← Back to Blog

The Google Workspace offboarding checklist: what to do when someone leaves

  • Admin console
  • Gmail
  • Drive
The Google Workspace offboarding checklist: what to do when someone leaves

Somebody resigns on a Tuesday and finishes on Friday. At a thirty-person company there is no offboarding runbook, so the manager asks for the laptop back, someone changes the Wi-Fi password, and the Google Workspace account sits untouched for four months because nobody is sure what deleting it would break. Then finance needs a contract that only ever existed in that person's Drive, the licence is still on the invoice, and an app the leaver authorised two years ago is still reading mail through a grant nobody recognises.

Offboarding in Workspace is not difficult. It is order-dependent, which is worse, because several steps become impossible once you have done the last one. Here is the sequence we run on a client account.

What deleting a user actually destroys

Every other decision follows from this one. Google is explicit that a deleted user's data is unrecoverable once it is deleted.

  • Gmail is gone. Not in a trash folder, not in an archive. If you want the mail, you handle it before the deletion.
  • Drive files the user owns, and their primary calendar, are held for 20 days and are only reachable if you restore the whole account.
  • Files in shared drives survive, because the organisation owns them rather than the individual. That is the best reason to move working documents into shared drives long before anyone resigns.
  • Vault does not save you. Delete a user and you also delete that user's Workspace data, including data held or retained by Vault. Retention rules and holds stop applying, the data can be purged immediately, and it is gone even if you restore the account inside the 20 days.

The account is the container for everything outside a shared drive. Keep it alive until you have emptied it.

Suspend first. That buys time, not savings

On the person's last day, suspend. Google keeps email, documents, calendars and other data intact, you can restore the account at any time, and the suspension resets the sign-in cookies for you.

What it does not do is reduce the bill. Suspended accounts are charged at the same rate as active ones, on both the Annual and the Flexible plan. We find two and three year old suspended accounts on almost every audit, each still on the invoice, because somebody treated suspension as the finished state. It is a pause button. Put a date on the calendar.

Move the files and the calendars while the account exists

Google offers a transfer at the moment of deletion, but only for Drive and Calendar. Gmail has no transfer option there, and that is the gap most people walk into. A super administrator can transfer some data inside the deletion flow; other admins have to transfer it before deleting the user at all.

The Calendar transfer is narrower than it sounds. Only future, non-private events on the primary calendar with at least one guest or resource move across. Private events are cancelled, past events do not transfer, and secondary calendars do not transfer at all: move those separately, while the account is still there.

On the Drive side, transferring files does not change who already has access, so a transfer is not a tidy-up. And if you leave unshared files out, shared files inside an unshared folder can move without the folder and end up with no path anyone can browse to.

The mailbox and the address: decide before you delete

  1. An Archived User licence, which is Google's own recommendation here: if a user has left your organisation, assign an Archived User licence instead of, or shortly after, suspending the account. The data stays searchable and exportable and the regular licence is freed for reassignment within 24 hours. It has to match the user's edition, archived data counts against your pooled storage, and only the Enterprise editions include archiving of Vault data. The price per edition is on Google's add-ons page, which we check on the day.
  2. The data migration service, which copies the mail into a new or existing account and which Google recommends at small scale, roughly 1 to 100 users. It needs IMAP on in the source account and 2-Step Verification off there for the duration, which sets your order: the migration happens before you harden the account, not after.
  3. An alias on an active user, so mail to the old address reaches whoever picks up the work. A user can hold up to 30 aliases at no extra cost and only one user can hold a given alias. Twenty days after deletion the address is removed from Workspace, though you can reassign it to another managed user before then.
  4. Delegation, when several people need to work from the address rather than one. Delegates can read, send and delete for the account but cannot change its password.

The access a password reset does not cut

Resetting the password is the step everybody does, and on its own it is not enough. In one direction it does more than expected: every app password on the account is revoked, and OAuth tokens for certain Google products are revoked automatically on a password change, so mail clients signed in with OAuth stop syncing. Everywhere else it does less.

  • Reset the sign-in cookies too, under Directory, the user, Security, Sign-in cookies, Reset. That signs the account out across all devices and browsers, though it can take up to an hour to end current Gmail sessions and it does not sign the account out of desktop applications such as Drive for desktop.
  • With single sign-on through a third-party identity provider, end the SSO session first, because resetting the Google cookies while that session is live may let the person walk back in.
  • Revoke the third-party app grants one by one. The user's Security page in the Admin console lists the active OAuth tokens that account has granted, per application, and lets you revoke them. A revoked app cannot reach that user's data until the user reinstalls and re-authorises it, so revocation is not a permanent block: it holds only while the account is also suspended or gone.
  • Clear the recovery phone and recovery email, because a recovery address or number is what lets somebody reset a password later.

