Client Offboarding Process

Last updated

Offboarding starts in the contract

Define client offboarding contractually before you need it. Your MSA should state the transition assistance you will provide, at what rate, and the condition that all invoices are paid before data and credentials are handed over. Without that language you're negotiating terms during a breakup – the one moment when neither side is generous.

Roles and trigger: assign a single offboarding owner (a senior tech or service manager) and run the exit as a project with a checklist – not as a loose pile of tickets. The trigger is written termination notice from either side.

The process

  1. Confirm the contractual position. Notice period, early-termination fee (commonly the remaining contract value or a defined buyout), and exactly what transition assistance you owe at what rate. Freeze new project work.
  2. Settle final billing. Contracts usually condition data and credential handover on all invoices being paid – enforce it. Invoice transition assistance at the contracted rate as you go. Collecting is awkward now and nearly impossible after handover, when you no longer control the handoff.
  3. Enumerate everything you hold. Pull the full inventory from your documentation platform: every credential, resold license, domain, tenant, deployed agent, and integration. This step is where documentation standards pay off – with complete docs it's an export; without them it's archaeology under deadline.
  4. Hand over data and documentation. Export and transfer all client data, documentation, and configurations: network diagrams, credential lists with MFA recovery codes, licensing inventory, ISP and vendor details, backup configuration. The client owns its data; your contract should already say so – what you keep is your own "Provider Work" (scripts, tooling, methodology), whose license to the client ends at termination.
  5. Transfer licenses, domains, and tenants. Transfer or cleanly terminate every license you resold, per your contract obligations – for Microsoft 365 that means a CSP transfer to the incoming partner. Hand over domain registrar and DNS control if you held it, and remove your delegated admin relationships (GDAP) from their tenant.
  6. Rotate credentials and remove access. Enumerate every credential you ever held: domain admin, local admins, firewall and switch logins, VPN, RMM and remote access, service accounts, scheduled tasks, backup agents, monitoring integrations, API tokens, SaaS admin logins – and the credential vault itself. Rotate in published, sequenced batches: rotating everything at once breaks integrations and looks like an outage to the client. The non-human credential sweep is where offboarding fails – service accounts and API tokens don't complain when you miss them; they just keep working for whoever holds them.
  7. Remove your agents and tools. Uninstall RMM agents, AV/EDR, backup agents, and monitoring per your standard removal procedure, coordinated with the incoming provider's deployment.
  8. Record and attest. Keep dated records of every credential rotated, access revoked, license transferred, and agent removed – then get the handover attested (below).

The condensed checklist

  • Termination notice received; contract terms and dates confirmed
  • Final invoices issued and paid before handover
  • Data and documentation exported and delivered
  • Resold licenses transferred or terminated (M365 CSP, line-of-business apps)
  • Domain registrar / DNS control handed over
  • Delegated admin (GDAP) relationships removed
  • All human credentials rotated in sequenced batches
  • All non-human credentials swept: service accounts, scheduled tasks, API tokens, integrations
  • Agents and tools removed
  • Dated offboarding record archived; attestation of handover signed

Protect yourself: the attestation of handover

Dated records of everything rotated, revoked, and transferred are cheap to produce during offboarding and nearly impossible to reconstruct if a claim or audit lands a year later. If the former client suffers a breach six months out, your dated record showing when your access ended is the difference between a five-minute answer and a legal problem.

Close the engagement with a short attestation of handover: a signed document listing what was delivered (data, documentation, credentials, licenses), what was rotated and removed, and confirming that your access has ended as of a stated date. It marks the clean end of your responsibility – and pairs with the offboarding terms your contract defined up front. Archive it with the dated records and your final copy of the client's documentation, and keep the bundle for as long as your contract's survival clauses and your insurer expect.

Exit criteria and the long game

The offboarding is done when:

  • No credential you ever held remains valid, human or non-human
  • No agent of yours is still reporting from their environment
  • No license is still billing to you
  • The final invoice is paid and the signed attestation is archived with the dated records

Then exit gracefully. Departing clients boomerang and refer – the shop they leave you for may disappoint, and the person who managed the exit remembers exactly how it went. Some churn happens to even well-run MSPs; a professional exit is the last impression you control, and in a local market it's also marketing. Run the departure with the same discipline as your client onboarding – the two processes bookend every relationship, and both get talked about.