Broker guides

Freight Broker TMS Employee Offboarding Checklist: Protect Access and Keep Loads Moving

When a dispatcher, account manager, or operations employee leaves a freight brokerage, removing a paid seat is only one task. The real offboarding job is to stop access, preserve the record, transfer unfinished work, and prove that no load or customer is stranded with the former user.

A good checklist works for a planned resignation, an internal transfer, and a same-day separation. It should also expose what your transportation management system cannot do. Use this guide as an operating and product-evaluation method—not as legal, employment, cybersecurity, or regulatory advice.

> Public-fact and product boundary: CISA and FTC sources cited below provide general access-control guidance. The eCFR defines broker transaction-record obligations. None of those sources evaluates ServeOps. This guide does not claim that ServeOps deactivates users, ends sessions, reassigns work, preserves audit history, rotates credentials, changes billing automatically, or provides any other offboarding function.

<!-- Visual placement: /content/broker-guides/freight-broker-tms-employee-offboarding-checklist/01-offboarding-control-map.svg -->

Start with two clocks, not one vague departure date

Record the employee’s last authorized access time and the business handoff deadline separately. For a planned departure, the work transfer may begin days earlier while access remains authorized. For a same-day separation, the access deadline may be immediate while load reassignment follows under a controlled owner.

Write down:

  • the person authorizing the separation;
  • the exact access cutoff time and time zone;
  • the administrator responsible for each system;
  • the operations owner accepting open work;
  • the billing or accounting reviewer; and
  • the person who records evidence and closes the checklist.

CISA’s Cross-Sector Cybersecurity Performance Goals recommend a defined process for departing employees that disables user accounts and access to organizational resources by the day of departure. That is general security guidance, not a statement about what a particular TMS does or what every employment situation legally requires.

1. Build the access inventory before changing anything

Do not treat the TMS login as the whole identity. Inventory every route the employee used to reach brokerage work:

  • TMS username, mobile access, and active browser sessions;
  • identity provider or single sign-on account;
  • email, shared inboxes, chat, file storage, and phone tools;
  • customer and carrier portals;
  • load boards, tracking links, factoring or payment portals;
  • API keys, integration users, forwarding rules, and app passwords; and
  • shared credentials or recovery methods that may need rotation.

Mark each route personal, shared, service/integration, or unknown. An unknown owner is not a completed check. Assign someone to resolve it.

The FTC’s business guidance says access to personal information should be limited to employees with a need to know and recommends a procedure so workers who leave or transfer no longer retain access to sensitive information. Use that principle to widen the inventory beyond one application.

2. Capture the employee’s operational footprint

Before disabling an account, create a departure snapshot from authorized administrative views. Do not ask the departing employee to export customer, carrier, or load data to a personal location.

At minimum, look for:

  1. Open loads and loads scheduled after the cutoff.
  2. Quotes, tenders, or customer requests awaiting action.
  3. Carrier offers, confirmations, check calls, or appointment changes in progress.
  4. Missing proof of delivery, lumper, detention, or other supporting documents.
  5. Loads held from billing or carrier payment review.
  6. Unresolved claims, service failures, accessorial disputes, or escalations.
  7. Customer and carrier relationships assigned only to that user.
  8. Draft or unsent communications and documents.
  9. Reports, exports, saved views, or scheduled tasks owned by the user.
  10. Personal inboxes, phone numbers, or spreadsheets acting as a hidden work queue.

For every item, record the current state, next action, deadline, new owner, and evidence location. “Transferred to operations” is too vague if no named person can find the load.

3. Transfer work before deleting or rewriting history

Reassign active work to named users or a controlled team queue. Preserve the original creator or actor attribution if the system supports it; do not overwrite history simply to make a dashboard look tidy.

Test the new owner’s view. Can that person see the current load status, latest customer and carrier commitments, supporting documents, unresolved exception, and next deadline without asking the former employee? If not, the handoff is incomplete even if the new name appears on the load.

Keep employment records and transportation records under the appropriate policies. A TMS user record, an email account, a brokerage transaction record, and an HR file are different objects with different owners and purposes.