The senders they left on your domain

This is the part most offboarding checklists skip, and the part that reaches your customers. The invoicing platform, the CRM, the online store and the helpdesk all send mail with your domain in the From header, from their own infrastructure. Somebody authorised each one, often the person who just left.

Two leftovers in particular. A send-as address or a per-user outbound route the leaver configured can keep sending under their identity after the account is suspended; we covered how those settings behave in SMTP relay and Send mail as. And a third-party sender still sitting in your SPF record for a tool nobody has opened in two years costs a DNS lookup against the ten-lookup limit and widens who is allowed to send as you, for no benefit.

App passwords belong in the same conversation: they are revoked the moment you reset the password, so any integration one of them powered stops working at that instant. Find out which ones matter on Wednesday, not after the Friday reset. You can see what your own domain authorises right now.

Devices, shared drives and the admin role

Devices come first, because the ordering here contradicts everything above. An account wipe removes the managed work account and its data and leaves personal apps and data alone, which is what Google suggests for a personal device when someone leaves. A device wipe removes all work data and apps, and on Android devices without a work profile and on device-enrolled iOS devices it takes personal data too. Deleting the device from the Devices list is not a substitute: except on iOS, it removes no work data.

The catch is that a wipe wants a reachable, working account: a suspended account has to be restored first, and if the person does not know their password you should reset it before the wipe, or they may wait at least 24 hours before signing back in. So in practice the device wipe comes before the suspension. Run it from Directory, the user, Managed devices, then More and Wipe Account or Wipe Device.

  • Admin roles come off before the account can go. You cannot delete a user who still holds an admin role, and you cannot delete your own administrator account: another super admin has to do it.
  • Shared drive membership is its own step. Removing a member from a shared drive also strips their access to files and folders in that drive that were shared with them directly.
  • Check what direct sharing survives. Google's guidance on removing people notes that a removed user can still reach files shared with them directly rather than through a group, and that files transferred to another user stay shared directly with the removed user by default. So the transfer you ran earlier can leave the leaver reading the documents you just moved. Verify it on your own domain.

Only now, the licence

The money question comes last because the answer is usually that there is no hurry. On the Flexible plan, deleting the user stops the charge, prorated to the deletion date. On the Annual plan it changes nothing immediately: your commitment drops at renewal, when Google renews it for the number of accounts you hold that day. So on an Annual plan the reason to delete is risk, not cost, and archiving is what frees a seat.

The twenty days after

Deletion starts a clock. A super administrator can restore the user for up to 20 days, and the restore fails once that window closes, or when no licence is free for the service the user previously had. So put day 18 in a calendar rather than in somebody's memory, and confirm then that nobody needs the mailbox and that the old address still routes where you decided.

How Guanacos Tech helps

The hard part of offboarding is not any single setting. It is that the steps constrain each other, and a company does this twice a year, never often enough to remember the order. So we do it once with you, write it down as a runbook your office manager can follow without us, and audit the two things a runbook rarely catches: the third-party grants on the leaving account, and the systems still sending as your domain. That work runs through our Google Workspace consultants engagements, and how we scope it is on how we work. A 30-minute call is enough to look at your suspended accounts, your licence plan and your senders, and say which is costing you money and which is costing you control.

Sources

Next step

Would you rather we did this for you?

Thirty minutes on Google Meet, free. We look at your domain or project with you, tell you what is wrong and what we would do first. If you can fix it yourself, we say so.

Book a 30-minute call or read about our Google Workspace consulting

Frequently asked questions

Should I suspend or delete the account when someone leaves?

Suspend on their last day so nothing is lost, then decide within a few weeks. A suspended account keeps the mailbox, files and calendar intact and can be restored at any time, but Google bills it at the same rate as an active account on both the Annual and the Flexible plan, so suspension is a pause rather than a saving. Deleting is permanent for Gmail.

Can I get a deleted Google Workspace account back?

A super administrator can restore a deleted user for up to 20 days. After that window the data cannot be recovered, and the restore also fails when no licence is free for the service or edition the user previously had. Content that Vault purged on deletion does not come back even inside the 20 days.

What is the cheapest way to keep a former employee mailbox?

An Archived User licence, which is what Google recommends for this case. It keeps the data searchable and exportable and frees the regular licence for reassignment within 24 hours. The licence has to match the user edition, archived data counts against your pooled storage, and the current price per edition is published on Google add-ons page.