Skip to content

Employee offboarding checklist

A software-access offboarding checklist that looks beyond SSO

Use this checklist to close identity access, direct SaaS accounts, account ownership, billing roles, and the evidence needed to show what was actually reviewed.

Before the departure

Set the scope before access changes hide the evidence

Confirm the person’s last working time, manager, authorized administrator, devices, shared responsibilities, and any legal or retention requirements. Capture the starting software list before deleting identities or transferring ownership.

  • Name one owner for the offboarding review and one approver for exceptions.
  • Record the employee’s primary and alias email addresses and relevant contractor identities.
  • List business-critical files, calendars, groups, automations, API credentials, and shared inboxes they own.
  • Decide whether the account will be suspended, archived, transferred, or deleted after required preservation steps.

Identity and Google Workspace

Secure the central identity, then inspect third-party grants

At the authorized cut-off time, suspend or otherwise secure the Workspace identity according to your organization’s process. Review current third-party application grants and recent token activity before assuming that the SSO application list is complete.

  1. 01

    Secure the Workspace account at the approved time and revoke active sessions where policy requires it.

  2. 02

    Review third-party OAuth tokens or application grants associated with the user.

  3. 03

    Transfer ownership of files, calendars, groups, shared drives, automations, and service accounts.

  4. 04

    Record each action, administrator, timestamp, and unresolved exception.

Accounts outside SSO

Reconcile identity evidence with the software and billing record

A direct login may never appear as a centrally assigned SSO application. Compare the identity review with the business software inventory, password manager entries, vendor administrators, approved finance records, and software invoices you are authorized to inspect.

  • Check tools the employee owned, requested, expensed, or administered.
  • Ask each application owner to confirm removal, transfer, or an accepted exception.
  • Review API keys, personal access tokens, integrations, webhooks, and bot identities separately from browser login.
  • Do not treat the absence of an invoice or OAuth token as proof that no account exists.

Billing and recovery

Transfer the account’s operating control—not only its login

For every retained subscription, confirm the business owner, billing administrator, recovery address, payment owner, renewal date, and location of the latest invoice or contract. Remove personal recovery methods when the vendor supports an authorized replacement.

Close-out

Finish with evidence and explicit unknowns

A completed checklist should distinguish confirmed removal, transferred ownership, accepted ongoing access, not applicable, and still unknown. Unknowns need an owner and due date; they should not disappear into a generic completed state.

From checklist to maintained record

Keep offboarding evidence attached to the software record.

Billproof early access is being built to reconcile Workspace application evidence, known software, ownership, and billing records into one reviewable offboarding view.

See the offboarding workflow

Sources and scope

Primary references

These sources support the Google Workspace capability statements. Operational checklist items should still be adapted to your contracts, roles, retention rules, and local law.

  1. Google Workspace Admin SDK — user tokens list ↗current token grants
  2. Google Workspace Reports API — token audit activity ↗recent audit events