Client Offboarding

Last updated

Definition

Client offboarding is the structured process of ending a managed services relationship: settling the contract, returning the client's data and documentation, handing over credentials and resold licenses, removing the MSP's agents and delegated access, and recording that all of it happened. It should be defined in the contract long before either side needs it.

Why it matters to an MSP

Offboarding is where an MSP's liability outlives its revenue. Three parts carry the risk. Credential handoff: every password, admin account, MFA recovery code, and domain registrar login you hold is transferred in writing to the client or incoming provider, and every credential you ever used is rotated afterward – including service accounts and API tokens, which do not complain when missed and keep working for whoever holds them. Data return: the client owns its data and documentation, and you export and deliver them once final invoices are paid; you keep only your own tooling and methodology. Access revocation: RMM, backup, and EDR agents uninstalled, GDAP relationships removed from the Microsoft tenant, CSP subscriptions transferred, VPN and remote-access accounts closed.

Miss any of it and you are exposed: an agent left on a former client's machine is a breach path you no longer monitor, standing admin access in a tenant you no longer manage is a liability when that client is breached a year later, and unreturned data is a dispute you lose. Done well, offboarding is 10–25 technician hours for a small client, billed as transition assistance, and closed with a signed attestation that lists what was handed over and rotated – the document that ends the argument when the next provider blames you. The step-by-step version, with contract language and checklist, is in the client offboarding process.

Related terms: GDAP, CSP Program, MFA, Churn Rate