The leaver who still had access: what exit software has to switch off, and when
Ganesh HS ·
In brief
Exit is a checklist across eight owners; software is how the checklist runs itself.
Access revocation is triggered by the resignation, scheduled to the last day — not remembered afterwards.
Full-and-final needs inputs from four places; the system collects them or someone chases them.
The exit record is what the business relies on months later, when the person is not there to ask.
An IT manager, running a routine review, found that an employee who had left three weeks earlier could still log into the sales system, the shared drive and the email account. Nobody had told IT the leaving date. HR had processed the exit, payroll had paid the settlement, the manager had held the farewell, and the one step that carried real risk had simply not been assigned to anyone. It was not negligence. It was eight owners and no list.
Offboarding is a coordination problem — a dozen actions across HR, IT, finance, the manager and facilities, each with a date — and coordination is what software is for. The value of an exit system is not that it records the resignation. It is that the resignation triggers everything else.
The resignation is the trigger
What one resignation should start
DAY 0 resignation logged; last working day computed
notice period, handover owner, exit interview date set
IT: access-end scheduled to last day, not requested later
FINANCE: settlement inputs requested, due date set
FACILITIES: asset return list generated from issue records
DAY -7 handover checklist due; manager confirms
DAY -1 asset return; access revocation confirmed for tomorrow
DAY 0 last working day; access off; clearances signed
DAY +N full-and-final computed from collected inputs; paid
Nothing on this list depends on someone remembering.
The shift is from remembering to scheduling. The moment a leaving date exists, every dependent action has a due date and an owner, and each owner sees their own list. IT does not need to be told; IT has a task dated to the last working day that appeared the day the resignation was logged. That is the whole product, and it is the part a spreadsheet cannot do.
Access, and why the last day is the wrong trigger
Most access revocation fails because it is triggered by the last day — someone is supposed to notice the person has gone and act. The reliable trigger is the resignation, with the action scheduled forward. Access to the most sensitive systems ends on the last working day; email may forward for a stated period; anything customer-facing transfers before the person leaves rather than after. The system holds the schedule; IT executes it. A separate, earlier step handles the rare case where access should end immediately on notice.
The list of what to revoke comes from the same place as the list of what to return: the record of what was issued at joining. Where onboarding recorded every system, device and credential against the person, exit is the mirror. Where it did not, exit is guesswork, and the IT manager's routine review is the only safeguard. This is why onboarding and employee movement and exit belong in one system: the issue record is the return list.
Full-and-final needs four inputs
1
Attendance and leave, to the last day
From the attendance system: days worked, leave taken, leave balance to encash. The number that is wrong most often, because the last month is closed in a hurry.
2
Recoveries
Advances, loans, asset damage, notice shortfall. Each needs an owner to confirm the amount; the system chases them.
3
Variable pay and pending claims
Incentives earned to date, expense claims submitted and not yet paid. Sales and field roles are where this is largest and most disputed.
4
Statutory components
Computed by payroll from the above. The exit system does not calculate these; it makes sure payroll has what it needs, on time.
The system's job is to collect the four, from four owners, by a date, and present them to payroll complete. A settlement paid late is almost always a settlement whose inputs arrived late, and the inputs arrived late because nobody was chasing them. The chasing is the product.
Handover as a task, not a hope
The step most often missing from an exit workflow is the one that costs most when it fails: handover of the work. The system can only help if handover is a task with an owner and a due date like the others — the leaver's manager confirms, a week before the last day, that clients have been introduced, systems documented, open items listed and a named person now holds each. Where that confirmation is a checkbox the manager ticks without looking, the exit is tidy and the work still walks out. Configure it as a short checklist the manager completes, per item, with the receiving person named. It is the only step in the workflow that protects the business rather than the record, and it is the one nobody thinks to make mandatory.
For senior and client-facing roles, add a second review a fortnight after the last day: did the named person actually pick each item up. That is the point at which a missed handover is still recoverable with a phone call to the leaver, and after which it is not.
The exit interview, and what to do with it
The exit interview is scheduled by the same trigger and is the least valuable part of the record if it is treated as a form. It becomes useful in aggregate: when reasons are captured as categories rather than prose, and when the categories are looked at by manager, team and tenure once a quarter. One team's leavers all citing the same thing is a finding the system makes visible and the individual interviews never did. That aggregate is what an exit and offboarding process is designed to feed, and the software is where the feed comes from.
What the record is for, later
A reference request, a year on: dates, role, reason for leaving as recorded.
A dispute about the settlement: what was computed, from what inputs, signed off by whom.
A rehire: whether they were marked eligible, and what the manager said at the time.
An audit: that access ended when it should have, with the dated confirmation.
Every one of those arrives when the people who handled the exit may themselves have moved on. The record is the only thing that will be there, which is why the trail — who did what, when — matters more than any individual step. An exit that was handled well but not recorded is, a year later, indistinguishable from one that was not handled at all.
Choosing
Exit belongs in the same system as the employee record, onboarding and payroll inputs. A standalone offboarding tool needs to be told who the person is, what they were issued and what they are owed — the three things the HRMS already knows — and every handover is a place the list breaks. The exit and offboarding module of a system that already holds the issue record and feeds payroll is the version that removes the coordination problem rather than relocating it.
Test it before buying with one scenario: log a resignation for a fictional employee, and check that IT, finance, facilities and the manager each see a dated task without anyone sending an email. If they do, the exit and offboarding workflow is doing the job. If someone still has to remember, it is a prettier spreadsheet.
Questions we are asked
The resignation, with the revocation scheduled to the last working day. Triggering on the last day itself relies on someone noticing, which is how a leaver keeps access for three weeks.
Usually because the inputs — final attendance, recoveries, pending claims, incentives — arrive late from four different owners. A system that chases them to a date is what fixes it; the calculation is fast once they are in.
No, for most growing businesses. It needs the employee record, the asset issue list and the payroll link, all of which the HRMS already holds. A separate tool re-creates every handover.
Individually, little. In aggregate — reasons by manager, team and tenure, quarterly — they surface patterns nobody sees one interview at a time. Capture reasons as categories so they can be counted.
A separate, earlier step that ends access on notice rather than on the last day. It is the exception path, and the system should make it a deliberate choice rather than a scramble.
Forty-one reviews, in forty-one documents, in a folder nobody opens between March and March. What a performance system has to hold to be worth the licence, and the process decisions it will expose.
A complaint was raised in March, handled by someone who left in May, and nobody could find what was decided in September. What engagement and employee relations software has to record, who may see it, and why the audit trail is the product.
Every month, someone spends three days assembling headcount, attrition and cost from four sources into one deck. What HR reports automation actually changes, which reports are worth automating, and why most of the value is in the data underneath.
Read the article
Let’s find your next step
Is your HR process ready to scale?
Identify critical compliance gaps, payroll leaks, and hiring bottlenecks with a free 360-degree HR audit. Get a clear roadmap for your business.