Patronum Logo
00%
Patronum Logo
menu-icon

Suspend, Archive or Delete a Google Workspace User?

By Patronum

August 10, 2026

Read Time: 4 mins

Suspend first, archive only if the account must stay in place, and delete last, after you’ve moved My Drive ownership to a live user and exported the mailbox. Deletion starts a clock: Google Workspace Admin Help says “You can restore a deleted account for up to 20 days.” Day 21 is too late.

A developer leaves on Friday, IT deletes the account that afternoon, and three weeks later a client asks for the deployment runbook. It lived in his My Drive, nowhere else.

What to do right now if you’ve just deleted someone

Check the calendar. Under 20 days, restore the user in the Google Admin console, then transfer their Drive files to a new owner. Google states a deleted user’s files “are saved for 20 days but are only accessible if you restore the user.”

Google Admin console user page showing the Reset password, Suspend user, Restore data and Delete user actions
Google Admin console user page showing the Reset password, Suspend user, Restore data and Delete user actions

Two catches. On Annual/Fixed-Term, Google warns that restoring a deleted user means “you’ll need another license.” And for those same 20 days, anyone with access to files inside the deleted user’s folders “can use Drive search to find those files.” Past day 20, your routes are Google Vault, if the data fell under a retention rule or hold, or a colleague’s copy.

Why this keeps happening

Deletion feels like the responsible ending. It closes the account and frees the license. But My Drive ownership is invisible at that moment, so nobody knows which single-owner files matter until somebody needs one. Google puts the work on you: “To keep data like Gmail messages or Drive files in your organization, you need to transfer their data to another user.” A manual step. It gets skipped.

Suspend, archive, delete or transfer first

Four options, in order of consideration.

OptionWhat survivesWhat it costsUse it when
Suspend“Email, documents, calendars, and other data aren’t deleted”Full price, “the same rate as active accounts”The first 30 to 90 days
Archive (AU license)Service data, plus Google Vault search with a Vault licenseFrees the active license in 24 hours; an AU license at an unpublished priceThe account is under a Vault hold
DeleteGmail, Drive and calendar for 20 days, Drive only if you restoreRestoring on Annual/Fixed-Term needs another licenseData is already transferred
Transfer and export, then deleteMy Drive files under a new owner, email in your own archiveLicense returns to the poolAlmost always. Your default

Archiving isn’t storage relief: “Data for archived users counts toward your organization’s pooled storage limit.”

The default order to retire an account

Run these seven steps in order, every time.

  1. Suspend. Access stops, data stays.
  2. Set mail handover, an auto-reply or routing if anyone still writes to that address.
  3. Transfer My Drive ownership to an active internal user.
  4. Move long-lived team content into shared drives where it belongs to a team, not a person.
  5. Export or archive the mailbox to storage you control.
  6. Remove groups, delegations, OAuth tokens, admin roles and managed devices.
  7. Delete only when your retention policy allows it, and never while a Google Vault hold is in force.

Caveat: shared drive files are organization-owned already. Google states “Your organization owns the files in a shared drive, not an individual,” and that “When someone leaves and an admin deletes their account, files they added or created in shared drives remain.” Step 3 is only about My Drive.

The fix: make the order automatic, not remembered

The reliable version isn’t a better checklist. It’s a policy that runs the same sequence every time, before deletion is possible. In Patronum, an offboarding policy chains the steps: Group, Calendar, Contacts, Roles and Spaces strip the leaver out of Google Groups, events, contact shares, Google Admin roles and Google Chat spaces, and Conditions can fire the policy from an End Date on the profile.

Two different tools, two different destinations. Google’s native admin transfer tool moves files to a user account only: Google says transferred folders and files land “in the new owner’s My Drive,” and the recipient must be a user in your organization. Patronum’s Files step offers both. Patronum’s help documentation describes it as “Transfer ownership of files to an Executor from within the FILES policy or transfer files to a Google Shared Drive.” So leaver content landing in a shared drive during offboarding is a Patronum workflow, not a native Google Admin console feature.

Step 5 is the one that makes the order safe rather than just tidy. Patronum Archive writes the leaver’s email and Google Vault data, including “deleted emails held under a retention or hold policy,” into your organization’s own Google Cloud Storage bucket in Mbox RFC 4155 format, searchable and restorable item by item. Run it before step 7 and deletion stops being a retention decision. The evidence is already out, under your retention schedule rather than Google’s 20-day clock, so the account can go when policy says so instead of whenever somebody feels brave.

Key takeaways

  1. Deleting starts a 20-day clock. Drive files return only if you restore the account.
  2. Suspension preserves everything and saves nothing.
  3. Archiving frees the active license in 24 hours but still consumes pooled storage.

Frequently asked questions

What happens when you delete a Google Workspace user?

The account is removed and restorable for up to 20 days. Google retains Gmail and the primary calendar for that window, and Drive files the user owned are saved for 20 days but only reachable if you restore. After that, the data is gone.

Is it better to suspend or delete a Google Workspace user?

Suspend first, then delete once the data is transferred and archived. Suspension keeps data intact and access blocked, but Google charges suspended accounts at active rates. A holding step, not an ending.

Does deleting a user delete their shared files?

No. Files in shared drives stay with the organization, and files owned by other users are unaffected. For 20 days, people who already had access to files in the deleted user’s folders can find them through Drive search. Only My Drive files go with the account.

Get the order right once

Set up a policy that transfers My Drive ownership and exports the mailbox before deletion, and the 20-day window stops mattering. See Patronum Archive, then use the offboarding checklist for zero data leakage.

Sources