sets out the provisioning side) and is updated every time access changes. On exit it becomes the checklist.
Reconstructing access at the point of exit reliably misses the same things: the tool someone signed up for on a free trial with their work address, the shared login pasted into a chat three months ago, the automation built under their account that now runs a weekly report. Nobody forgets the email account. Everybody forgets something on that list.
Two records catch most of what a ledger misses, and both are worth checking at every exit. The identity provider shows every application connected through single sign-on. The company’s card and invoice records show every paid tool, including the ones never connected to single sign-on, which are precisely the ones an access review overlooks.
The remote employee offboarding checklist
The employee offboarding checklist below runs in five stages and starts on the day notice is given. In Indonesia a resignation requires at least 30 days’ written notice (Government Regulation No. 35 of 2021, Pasal 36 huruf i). That notice period is the best offboarding window you will get, because the person is still working and still able to hand things over.
When | Step | Owner |
|---|---|---|
From notice | Start a review of the person’s recent activity: downloads, external shares, forwarding rules and new app grants | IT |
From notice | Open the person’s Access Ledger and reconcile it against the identity provider and the company’s billing records | Line manager with IT |
From notice | Agree a written handover: open work, customer relationships, recurring meetings and where each now sits | Line manager |
From notice | Transfer ownership of documents, shared folders, code repositories, dashboards and automations the person created | Line manager with IT |
From notice | Move admin and owner roles to a named successor and stop granting new access | IT |
From notice | Ask the person to move any personal files off the laptop before the last day | Line manager |
From notice | Confirm the last working day in writing and start the final pay calculation | Employer (or employer of record) |
From notice | Arrange the device’s return for the day after the last working day | IT (or managed IT provider) |
Last day, at an agreed hour | Disable the identity account and revoke active sessions, in the identity provider and in any app that keeps its own | IT |
Last day, at an agreed hour | Revoke third-party app grants authorised by the account | IT |
Last day, at an agreed hour | Remove the person from every system on the ledger that sits outside single sign-on | Line manager with IT |
Last day, at an agreed hour | Replace recovery phone numbers and emails, and remove authenticators, on shared or role-based accounts | IT |
Last day, at an agreed hour | Rotate every shared credential, service-account password and API key the person could see | IT |
Last day, at an agreed hour | Remove mail forwarding rules and delegated access; route the mailbox to the manager with an auto-reply | IT |
Last day, at an agreed hour | Remove the person from chat workspaces and customer-facing groups; move any business WhatsApp number to a company-held one | Line manager |
Last day, at an agreed hour | Remote-lock the laptop so it is inert until it is back | IT (or managed IT provider) |
First week | Receive the device, run a certified wipe, and record the serial number against the wipe certificate | IT (or managed IT provider) |
First week | Close the activity review, covering the notice period and the last day, and record the outcome; reassign or cancel licences | IT |
By the end of the month after departure | Pay the final entitlements, issue the withholding slip, and issue the resignation letter the employee needs to claim JHT | Employer (or employer of record) |
30 to 90 days | Reconcile billing again for any account still charging; archive or delete records per the retention schedule | IT with finance |
30 to 90 days | Add anything this exit surfaced to the ledger template, so the next one catches it at onboarding | IT |
The agreed hour on the last day is deliberate. Cutting access at 9am on someone’s final day wastes a day of handover and tells a loyal employee they were never trusted. Cutting it at midnight three days later leaves a window nobody is watching. Agree the time with the person, run every last-day step in that hour, and tell them it is standard, because it should be.
The IT offboarding checklist: eight places most exits miss
The items that stay open after a remote exit are almost always the same eight, and disabling an email account closes none of them on its own.
Active sessions and tokens. Disabling an account or resetting a password does not always end sessions that are already signed in, particularly on mobile apps. Revoke sessions in the identity provider, then check the session lists of high-risk apps that keep their own, since not every app is deprovisioned automatically.
