Patronum Logo
00%
Patronum Logo
menu-icon

The Complete Employee Offboarding Checklist (with Free Template)

By Patronum

July 15, 2026

Read Time: 5 mins

A good employee offboarding checklist runs in one order: arrange mail and data handover, suspend the account, reset credentials and revoke sessions and connected apps, transfer Drive files and review their sharing, remove group and role assignments, wipe managed devices, then archive or delete based on your retention policy. Do those in sequence and you close the main access paths. The full copy-and-paste template is below, grouped so you can hand it to whoever runs exits.

Offboarding fails in the gaps between steps, not in the policy document. One person assumes another revoked the tokens, a device keeps syncing, a forwarding rule keeps copying mail. The point of a checklist is to make each step someone’s explicit job. And the stakes are real: in a 2022 Beyond Identity study, 83% of former employees said they still had access to accounts from a previous employer (Beyond Identity). Treat that as a prompt to close every item below.

The offboarding checklist

First move depends on how the person is leaving:

SituationFirst move
Planned departureSet handover first, then suspend and revoke access
Immediate or high-risk departureSuspend and revoke access first, then recover handover through admin routing and retention tools

1. Before the last day

  • Confirm the exact departure date and time with HR.
  • Decide where the person’s incoming mail should go, and set up handover before you suspend, because a suspended account blocks new mail and calendar invitations. Use an admin-level approach such as an address map to redirect or forward messages to a manager (Google Admin Help). Address-map changes can take up to 24 hours to apply, so configure planned handover ahead of time, not at the last minute.
  • Identify the files, calendars, and responsibilities that need a new owner.
  • Note every group, shared drive, mailbox delegation, and third-party app the person belongs to.

2. Suspend the account

  • In the Admin console, go to Directory, then Users, and suspend the user. Suspension blocks sign-in immediately while preserving all data (Google Admin Help).
  • Do not delete yet. Deletion is the last step, after data is transferred.

[SCREENSHOT: Admin console > Directory > Users > “Suspend user” – SOURCE: Google Admin UI (we capture)]

3. Reset credentials and revoke access

  • Reset the password to a random value and sign the user out of all sessions.
  • Delete app-specific passwords and security keys, revoke OAuth tokens, use the Admin console security controls to reset sign-in cookies where available, and complete any separate MFA cleanup required by your identity provider.
  • Remove or update the recovery email and phone details so the leaver cannot recover the account.
  • Revoke access for connected third-party apps.
  • If you use third-party single sign-on, terminate the user’s identity-provider session too. Resetting Google sign-in cookies alone may not end it (Google Admin Help).

4. Transfer data, then review sharing

  • Transfer the My Drive files owned by the leaver to another internal user, and move long-lived team content into the appropriate shared drive, before the account is deleted (Google Admin Help).
  • Review the transferred files’ sharing. Changing ownership does not change who already had access.

5. Remove roles and memberships

  • Remove the user from every Google Group, shared drive, and delegated mailbox.
  • Remove any admin roles or other privileges so nothing is restored if the account is later reactivated.

6. Wipe managed devices

  • Wipe managed devices, or remove the corporate account where endpoint management supports it, so cached mail and synced files do not leave on a personal device. For unmanaged BYOD devices, rely on account suspension, credential revocation, and your BYOD policy rather than assuming a remote wipe is available.

7. Confirm mail handover and choose an end state

  • For planned departures, set any auto-reply, alias, address map, routing rule, or shared-inbox handover before suspension, since a suspended account is blocked from new mail. After suspension, handle the end state.
  • Before deleting, check for Vault holds and legal holds. Deleting an account under hold needs careful handling.
  • Choose an end state based on your retention schedule: archive the account where you need to preserve data, or delete it once transfers, legal holds, and retention obligations are satisfied. Google treats suspension, archive licenses, transfer, export, Vault, and deletion as separate options for preserving a former employee’s data (Google Admin Help).

The template

Copy this block into your ticketing system or a shared doc, assign the owner, and require a checkmark before an exit is marked complete.

StepOwnerDone
Confirm departure date and timeHR
Set mail routing or auto-reply before suspensionIT
Suspend accountIT
Reset password and revoke sessions, tokens, and appsIT / Security
Transfer My Drive files and review sharingIT / Manager
Reassign calendars, recurring meetings, and owned resourcesIT / Manager
Remove groups, shared drives, roles, and delegationIT
Wipe managed devices or remove corporate accountIT
Check Vault and legal holdsIT / Legal
Archive or delete per retention policyIT / Legal

For the reasoning behind the order, see our full guide on Google Workspace offboarding, and for the security-first version, the forensic offboarding checklist.

Automate the checklist

A checklist only works if someone runs every line, every time. That is exactly what breaks under pressure. For Google Workspace, Patronum can run an offboarding policy that carries out the routine steps consistently: resetting the password, updating the recovery email, deleting app-specific passwords, revoking data access, wiping mobile devices, setting an auto-responder, applying an archive-user license, and scheduling the eventual deletion. For planned departures, configure the auto-reply and any mail routing before suspension, since a suspended account is blocked from new mail. The value is not speed for its own sake. It is that a defined policy runs the same way every time, so the step that usually gets forgotten does not.

FAQ

What should be on an employee offboarding checklist?
Mail and data handover, account suspension, credential reset and session and app revocation, Drive transfer with a sharing review, removal of group, role, and mailbox-delegation assignments, device wipe, a Vault and legal-hold check, and a retention-based archive or delete decision.

Should I suspend or delete the account first?
Suspend first. Suspension blocks sign-in immediately while preserving data. Delete only after data is transferred and your retention window has passed (Google Admin Help).

How do I keep the person’s email and files?
Transfer My Drive files owned by the leaver to another active internal user, then review sharing. Move long-lived team content into an appropriate shared drive where needed, and note that files already in shared drives are owned by the organization. Set up admin-level mail routing to a manager before suspension, and preserve the historical mailbox through your retention process (Google Admin Help).

When can I safely delete the account?
Once transfers are done and any legal holds and retention obligations are satisfied. Archive first if you need to preserve data (Google Admin Help).

Can I automate offboarding in Google Workspace?
Yes. A Patronum offboarding policy can run the routine chain automatically: password reset, recovery-email update, app-password deletion, data-access revocation, mobile wipe, auto-reply, archive license, and scheduled deletion. For planned exits, auto-reply and mail routing should be configured before suspension, since a suspended account is blocked from new mail.

Run every exit the same way

Offboarding is only as good as its weakest step. See how Patronum automates Google Workspace offboarding so the whole checklist runs as one consistent policy, every time.

Sources

  • Google Admin Help, “Delete or suspend a user”: https://support.google.com/a/answer/33314
  • Google Admin Help, “Transfer Drive files to a new owner”: https://support.google.com/a/answer/1247799
  • Google Admin Help, “Options to preserve former employee data”: https://support.google.com/a/answer/11524030
  • Google Admin Help, “Redirect or forward Gmail messages to another user”: https://support.google.com/a/answer/4524505
  • Beyond Identity, former-employee access study (2022): https://www.beyondidentity.com/announcements/beyond-identity-study-shows-former-employees-are-likely-to-continue-accessing-old-employer-information