When a senior teammate resigned on short notice last year, we discovered we didn't actually have an offboarding process — we had a vague collective memory of one. Return the laptop, run the exit payroll, kill the email account. We did those three things, felt responsible, and moved on. Then, three full weeks after their last day, someone noticed they still had active, full access to our customer CRM. Not malicious in the slightest — they'd long since started a new job and never logged back in. But it was a live credential to every customer record we had, sitting wide open, simply because it wasn't on anyone's list. It wasn't on anyone's list because there was no list.
The problem was ownership, not steps
We sort of knew the steps. What we didn't have was a single source of truth that assigned each step to a specific person and actually covered the whole surface area. IT didn't have a list of the third-party SaaS tools this person used — half of them were apps they'd signed up for with a company card and a personal-feeling login that never touched our central directory. Finance didn't know whether there were outstanding expenses. The manager wasn't sure what knowledge had genuinely been transferred versus what had been promised in a hallway conversation and then forgotten. Four people each held roughly a quarter of the picture and each quietly assumed the other three had their quarters handled.
That's the failure mode of every informal process: it's not that anyone is careless, it's that responsibility is diffuse enough that the gaps are invisible until one of them becomes a security incident or a payroll error or, in our case, an open door to our customer data.
Building a process that survives a rushed exit
For the next departure I ran the Offboarding Checklist & Warm Farewell Email Generator prompt through Grok 4.3. I listed every system the person had access to — and this time I was genuinely thorough, including the obscure analytics tool and the design-file account nobody thinks about — and pasted in their transition notes. The checklist came back grouped by phase, with every single line assigned to [IT], [HR], [Manager], or [Employee], and crucially, it flagged two systems that held customer and project data with an explicit instruction to archive before revoking. Grok 4.3 handled the breadth of this well and returned it fast, which genuinely matters when you're racing a last day and don't have a week to assemble a checklist by committee.
- Every system access revoked on the last day — nothing missed, including the CRM this time
- The archive-before-revoke flag caught two systems we'd otherwise have wiped with no backup, including a folder of customer contracts
- Exit interview scheduled within 48 hours of the last day, a first for us
- The farewell email was drafted, approved, and sent the same morning as the announcement instead of three awkward days later
The farewell email is the part people remember
Part two of the prompt — the internal farewell email — seemed like a throwaway feature when I first read the output, and it turned out to matter more than almost anything else. It produced a warm, specific note from the manager that named the project the departing person had led and wished them well in a way that read genuine rather than corporate. It also, by design, said nothing whatsoever about why they were leaving, which kept it appropriate regardless of whether the departure was a happy resignation or something more complicated. Two former colleagues messaged me afterward to say it was the kindest departure note they'd received anywhere they'd worked. That costs nothing to write and it shapes how both the person leaving and, just as importantly, the people staying feel about the place. Everyone watches how you say goodbye.
The honest caveat
I have to be clear-eyed about what this prompt is: it's a checklist generator, not a security tool. It will only revoke access for the systems you actually tell it about, so the discipline of maintaining an accurate per-role list of every credential is still entirely on you and your IT team. The prompt's value is that once you have that list, it converts it instantly into an owner-assigned, phase-organized, archive-aware checklist that nothing falls through. So I built that master list once, per role, and now I keep it current as part of onboarding — which means the offboarding is half-done before anyone ever resigns. Grab the Offboarding Checklist & Warm Farewell Email Generator prompt on Prompt Dock before your next departure, and pair it with my 30-Day New-Hire Onboarding Plan, Week by Week prompt so the door swings both ways with the same care; the way you close a chapter says as much about your culture as the way you open one.