4. Disable access and verify the result

At the authorized cutoff, complete the controls your systems actually provide. Possible actions to test include disabling the user, ending active sessions, removing single sign-on access, revoking recovery methods, removing group membership, and rotating credentials the user knew.

Do not assume that changing a password ends every existing session. Do not assume that deleting a paid seat disables an identity everywhere. Ask each vendor what the action does, then verify from an approved admin view or controlled test account.

Capture evidence such as the administrator, timestamp, account state, affected groups, and confirmation that expected access paths no longer work. Never retain or reuse the former employee’s password to perform the test.

5. Protect broker records while access changes

Current 49 CFR 371.3 requires a broker to keep a record of each transaction, identifies information the record must show, sets a three-year retention period, and provides review rights to each party to the brokered transaction.

That rule does not say that deleting, disabling, or reassigning a TMS user automatically preserves a compliant record. After the access change, retrieve a completed load touched by the former user and confirm that the brokerage can still find the required transaction information and supporting evidence under its approved policy. Have qualified advisers determine what your brokerage must retain and how.

6. Test communication continuity

For each customer and carrier relationship, decide where new messages should go. Configure only authorized forwarding, shared-inbox, or replacement-contact changes. Avoid a permanent silent forward from a departed user’s account without security, privacy, and management review.

Send controlled internal tests to the normal channels. Confirm who receives them, what sender identity appears, and whether a reply stays in a brokerage-controlled record. Update customer-facing contacts deliberately when needed; do not broadcast employment details.

7. Verify the seat and bill separately

Access status and subscription billing may be separate. Record the vendor, plan, seat count before and after, effective date, next invoice date, and confirmation reference. Ask whether the change is immediate, next-cycle, prorated, credited, reversible, or subject to a minimum commitment.

Treat every answer as unverified until the contract, admin screen, or vendor confirmation supports it. This guide makes no claim about ServeOps seat-removal timing, credits, refunds, prorating, or reactivation behavior.

8. Run the 24-hour and seven-day checks

Offboarding is not finished when the first admin screen says “inactive.” Within 24 hours, review failed or unexpected sign-ins, forwarding rules, shared credentials, unresolved work, and newly arrived messages. At seven days, confirm that load ownership, billing holds, customer contacts, recurring reports, integrations, and seat records still reflect the intended state.

Those review windows are an original editorial practice, not legal deadlines or CISA requirements. Change them to match your risks and policies.

<!-- Visual placement: /content/broker-guides/freight-broker-tms-employee-offboarding-checklist/02-offboarding-evidence-board.svg -->

A pass/fail scorecard for your TMS

Score the offboarding workflow against evidence:

  • Pass: access is stopped at the approved time, work has named owners, required records remain retrievable, communications reach controlled channels, and the seat decision is documented.
  • Conditional: the outcome works, but requires a documented manual step, vendor action, separate system, or later verification.
  • Fail: former access remains available, active work has no accountable owner, material records cannot be retrieved, or the brokerage cannot explain the billing state.

Do not average away a failed access check because load reassignment was easy. Security, continuity, records, and billing are separate decision gates.

Public facts versus verified ServeOps functionality

Public facts and guidance: CISA recommends a defined departure process that disables accounts and organizational access; FTC guidance recommends need-to-know access and procedures for workers who leave or transfer; current 49 CFR 371.3 defines broker transaction-record content, retention, and review rights.

Original editorial method: the two-clock plan, operational-footprint list, evidence board, 24-hour/seven-day reviews, and pass/conditional/fail score are ServeOps editorial tools. They are not laws, government requirements, or guarantees.

Verified ServeOps offer only: 60-day free trial; card collected upfront; no charge for 60 days; cancel anytime; then $49 per seat/month or $490 per seat/year.

No ServeOps offboarding, security, record-retention, reassignment, communication, integration, or billing functionality is claimed here. During a trial, use synthetic or properly authorized data and test every required control directly.

Start a 60-day ServeOps trial and include one controlled user-offboarding drill in your purchase decision.

Sources