Secure offboarding in Google Workspace: a checklist for employee departures
By the QuantumSec team
Poorly managed former-employee accounts are a silent attack surface: access that stays active, data that's lost and tokens that are never revoked. This checklist covers the secure offboarding of an employee in Google Workspace, step by step.
Suspend the account immediately
The first step when offboarding an employee is to suspend the account, not delete it. Suspension cuts access instantly while preserving the data and allows you to transfer it in an orderly way. Deleting the account outright can cause the loss of valuable information.
Revoke sessions, OAuth tokens and app passwords
Suspending the account doesn't always invalidate all access: third-party OAuth tokens and app passwords may remain active. Explicitly revoke sessions, tokens and app passwords to ensure no open access remains.
Transfer data ownership
Before deleting the account, transfer ownership of email, Drive files and calendar events to a manager or a shared drive. Google's data transfer tool makes this step easier and prevents the loss of business information.
Review rules, delegations and devices
Remove forwarding rules and filters, revoke mailbox delegations and unlink or remotely wipe the devices associated with the account. Finally, apply the retention policy (with Vault if applicable) and free up the license.
FAQ
Should I delete the account immediately?
No. It's advisable to suspend it first, transfer the data and only then delete or archive it according to your retention policy. Deleting it outright can cause the loss of information and evidence.
If the account was compromised, is suspending it enough?
Suspending it cuts the sign-in, but you must also review OAuth tokens, forwarding rules and delegations, because they can keep the attacker's access independently of the password.