Employee Offboarding Checklist for Access Control

When someone leaves, collecting their keys is only one step. Check badges, door permissions and shared codes, with clear ownership and proof of removal.

Illustrative commercial entrance with a person presenting a mobile credential to a door reader

Someone leaves the business. Their laptop comes back, their email is closed, and the farewell message goes out. Who checked whether their office key or phone could still open the building?

The uncertainty appears from the employee’s side too. In a September 2024 public discussion, a former worker asked what to do with building keys nobody had requested back. That anonymous account is not evidence of a local crime trend. It is a useful reminder that a departure can leave both sides unsure about the handover. Public question about returning keys.

The practical answer is to agree when access ends, collect the items, remove the permissions and confirm the changes worked. Give HR, IT and facilities a named part in that process, including a plan for anything still outstanding.

What do Canadian organisations recommend?

Official guidance treats ending access as a deliberate departure task. The Canadian Centre for Cyber Security’s readiness toolkit, goal 2.3, recommends a defined process by the day of departure that revokes and returns physical badges, cards and tokens and disables access to organisational resources. It is security guidance, not an employment-law timetable for every situation.

There is a practical local example too. Victoria University in Toronto’s employee departure checklist includes collecting office keys and fobs alongside notifying internal partners. That is one institution’s procedure, rather than a rule for every Ontario employer.

For your business, the useful question is whether the departure process reaches everyone who controls access. Closing an IT account does not establish that a separately managed building credential has also been dealt with. Ask each owner to confirm their part.

What is actually at stake if access stays active?

The immediate concern is an access permission that no longer matches someone’s role. It does not mean the departing person intends harm.

Consider an illustrative situation: a former employee returns to collect personal belongings and uses a still-working credential because no visit was arranged. Staff are surprised, the person is confused and the manager has to establish what happened. A clear handover and a planned collection appointment could have avoided the uncertainty.

At a site containing stock, confidential records or restricted work areas, unresolved access could also expose those spaces to entry the business no longer authorises. The consequence depends on which doors can be opened, when they can be used and what other controls exist. No incident or loss is inevitable.

Review the actual access involved before choosing a response. A returned meeting-room key and an outstanding master key deserve different assessments. Changing every lock after every resignation may create unnecessary cost; leaving a consequential gap without an owner creates a different problem.

When should the changes happen, and who decides?

Agree one access end time and a named coordinator before asking people to carry out changes.

HR and the responsible manager should establish the departure arrangements, including any remaining work, a handover or a visit to collect belongings. Facilities then knows when building access should change, while IT handles the relevant accounts and administration tools. In a leased property, the landlord or building manager may control an additional fob or parking permission.

For a planned departure, prepare the list ahead of time. For an unexpected departure, use the same responsibilities with an agreed urgent contact route. Restrict sensitive employment details to people who need them; the person cancelling a parking pass usually needs the instruction and timing rather than the full personnel history.

A role change needs attention too. Someone moving between sites may still need access to the organisation while no longer needing their previous office, stockroom or after-hours permissions. State what should remain as carefully as what should end.

Use a checklist that separates return from removal

Keep one departure record with separate completion fields. The following is a suggested working checklist, not a statutory form.

CheckResponsible team to confirmEvidence to keep
Agreed access end time and remaining dutiesHR and managerApproved instruction and coordinator
Building cards, fobs and mobile credentialsFacilities or access administratorItems returned, permissions removed and time completed
Office, cabinet and other mechanical keysFacilitiesKey inventory, returns and outstanding-key decision
Parking, shared-building and other site accessBuilding manager or local ownerConfirmation from each separate owner
Alarm codes and security-system administrationAuthorised system administratorRelevant access removed or shared access reviewed
Personal belongings and handover visitManager or HRAgreed appointment and host where needed
Failed changes and unfinished actionsDeparture coordinatorNamed owner, interim measure and follow-up date

Work from the person’s actual access inventory. If it is incomplete, ask the manager and site owners to help reconstruct it. Record uncertainty instead of marking an item complete because nobody remembers issuing it.

