Before the departure
Set the scope before access changes hide the evidence
Confirm the person’s last working time, manager, authorized administrator, devices, shared responsibilities, and any legal or retention requirements. Capture the starting software list before deleting identities or transferring ownership.
- Name one owner for the offboarding review and one approver for exceptions.
- Record the employee’s primary and alias email addresses and relevant contractor identities.
- List business-critical files, calendars, groups, automations, API credentials, and shared inboxes they own.
- Decide whether the account will be suspended, archived, transferred, or deleted after required preservation steps.
Identity and Google Workspace
Secure the central identity, then inspect third-party grants
At the authorized cut-off time, suspend or otherwise secure the Workspace identity according to your organization’s process. Review current third-party application grants and recent token activity before assuming that the SSO application list is complete.
- 01
Secure the Workspace account at the approved time and revoke active sessions where policy requires it.
- 02
Review third-party OAuth tokens or application grants associated with the user.
- 03
Transfer ownership of files, calendars, groups, shared drives, automations, and service accounts.
- 04
Record each action, administrator, timestamp, and unresolved exception.
Accounts outside SSO
Reconcile identity evidence with the software and billing record
A direct login may never appear as a centrally assigned SSO application. Compare the identity review with the business software inventory, password manager entries, vendor administrators, approved finance records, and software invoices you are authorized to inspect.
- Check tools the employee owned, requested, expensed, or administered.
- Ask each application owner to confirm removal, transfer, or an accepted exception.
- Review API keys, personal access tokens, integrations, webhooks, and bot identities separately from browser login.
- Do not treat the absence of an invoice or OAuth token as proof that no account exists.
Billing and recovery
Transfer the account’s operating control—not only its login
For every retained subscription, confirm the business owner, billing administrator, recovery address, payment owner, renewal date, and location of the latest invoice or contract. Remove personal recovery methods when the vendor supports an authorized replacement.
Close-out
Finish with evidence and explicit unknowns
A completed checklist should distinguish confirmed removal, transferred ownership, accepted ongoing access, not applicable, and still unknown. Unknowns need an owner and due date; they should not disappear into a generic completed state.
From checklist to maintained record
Keep offboarding evidence attached to the software record.
Billproof early access is being built to reconcile Workspace application evidence, known software, ownership, and billing records into one reviewable offboarding view.
Sources and scope
Primary references
These sources support the Google Workspace capability statements. Operational checklist items should still be adapted to your contracts, roles, retention rules, and local law.
- Google Workspace Admin SDK — user tokens list ↗current token grants
- Google Workspace Reports API — token audit activity ↗recent audit events