Somebody left seven weeks ago. Their laptop came back. Did their password manager?
At a company without an IT department, joining and leaving usually runs out of an email thread, and the thread works — right up until the week it doesn’t. Two people leave at once, one of them was the only admin on something, and two weeks later nobody can say for certain which accounts are still open. Not because anyone was careless, but because a checklist can only tell you a box is unticked. It cannot tell you which unticked box is the one that matters today.
This workbook does that part. It is an onboarding and offboarding tracker for Excel, Google Sheets and LibreOffice, built for the HR or ops lead at a 5- to 150-person company with no IT department and no HR platform. It scores every access item you have not closed yet, ranks them, and hands you the list in the order you should work it.
What “exposure” means, and why it sorts the list for you
Every system in the catalog carries a sensitivity weight — Critical 10, High 6, Medium 3, Low 1. Every open item on the Access Register multiplies that weight by the number of days it has sat open past its due date. Close the item and the score drops to zero.
That one number does the thing a flat checklist cannot: it puts a critical system left open four days above a low-sensitivity one left open a month, and it moves on its own overnight. The Dashboard adds the scores into an exposure index per person and ranks the individual items into a queue, so “what do I deal with first” is a number you read, not a judgment you make at the end of a bad week.
The mover — the case a plain checklist rarely covers
A joiner needs everything granted. A leaver needs everything removed. Both are straightforward, and both have an obvious date on somebody’s calendar.
A mover has neither. Somebody changes teams and the new access gets granted, because a person is waiting on it. The old access rarely gets revoked in the same motion, because revoking feels like something that belongs to a leaver. Three internal moves later, they are carrying access from every stop along the way, and nothing about their file looks unusual.
The Action Builder treats that as a first-class case. Pick a person, and it reads whether they are joining, moving or leaving, looks up what their current role has and what their next one needs, and computes the exact list: what to grant, what to revoke, what to change the level of, and which systems will strand shared files if you close the account before handing ownership over.
Hand over first, then revoke
Disabling somebody’s account does not move what they personally owned. Shared drives, calendars, distribution lists, admin seats, recovery contacts, API keys created under their login — those go with them unless somebody moves them first, and recovering them afterward ranges from a support ticket to impossible.
The Systems Catalog flags every system where that is true. Those rows come back as REVOKE + TRANSFER OWNER rather than a plain revoke, the Dashboard counts the handovers still open, and there is a printable sign-off sheet for recording who the new owner is.
Unrecovered equipment value, and the seats still billing
Equipment depreciates over its category’s replacement life but never to nothing — a four-year-old laptop that still boots is not worth zero, because you would have to replace it. The Equipment Register carries a due-back date that appears on its own for anyone marked as leaving, and a per-item value at risk that the Dashboard totals into what you have not recovered.
The other number is quieter. Every seat you have not revoked is still billing. The Dashboard multiplies the open revocations by the seat costs in your catalog and shows you the monthly figure and the annual one.
How the eight tabs fit together
- Read Me — every colored word in the workbook, defined once.
- Systems Catalog — the 46 systems, their sensitivity, seat cost and hand-over risk. Setup you do once.
- Role Access Matrix — nine roles against every system, one decision per cell. Also setup you do once.
- People — the roster: who is joining, moving or leaving, the role now and next, and the one effective date everything measures from.
- Equipment Register — what each person has, when it is due back, and what it is worth today.
- Access Register — one row per grant, revoke or hand-over, with days open and exposure computed for you.
- Action Builder — reads one person from People against the Role Access Matrix and returns the grant, revoke, change-level and hand-over-first list.
- Dashboard — reads all of it back: the close-first queue, the exposure index per person, and the two money totals.
The catalog ships with 46 systems already researched — not just names, but how removal actually works in each one and the trap to check before you close it. Those removal steps describe the general shape of the job rather than any one vendor’s current admin console, so check them against your own settings as you go. Delete what you do not use, correct the seat costs to what you actually pay, and the whole engine re-computes around your version.
It works in Excel, Google Sheets and LibreOffice. The Google Sheets version is a real native sheet you copy with one click — not an import you have to fix afterward.
Try the free version first
Running one person right now? The free single-person onboarding and offboarding checklist covers one joiner or one leaver — a fixed list of systems with the hand-over-first flag already set, plus the kit they have out. No email, no signup.
It has no exposure scoring, no ranked queue and no role-change diff. Those are what the full workbook adds once you are running more than one person at a time.
What it costs against a per-seat platform
A blank spreadsheet is free and you build all of it, with no sensitivity model and nothing to tell you what to close first. A per-seat identity or IT asset platform is generally priced and built for larger teams with an IT department to run it, bills monthly while you use it, and hosts your data.
This is the rung in between: a file you buy once and keep. No subscription, no seat count, no renewal.
An honest note
It records that access exists — who has what, at what level, and when it changed. Every entry is something you record by hand: it does not connect to your systems, and it never grants, revokes, scans or audits anything on its own. It is not security, legal, tax or compliance advice.
It deliberately stores no passwords, access keys or recovery codes — never type one in. Your completed file will hold employee details, though: names, managers, work locations, asset tags and a per-person map of which systems each person can get into. Keep it access-controlled and retain it only as long as your own data-protection obligations allow.
All sample people and dates are fictitious; seat costs and equipment replacement lives are illustrative planning figures to replace with your own.