Third-party app grants. Apps a person connected to their work account (a scheduling tool, a browser extension, an AI assistant reading their mailbox) hold their own authorisation. Review and revoke those grants as a separate step.
Shared credentials. Team logins kept in a password manager, a spreadsheet or a chat thread. If the person could see a credential, rotate it. A password manager that records who opened which item turns this from a guess into a short job.
Authenticators and recovery details on a personal phone. A company account whose recovery number is the leaver’s personal mobile can, in principle, be recovered by the leaver. Replace recovery details and remove registered authenticators on every shared or role-based account.
Forwarding rules and delegations. A rule set up to “keep an eye on things while travelling” will keep sending company mail to a personal address long after the person has gone. Check for rules and for delegated access to shared mailboxes and calendars.
Accounts in client and customer systems. In an outsourced or employer-of-record arrangement, much of the access that matters lives in the client’s own tools, and some in the end customer’s portals. The employer of record cannot see those accounts, so the client has to close them. Put them on the ledger the moment they are created.
WhatsApp and personal numbers. In our experience running Indonesian teams, a great deal of day-to-day customer and supplier communication happens on WhatsApp. When a business conversation lives on an employee’s personal number, the relationship leaves with the number. The fix belongs at onboarding: customer-facing roles use a company-held WhatsApp Business number, never a personal SIM.
API keys, personal access tokens and automations. Keys issued to a developer, tokens used by scripts, and no-code automations built under the person’s account. These are an operational gap as well as a security one: delete the account without transferring them and the weekly report, the data sync or the deployment pipeline quietly stops.
Getting the laptop back from a home office
Lock first, collect second. Remote-lock the laptop at the agreed hour on the last day, so the device is inert whatever happens to the return date, and ask the person to move their personal files off it beforehand. When it comes back, check it against the provisioning record (charger, peripherals, serial number) and run a certified wipe before it is reassigned.
The wipe certificate is the part employers skip, and it is the part that matters if a regulator, an auditor or a client ever asks what happened to the data on that machine. A documented wipe matched to the serial number is evidence. “IT reset it” is not.
If a device is not returned, the lawful route in Indonesia is narrower than many foreign employers assume. Government Regulation No. 36 of 2021 on Wages allows a deduction for compensation for loss (ganti rugi) only where the employment contract, company regulations or collective agreement provide for it, and caps all deductions at 50% of each wage payment (Pasal 63 and 65). Put the return obligation and its consequence into the employment documents at the start, and take advice before making any deduction from final pay.
On a fleet managed through MDM, most of this is routine. Our guide to remote work device security and MDM covers the controls that make remote lock and wipe possible in the first place: without enrolment, the device is only as secure as the person holding it.
The employment exit in Indonesia runs alongside the security steps
The employment side of an Indonesian exit has statutory steps with their own deadlines, and they should run in parallel with the security steps rather than after the laptop is back. The points below are indicative, read from the regulations on 24 September 2026; confirm them with Indonesian legal counsel for any real case.
Notice. A resigning employee must submit a written request at least 30 days before the resignation date, must not be bound by a service bond (ikatan dinas), and must keep working until that date (PP 35/2021, Pasal 36 huruf i).
Final entitlements. A voluntary resignation carries no severance (pesangon) and no long-service payment (UPMK). The employee receives compensation for rights (uang penggantian hak), covering untaken annual leave, the cost of returning to the place of hire and anything else set in the employment documents, plus a separation payment (uang pisah) whose amount PP 35/2021 leaves to the contract, company regulations or collective agreement (Pasal 40 ayat (4) and Pasal 50). Set the uang pisah before the first resignation, not during it.
Tax. PPh 21 is recalculated in the month the employee stops working, which Minister of Finance Regulation No. 168 of 2023 treats as their last tax period (Pasal 1 angka 18), and the employer must give them a withholding slip (bukti potong) (Pasal 20 ayat (1) huruf b). The regulation’s worked example, and Pasal 21 where tax was over-withheld, put that by the end of the following month.
