MSP offboarding evidence checklist: what to verify after the ticket closes
Start with the departure record, compare it with current access evidence, and record which systems remain unverified. A closed ticket records workflow progress. To judge whether access was removed, the reviewer also needs evidence from the systems in scope.
Download the review sheet (CSV)
A worked example
Illustrative scenario: A departure record gives an effective time of 17:00. The offboarding ticket closes at 17:10. An identity export at 17:20 shows the matched account as enabled. Access to a separate vendor application has not been checked.
Review finding: The records disagree about the account state, and application coverage is incomplete. Confirm the identity match, collection times, and any approved exception before deciding what action is needed. An enabled account alone does not prove that a sign-in succeeded.
Six questions for the reviewer
- Who left, and when? Record the authoritative departure notice, effective time, responsible owner, and stable identifiers used to match the person across systems.
- Which access is in scope? List relevant identity accounts, applications, remote access, delegated roles, and customer environments. Mark unexamined systems as unknown.
- What do current records show? Capture account and access state with the source, tenant or environment, and collection time. Compare evidence collected after the change with the requested outcome.
- What must be preserved or handed over? Document the approved data-retention and business-handoff plan. Microsoft treats access prevention, mailbox and OneDrive handling, and account removal as separate parts of its former-employee workflow.
- What disagrees? Separate confirmed discrepancies from stale exports, identity-matching uncertainty, approved exceptions, and missing evidence. Assign an owner to each unresolved question.
- What proves the follow-up? After the responsible team makes a change, capture fresh evidence and record the reviewer’s decision. Retain the original finding so the before-and-after comparison remains clear.
What the review sheet captures
The downloadable sheet includes the review question, expected evidence, source and observation time, current state, open question, owner, and follow-up evidence. It contains one fictional example and six blank review rows. Use references to appropriately stored evidence rather than copying sensitive records into an unsecured worksheet.
Connecting the review to readiness work
For a defense-contractor client, the resulting record can inform the evidence review for the agreed system scope. The reviewer still needs to establish which requirements apply and what each artifact supports. This checklist is a focused operational review, not a complete CMMC assessment.
Customer requests add another source of context. Our prime supplier guides link to published instructions for further review against the customer’s current documents.
Discuss one client workflow
ViKeLaAi helps MSPs connect collected evidence to findings and reviewed readiness documents. Bring a description of one workflow where your team has to reconcile records across tools. We can discuss the inputs, review responsibility, and a bounded scope.