Every client leaves eventually. Some are acquired, some bring the work in-house, some run out of budget, and some fire you. The reason matters less than you would think. What matters is whether the last two weeks of the relationship are organised or chaotic, because that is the part the client remembers and describes to other people.
Offboarding is also where agencies quietly accumulate risk. Access that is never revoked, client data that is never returned, assets that turn out to be owned by the wrong company. None of it is urgent on the day. All of it is expensive later.
This is the checklist. It is deliberately short, because the value here is in doing every step, not in doing clever ones.
Why offboarding is worth a process
Three reasons, in order of how often they bite.
Security and compliance. If you never revoke access, you are holding live credentials to the accounts of a company you no longer work for. Under GDPR and equivalent regimes you are still a data processor for as long as you can reach that data, and you are still liable if something happens on it. Most agencies discover this during a client's security audit rather than their own.
Referrals and returns. A client who leaves well recommends you. A meaningful share of them also come back, usually within eighteen months, having discovered that the in-house hire or the cheaper agency did not work out. A messy exit closes both doors.
Your own record. When the relationship ends is when you find out whether your access register was accurate, whether the client actually owned their own ad account, and whether anything important lived only in a former employee's personal drive.
The offboarding checklist
Run this in order. The whole sequence should fit inside a two-week notice period comfortably.
1. Acknowledge in writing, within one day
Confirm the end date, the notice period as it stands in the contract, and what remains in scope until then. Ambiguity here is what turns a routine exit into a dispute over the final invoice.
2. Book the handover call
One call, thirty to forty-five minutes, scheduled before you start packing anything up. It sets the tone and it surfaces what the client actually wants back, which is rarely what you assumed.
3. Agree what is being handed over
Write the list and get it confirmed. Typically: creative files and source assets, reporting history, campaign structures, audience and list data, documentation and process notes, anything scheduled that will publish after your last day.
4. Complete work in progress, or stop it deliberately
Nothing should be half-finished and unlabelled. If something will not be completed, say so explicitly and in writing rather than leaving it for the client to discover.
5. Cancel or transfer anything scheduled
Scheduled posts, automations, recurring reports, active ad campaigns, email sequences. An automation that keeps firing three weeks after you left is the single most common offboarding embarrassment, and it is entirely preventable.
6. Export and hand over the data
Reporting history, creative assets in editable source formats, and any list or audience data the client is entitled to. Send it somewhere durable, not as attachments to an email thread that will be lost.
7. Transfer ownership of anything in your name
This is the step that goes wrong, and it goes wrong because of decisions made at onboarding. If your agency created the client's ad account inside your own business portfolio, or set up their Tag Manager container under your organisation, ownership transfer ranges from awkward to impossible. On Meta, whichever business portfolio claims an asset owns it, and there is no self-serve transfer for Pages or ad accounts. On TikTok, an ad account transfer cannot be reversed once complete. Google Tag Manager has no self-service ownership transfer at all.
If you are reading this at the start of a relationship rather than the end, the fix takes twenty minutes at kickoff: have the client create the container and grant you access to it, rather than creating it yourself. The platform-by-platform version is in our client account access guide.
8. Revoke your own access, platform by platform
Work from your access register. For each entry: remove your users, remove your partner or agency link, and confirm the removal actually took effect rather than assuming the invitation was withdrawn.
Include the accounts people forget: analytics properties, Search Console, Tag Manager, Business Profile, ad accounts, page roles, email platform, ecommerce back end, DNS and hosting, any shared drive, any project tool the client was a guest in.
9. Remove the client from your own systems
The mirror image of step eight, and the one almost everyone skips. Remove client staff from your Slack, your project tool, your shared drives and your internal dashboards. They should not be able to see your other clients' work the week after they leave.
10. Delete or archive client data on your side, per contract
Check what your contract and privacy policy actually promise. If you committed to deletion within a period, do it and record that you did. If you are retaining records for legitimate business reasons, know which ones and why.
11. Settle the money
Final invoice, any outstanding balance, cancel the recurring payment or subscription so the client is not charged after their last day. An accidental charge after departure undoes every other thing on this list.
12. Send the closing note and ask the honest question
A short message confirming everything is handed over, who to contact if something surfaces later, and one direct question: what would have made this better? Departing clients answer honestly in a way current clients never do. It is the cheapest feedback you will ever get.
The mistakes that cost most
Revoking access before the handover is complete. Do the export first. Once you are removed from an ad account you cannot pull its history, and asking to be re-added is not a good look.
Assuming the access register is accurate. It is accurate only if it was maintained. Audit each platform directly rather than trusting the list, and treat every discrepancy as a lesson for your onboarding process.
Leaving automations running. Set a calendar reminder for two weeks after the end date and check again. Recurring things have a habit of surviving.
Treating the exit as personal. Even when the client behaved badly, the exit is a business process. The version of the story they tell for the next three years is written in these two weeks.
Not asking why. Exit feedback is the highest-signal data an agency gets about its own delivery, and most agencies never collect it because the conversation is uncomfortable.
Offboarding starts at onboarding
Almost every painful offboarding traces back to a decision made in the first week.
The asset that cannot be transferred was created in the wrong container. The access that cannot be found was never written down. The data the client wants back was never structured to be handed over. The dispute over the final invoice exists because scope was never precise.
So the practical version of an offboarding process is this: keep an access register from day one, create everything inside the client's own containers, and document the handover expectation while everyone is still friendly. Do that, and the twelve steps above take an afternoon.
Our agency client onboarding checklist covers the setup side, including the access register and the ownership rule that makes step seven painless instead of impossible.
Questions we get asked
How long should offboarding take?
Two weeks is comfortable for a standard retainer. The constraint is usually data export and ownership transfer, not the revocation itself.
Should we revoke access immediately when a client gives notice?
No. Revoke last, after export and handover are complete and confirmed. Revoking first means you cannot retrieve the history the client is about to ask for.
What data are we obliged to hand back?
Whatever your contract says, plus whatever the client's own data protection obligations require them to hold. Read the agreement before the handover call rather than during it.
Do we have to delete client data afterwards?
It depends on what you committed to in your contract and privacy policy. Under GDPR, retaining personal data without a lawful basis after the relationship ends is a problem. Record what you deleted and when.
Can we transfer a Meta ad account we created to the client?
Not through a self-serve flow. Meta publishes ownership-transfer flows for catalogues and apps but not for Pages or ad accounts. This is why the account should be created inside the client's business portfolio at the start.
Is it worth asking for exit feedback?
Yes, and ask a specific question rather than a general one. "What would have made this better?" gets a usable answer. "Any feedback?" gets a polite nothing.