For organisations operating several premises, the multi-site access-control migration guide provides broader context for bringing scattered systems under a manageable arrangement. This departure checklist has a narrower job: confirming one person’s access changes across the systems already in use.

How do you know the badge really stopped working?

Ask the administrator what confirms a change reached the relevant doors. A request entered into a screen and a completed change are different stages.

Platform behaviour matters. For example, the AXIS A1001 and Entry Manager documentation states that more than half of the controllers in its system must be online to add, remove or edit users. That is a product-specific condition, not a rule for all access systems. It illustrates why the person responsible should consult the documentation for your installed platform and report failed or pending work.

For a suitable site, arrange a controlled test using the returned credential, with an authorised person present and a way to avoid stranding anyone. Review the corresponding event as well as the administrator’s record. A single test at the front entrance does not prove that a separate parking system or another building was updated.

If a controller or service is unavailable, leave the affected item open. Ask the system maintainer to explain the exposure and recommend a proportionate interim arrangement. Do not improvise changes to door wiring or emergency-release functions.

What if a key is missing or a code was shared?

Treat it as a specific unresolved access question. Record the affected key or code, the spaces it can reach and the plan to close the gap.

Provide a practical return method so the former employee knows what is expected. If a mechanical key remains outstanding, facilities and a qualified locksmith can assess whether rekeying is justified by the access it provides and the circumstances. Avoid assuming that a software change can withdraw a physical key’s ability to operate a lock.

Where a shared code needs changing, plan who legitimately needs the replacement and how they will receive it securely. Check that the change will not unexpectedly prevent the remaining team from opening or closing the site. Individual credentials may make future changes easier to manage, but first establish whether the current system supports them and whether the benefit justifies the work.

Any hardware change must preserve compliant exit arrangements. Ontario’s Fire Code, Division B, Article 2.7.2.2 addresses opening applicable exit and access-to-exit doors from inside, with specified exceptions. Have a qualified professional assess the actual door and applicable requirements; do not add an improvised lock to solve an offboarding issue.

Keep useful proof without keeping unnecessary personal information

The completion record should answer who authorised the change, what was changed, when it was completed and what remains unresolved.

Keep employment explanations out of widely shared access tickets. Restrict access to departure records and use the organisation’s justified retention arrangements, including any applicable preservation requirements. Avoid keeping every access log indefinitely merely because storage is available.

The Office of the Privacy Commissioner of Canada’s workplace privacy guidance discusses safeguards and limits on the handling of employee information. Applicable law depends on the employer and activity; federal private-sector employee provisions do not automatically cover every Ontario workplace. Obtain appropriate privacy advice where the position is unclear.

Start with the last completed departure

Before buying anything, review a recent departure with the responsible teams. Can you show that the items came back, permissions ended and any exception was resolved? If one answer depends on an assumption, give that gap an owner.

An adequate existing system may only need a clearer process and reliable follow-up. If your team cannot determine where access remains active or verify changes, a review of your access-control setup can help identify the next proportionate step. The aim is a respectful departure and a building whose permissions reflect who should be there now.

Frequently Asked Questions

Collect the item and separately remove its permission to open doors. Also review other access methods, such as mobile credentials, parking remotes and shared codes, rather than assuming one returned item covers them all.

Record which keys are outstanding, arrange a clear return method and ask facilities to assess which spaces remain exposed. A qualified locksmith can advise whether rekeying is appropriate. A missing key does not by itself establish wrongdoing.

HR and the responsible manager should agree the appropriate access end time based on the person's remaining duties and departure arrangements. Communicate that time to everyone carrying out the changes. Do not treat every resignation as an immediate security incident.

Keep the completion record from each responsible system owner and resolve any offline or failed changes. Where appropriate, arrange a supervised credential test and review the corresponding event. A saved request alone is not confirmation that every door received the update.