HomeBlog › Offboarding Checklist for Jira

Offboarding Checklist for Jira: IT, HR, Legal & Security Steps

TL;DR: An employee offboarding checklist in Jira runs across five departments: IT revokes access and collects hardware, HR closes out payroll and benefits, legal confirms NDAs and any litigation hold, security invalidates keys and tokens, and the manager reassigns work and captures knowledge. The single biggest gotcha is timing: IT and security tasks have to be finished on or before the last day, because lingering credentials are how former employees end up linked to breaches. The reason this belongs in Jira rather than a Slack message is that offboarding is a coordination problem across teams on different timelines, and a checklist in someone's head will miss the tasks that feel least urgent.

Onboarding gets all the attention. There are templates, welcome kits, buddy programs, 90-day plans. Offboarding, meanwhile, is usually a Slack message to IT saying "can you disable Sarah's account?" followed by three weeks of discovering things that were never turned off.

This is a problem that compounds. Every incomplete offboarding leaves behind active credentials, lingering access to shared drives, API tokens nobody revoked, and knowledge that walked out the door without documentation. The risk is not theoretical. According to the Ponemon Institute, 20% of organizations have experienced data breaches linked to former employees.

Offboarding is a cross-department coordination problem, which makes it a perfect fit for structured checklists in Jira. Below is the full list, broken down by department.

IT and Infrastructure

IT owns the largest chunk of offboarding tasks, and these are the most time-sensitive. Every hour of delay after an employee's last day is an hour of unnecessary access.

For engineering-specific offboarding (SSH keys, deploy access, code review ownership), see the Engineering Offboarding template.

HR and People Operations

HR offboarding is less urgent than IT, but has legal deadlines attached to some of it.

If you are tracking leave in Jira, the departing employee's leave balance and history should be exported before their records are archived.

Legal and Compliance

Legal tasks are often overlooked because they involve paperwork that does not feel urgent. They are urgent.

Security

Security overlaps with IT but deserves its own section because these tasks are the ones that get skipped. For a deeper treatment, read The Security Tasks Everyone Forgets During Offboarding.

Timing matters. IT and security tasks should be completed on or before the employee's last day. HR and legal tasks can extend a few days after. If you are using a checklist in Jira, set due dates accordingly rather than treating everything as "do it when you can."

Manager and Knowledge Transfer

The manager is responsible for making sure the team does not lose institutional knowledge when someone leaves.

Why this belongs in Jira

Offboarding involves five departments doing different things on different timelines for the same person. That is a coordination problem, and coordination problems need a system of record. A checklist in someone's head, a Google Doc, or a Slack thread will not cut it when you are offboarding three people in the same month.

The General Offboarding template in TeamOps includes all of the above, pre-assigned by department and phased by urgency. Launch it for a departing employee and every task is created, assigned, and tracked automatically. You get a progress bar instead of a spreadsheet and a hope that nothing was missed.

If your offboarding needs are engineering-specific (deploy keys, code ownership, CI/CD access), the Engineering Offboarding template covers those additional steps.

Frequently asked questions

What should an employee offboarding checklist in Jira include?

A complete offboarding checklist covers five departments: IT (disable SSO, revoke SaaS access, rotate shared credentials, collect hardware), HR (final payroll, benefits termination, exit interview, HRIS update), legal (NDA confirmation, IP assignment, litigation hold, data retention), security (revoke SSH keys, invalidate access tokens, audit recent data exports), and the manager (reassign work and run a knowledge transfer). The tasks that get skipped are usually the security and legal ones, because they do not feel urgent.

How do you revoke Jira access when someone leaves?

Disable the employee's SSO or identity-provider account first (Okta, Azure AD, Google Workspace), since most Jira access is granted through SSO and disabling it cascades. Then remove the user directly in Jira and Atlassian admin so any non-SSO access is closed, and walk the SSO audit log to confirm nothing was missed. Do this on or before the last day.

What is the difference between an offboarding checklist and an offboarding workflow in Jira?

A checklist is the list of tasks that must happen when someone leaves. A workflow is how those tasks get created, assigned, sequenced by due date, and tracked to completion. In Jira, a checklist alone lives in a document or a Slack thread; a workflow turns it into assigned issues with owners and deadlines so nothing depends on someone remembering.

When should IT and security offboarding tasks be completed?

IT and security tasks should be done on or before the employee's last day, because every hour of lingering access after departure is unnecessary risk. HR and legal tasks can extend a few days after, since they involve paperwork with their own deadlines rather than live credentials.

Why do companies use Jira for employee offboarding?

Offboarding involves five departments working on different timelines for the same person, which is a coordination problem that needs a system of record. Jira gives every task an owner, a due date, and a status, so a manager sees a progress bar instead of trusting that a spreadsheet or a Slack thread caught everything.

TeamOps handles this inside Jira. Free for up to 10 users.