Old-age savings (JHT). A resigning employee can claim JHT in cash and in full after a one-month waiting period that runs from the date of the employer’s letter confirming the resignation, and the claim must attach that letter (Minister of Manpower Regulation No. 4 of 2022, Pasal 8 and 9). A late letter delays the employee’s money, so issue it promptly. Resignation does not qualify for the job-loss benefit, JKP (PP 37/2021, Pasal 20, as amended by PP 6/2025).
Employment certificate. As we read the Civil Code (Pasal 1602z), when employment ends the employer must, if the employee asks, provide a signed statement of the nature of the work and how long it lasted, and, on a specific request, of how they performed and why the employment ended.
Personnel records. Under Law No. 27 of 2022 on Personal Data Protection, a controller must end processing when the retention period is reached or the purpose is achieved, delete or destroy data it no longer needs, and tell the person it has done so (Pasal 42 to 45). Personnel records therefore need a written retention period, set with tax, social security and dispute rules in mind, and a recorded deletion at the end of it. An implementing Government Regulation has reportedly been issued (PP 33/2026, effective 16 January 2027). Where a client outside Indonesia also holds the records, the cross-border rules in our data protection primer for remote teams apply too.
A dismissal is a different process. Termination (PHK) in Indonesia needs a lawful ground and a defined procedure, set out in our guide to employee termination in Indonesia. For the security side the difference is timing: agree the access plan with the employer of record before the conversation happens, and treat any question of relieving someone of duties during the process as a matter for counsel.
When to cut access: by type of exit
The checklist stays the same across exits. What changes is how early the access steps run.
Type of exit | When access is removed | What to watch |
|---|---|---|
Resignation, amicable | Privileges reduced during notice; full removal at the agreed hour on the last day | Handover quality; ownership transfer of documents and automations |
Resignation to a competitor, or to a client’s competitor | Earlier where possible. The employee must keep working through the notice period, so whether to relieve them of duties is a question for counsel, raised through the employer of record | Unusual download or sharing activity during notice |
Dismissal (PHK) | Plan agreed before the conversation; timing follows the process counsel advises | Keep the process lawful and record every access decision |
Internal move to another team | Old access removed on the day of the move | Access that accumulates across roles and never gets removed |
The last row is the one most companies never treat as offboarding at all. Someone who has moved through three teams in two years often still holds the access of all three. NIST gives it a control of its own (PS-5, Personnel Transfer), which specifies reviewing and modifying access when a person is reassigned instead of adding the new role on top of the old one.
How MixWork handles the exit
MixWork is the legal employer for the teams we place in Indonesia, so the employment exit is ours to run: the final entitlements, the tax and social security steps, the statutory documents, and the PHK procedure where a termination applies. Your HR manager, backed by our HR team under Total Care 360, is the point of contact for timing, so the employment steps and your security steps can be scheduled together.
Where a client adds MixWork Managed IT, a priced add-on, the device side is ours too. Managed laptops are encrypted and enrolled from the day they are issued and can be remotely locked and wiped, and every returned device gets a certified wipe documented for your records before it is redeployed. Managed IT costs from USD 99 per device per month, with no deposit and no upfront hardware cost, on a three-month minimum term. Current rates for every service are on our pricing page.
The access inside your own systems is the part only you can close, which is why we suggest keeping an Access Ledger for your side of the team from the first day. With twelve-month retention across our placements running above 90%, most client teams will run this checklist rarely, and a process that runs rarely is exactly the one worth writing down. If you want the employment and device side of every exit run by one accountable partner, talk to us.
Note: Statutory references reflect Indonesian regulations as read on 24 September 2026 and are indicative. Indonesian employment law is changing: Constitutional Court Decision No. 168/PUU-XXI/2023 requires a new Manpower Law, and regulations are amended between statutes. Confirm current requirements with qualified Indonesian legal counsel before acting on them. Security statistics are attributed to their reports above. This article is general guidance, not legal advice.






