Process

Software offboarding: what to cancel, reassign and reclaim when someone leaves

8 min read

Most offboarding checklists are written by security people, so they stop at access. Disable the account, kill the sessions, collect the laptop, done. That is the urgent half and it is the half most teams get roughly right. The other half is quieter and nobody owns it: the seats you keep paying for, and the contracts that just lost the only person who understood them.

This guide covers the software side of a leaver. It assumes you already have an identity process for revoking access, and focuses on the two things that outlast the last day. Any figures below are illustrative arithmetic, not measurements of any particular company.

What a leaver actually takes with them

Three separate things leave when a person does, and they have three different deadlines. Treating them as one task is why the last two get missed.

  1. Their access. Urgent, ideally same day, and the part your security policy already covers.
  2. Their seats. Not urgent, but it costs money every month until you deal with it, and the real saving usually only lands at the next renewal.
  3. Their ownership. Not urgent, invisible, and the one that quietly turns a tracked tool into an untracked one.

Before the last day: build the leaver's list

You cannot offboard software you cannot list. Before anything else, produce one list of every tool connected to that person, in three senses: tools they had a login for, tools they were the named owner of, and tools that are billed to their card or registered to their email address. Those are three different lists and only the first one is usually available from your identity provider.

If you keep a register with a named owner per tool, the second list is a filter rather than an investigation. If you do not, the leaver's last week is the worst possible time to start asking who owns what, because the person who knows is on their way out. Our guide to the register fields that matter covers what to capture so this is a lookup, and finding the software nobody owns covers how to rebuild the list if you are starting cold.

Ask the leaver, while you still can

Add one question to the exit conversation: which tools do you pay for or administer that IT might not know about? People answer this honestly on the way out, and it surfaces the card-billed utilities and single-admin accounts that no directory will ever show you. It takes two minutes and it is the highest-yield step in this whole list.

Revoke access in the right order

Identity first, then the applications behind it. Disabling the directory account closes anything behind single sign-on immediately, which is the bulk of the estate for most teams. What it does not close is everything bought outside single sign-on: the tool a team signed up for with a work email and a password, the utility on a personal card, the vendor portal with its own separate login. Those need visiting one at a time.

Two details are worth being deliberate about. Revoke active sessions and API tokens rather than only resetting the password, because a live session or a personal access token can outlive the credential that created it. And check what happens to the data they owned before you delete anything: files, dashboards, scheduled reports and automations are often owned by an account rather than a team, and deleting the account takes them with it. Suspend first, delete once you have moved what matters.

Reclaim the seat, and know when it actually saves money

This is where offboarding checklists tend to overpromise. Removing a user does not automatically reduce a bill. What happens depends on the licence model, and it is worth knowing which of these three you are dealing with before you claim a saving.

  • Pooled seats: you bought a contracted number of licences. Removing a user frees a seat for reuse but changes nothing on the invoice until you reduce the contracted count, which is normally only possible at renewal.
  • Per-active-user billing: usually monthly tools that charge for whoever is active in the period. Here removal is a real, immediate saving.
  • Suspended or deactivated states: several vendors keep billing for a suspended account exactly as if it were active. Suspension is a safety measure, not a cancellation. If the plan is to save money, the account has to be removed, not parked.

So the honest sequence is: free the seat now so it can be reused instead of buying another, and record the freed seat against the tool so that the next renewal drops the contracted count. A team that reclaims eight seats through the year and then renews at the same number has saved nothing at all.

Reassign the ownership, not just the licence

This is the step that gets skipped, because nothing breaks when you skip it. The tool keeps working, the bill keeps being paid, and the record still exists. What has changed is that the renewal reminder now goes to a mailbox nobody reads, and the person who knew why the contract was signed, what was negotiated last time and what the notice period is has gone.

Every tool the leaver owned needs a new named owner before their account closes, not at some point afterwards. A team name is not an owner. If the field can hold a leaving employee it can hold nobody, and unowned tools are exactly the ones that auto-renew unchallenged. While you are on the record, check three things that tend to point at the person rather than the role: the billing contact, the vendor portal admin, and the address the renewal notice is sent to.

The sole-admin problem

Some tools will have exactly one administrator, and it is the person leaving. Closing their account can lock the organisation out of its own subscription, and recovering it means a support ticket, proof of ownership and a wait. Before the last day, promote a second administrator on every tool where the leaver is the only one. Do the same for anything registered to their individual email address rather than a shared one, and for anything billed to a card in their name.

Make it repeatable

A leaver checklist that lives in someone's head works until the week it is busy. Write it down as a short standing list, run it every time, and record what was done against each tool so the next person can see the history. Four lines is enough: access revoked, data moved, seat freed, owner reassigned.

The one thing that makes all four cheap is having the list before you need it. When every tool already carries a named owner, a seat count and a notice period, offboarding the software side of a leaver is a filter and an afternoon rather than an archaeology project. If you are unsure what your notice windows are, notice periods in SaaS contracts explains how to find them and why they decide when a reclaimed seat turns into money.

StackTrackr keeps that register: one record per tool with a named owner, the seats you pay for, the renewal date and the notice period, so you can filter by the person leaving and see their whole list in one place, then hand each record to its new owner and let the reminder find them instead. See the features overview, or start free and have the list ready before the next resignation.

Take control of your software estate.

Start with your ten most expensive tools. In an afternoon you will know every renewal date, every notice period, and who owns what.

No credit card required. Self-hostable. Cancel anytime.

Software offboarding: what to cancel, reassign and reclaim when someone leaves · StackTrackr