Learn
Guide


When an employee in Singapore finishes their last shift on a Friday afternoon, it is Saturday morning in London and pre-dawn Friday in New York. If your offboarding process depends on a human logging into an admin console to revoke access, that gap is already open and nobody is awake to close it. The risk mechanics of offboarding are covered in our first-24-hours checklist and offboarding gaps guide. This article is about what changes when your departing employee, their manager, and your admin are in different regions, and the specific failure modes that only appear in that configuration.
TL;DR
The access-risk window that exists in every offboarding grows substantially when the process depends on a human trigger and the key people are in different time zones.
BYOD remote-wipe coordination and recovery-method removal are the two steps most uniquely dangerous for international employees, and both require proactive policy before someone actually leaves.
Offboarding triggered by an HRIS departure date, rather than a person remembering to act, is the only reliable fix for the time-zone coordination problem.
ShiftControl is purpose-built for Google Workspace and handles this without requiring a dedicated IT team or coordination across regions.
About the Author: ShiftControl was built by operators who scaled IT for a globally distributed team from 100 to over 700 employees across seven offices. The offboarding complexity described in this article is something the founding team navigated firsthand at ExpressVPN, which is why it became a core design priority for the platform.
The Coordination Failure That Time Zones Create
In a co-located company with an IT desk, offboarding is a logistics problem. In a distributed company, it is a coordination problem, and the failure mode looks different.
Consider the standard sequence Google recommends: wipe managed mobile devices, revoke password recovery access, change the user’s password, revoke all OAuth 2.0 tokens, and reset sign-in cookies. Each step is straightforward in isolation. The problem is that executing all of them in sequence requires someone with admin access to be alert and acting at the moment the employee’s access should end.
When that moment falls outside local business hours, manual processes produce one of two outcomes: the steps happen late (access window extends), or they happen in the wrong order because whoever is available works from memory rather than a complete checklist. Either way, the employee’s access outlasts their employment.
The compounding factor is that the departing employee often knows this. A remote employee who is leaving on poor terms has hours, sometimes more than a day, during which they retain full access because the admin team is asleep.
The Two Steps Most Acute for International Employees
The general offboarding gaps that affect all companies are covered in our offboarding gaps article. Two specific steps sit in a different risk category for international and remote employees.
BYOD Remote Wipe Coordination
Remote employees frequently use personally owned devices enrolled in a mobile device management (MDM) policy. Wiping a managed device is a routine admin action in Google Workspace, but for a BYOD device, it erases personal data alongside company data. That creates a coordination requirement: the employee typically needs to be notified and given an opportunity to back up personal content before the wipe executes.
For an in-office departure, this conversation happens in person on the last day. For an international remote employee, it requires scheduling across a time zone gap, often with a departing person who has limited motivation to cooperate. If the conversation does not happen before the employee’s access is suspended, you have two bad options: delay the wipe (leaving company data on a personal device) or execute it unilaterally (risking a dispute over destroyed personal files).
The only reliable answer is a policy that is communicated and agreed upon before any specific departure. The BYOD wipe procedure should be part of the employment agreement or onboarding documentation, not something you negotiate with a departing employee the week they leave.
Recovery Method Removal
International employees commonly register personal phone numbers or personal email addresses as Google account recovery methods, sometimes because they set up the account before IT had a standard provisioning process, sometimes because they traveled frequently and wanted a backup. These methods survive account suspension in some configurations and can be used to regain access to an account that you believe you have locked down.
The correct step is to remove all personal recovery methods before or at the point of suspension, replacing them with a company-controlled recovery address or removing them entirely. This step does not always appear on informal offboarding checklists, and for remote employees who set up their own recovery methods without IT involvement, there may be no record of what those methods are.
An admin audit of recovery methods should run before the departure date, not after access is suspended. By then, you cannot always be certain the account is fully sealed.
A Practical Checklist for Time-Zone-Safe Offboarding
The following steps are specific to distributed and international employees. The general Google Workspace offboarding sequence lives in our first-24-hours checklist.
Step | Why it is different for remote/international employees | When to complete it |
|---|---|---|
Audit recovery methods (phone, personal email) | Remote employees often self-register personal recovery contacts without IT visibility | Before the departure date, not on the day |
Document BYOD devices and communicate wipe policy | Wipe requires coordination; personal data is at stake | At notice, not at departure |
Confirm MDM enrollment status | Remote employees may have enrolled devices IT has no record of | At notice |
Schedule offboarding sequence to exact departure time | Prevents access window from extending across time zones | When departure date is confirmed |
Identify non-SSO SaaS seats the employee may hold | Remote teams accumulate tools independently of IT; see shadow IT and manual offboarding | During notice period |
Assign a backup admin in a closer time zone if departure is outside your local hours | Ensures someone can intervene if automated steps fail | When departure date is confirmed |
Revoke group and distribution list membership | Sensitive communications can route to a former employee long after departure | Same day as account suspension |
How Automation Closes the Time Zone Gap
The reason time zone coordination fails is that manual processes require someone to decide to act. Automation removes that dependency.
When offboarding is triggered by an HRIS departure date rather than a human decision, the sequence executes on schedule regardless of where your admin is. Google Workspace de-provisioning, OAuth token revocation, group removal, and SaaS seat flagging all fire at the configured time. Nobody needs to be awake in the right city.
ShiftControl is purpose-built for Google Workspace and handles this in one place: provisioning and access, SaaS spend management, app-permission visibility, and incident response, rather than four tools and a spreadsheet. It connects to your HRIS so offboarding begins when HR acts, not when IT remembers. Setup takes about 10 minutes via a single Google Workspace login. No dedicated IT team required, and no implementation project.
For BYOD and recovery-method steps that require human judgment, the platform surfaces them as action items with clear ownership and deadlines, so they do not slip because nobody knew they owned them.
Cyber incident response via Blackpanda (IR-1) is included in every ShiftControl subscription. If a former employee’s lingering access is later exploited, you are not scrambling to find help after the fact.
If distributed offboarding is still running on a checklist and good intentions, visit shiftcontrol.io to see a live demo without needing to log in.
