Disabling the directory account is the easy part. The leaver’s API tokens, the CRM records they owned, the design tool on their own card and the seat you keep paying for until renewal all sit outside it.
This free SaaS offboarding checklist covers the application layer of a departure. IT teams, security teams and MSPs run it alongside their main leaver process to find every app the person used, inside and outside single sign-on, then close each account, revoke tokens, rotate shared credentials, move data to a new owner, reclaim the licence and keep the evidence.
Blocking sign-in at the identity provider stops new logins to apps connected through SSO. It does nothing to a local password in an app outside SSO, a personal access token, an OAuth grant to a third-party tool or a billing account in the leaver’s name. Those need work in each app, and that work goes missing when one line on the leaver checklist says “remove from SaaS apps”.
IT offboarding
The person and their devices
Covers: identity provider disable, sessions, MFA, laptop return, building access.
Owner: IT, triggered by HR.
Done when: the directory account is blocked and the hardware is back.
SaaS access offboarding
This checklist
Covers: each app the leaver used, its tokens, shared logins, data, licence and bill.
Owner: IT or the SaaS owner, with each app admin.
Done when: every app row is closed, transferred and reclaimed, with evidence.
Periodic review
Catching what was missed
Covers: stale accounts and access that should no longer exist.
Owner: IT and system owners, quarterly.
Done when: each account is kept, changed or removed and signed off.
Seven phases take one leaver from inventory to evidence. The leaver type on the first task adds an urgent cut-off phase for a hostile or urgent exit and admin tasks for privileged leavers, and data is not deleted until the new owner confirms the handover.
Phase 1
Phase 1: Leaver, Type & Owners
The leaver type on the first task decides whether Phase 2 appears and whether the admin tasks in Phase 5 appear.
Record the leaver, the last working day and the leaver type — Standard, Admin or privileged, or Hostile or urgent
Name the SaaS owner, the data recipient and the finance contact — the data recipient is usually the leaver’s manager or successor
Link the IT offboarding record for the same leaver — the identity provider disable, device return and HR steps run there, not here
Agree the timing with HR — a standard leaver keeps access until the last day; a hostile exit loses it during the conversation
Set the rule for this run: suspend or deactivate first, delete last — deleted accounts often take their files, calendars and history with them
Phase 2 — Urgent
Phase 2: Urgent Cut-Off
Tasks appear only when the leaver type is Hostile or urgent. They run at the agreed minute, before the full inventory.
Revoke refresh tokens and sessions at the identity provider — in Entra ID, Revoke-MgUserSignInSession; access tokens already issued keep working until they expire, typically about an hour
Revoke the leaver’s OAuth tokens and app passwords in Google Workspace — the user’s security page lists connected applications and app passwords
Revoke tokens in source control and cloud consoles — GitHub organisation owners can revoke fine-grained tokens under Active tokens, filtered by owner
Suspend the leaver in the password manager — suspending keeps the vault recoverable; removing it can delete their items for good
Take the leaver off billing, DNS, payment and social media admin roles — the apps outside SSO where one person often holds the only login
Phase 3
Phase 3: SaaS Inventory
Each app found becomes a row in the app table on the last task.
Export the apps assigned to the leaver in the identity provider — direct and group assignments in Entra ID, Okta or Google Workspace
Pull 90 days of the leaver’s SSO sign-in events — they show which apps were used, not just assigned
Search expense claims and card statements for SaaS charges — tools bought on a personal or team card never touch SSO
List the third-party apps the leaver granted OAuth access — a grant to a note-taker or AI assistant can keep reading mail and files
Ask the manager which tools only the leaver used — one-person tools are the ones with no second admin
Record each app in the table — app, SSO or not, account action, new data owner and licence reclaimed
Phase 4
Phase 4: Deprovision Each Account
Deprovision SCIM-connected apps from the identity provider — Entra ID provisioning runs about every 40 minutes, so check each app instead of assuming
Confirm the app account is deactivated, not just unassigned — Okta deactivates the downstream account rather than deleting it, and some apps still bill a deactivated seat
Disable local logins on apps that also use SSO — password fallbacks and accounts created before SSO was enforced
Deactivate accounts by hand in apps outside SSO — in each admin console, with the date recorded against the app row
Freeze first where an app blocks deactivation — Salesforce will not deactivate a default lead or case owner; freeze, reassign, then deactivate
Remove the leaver’s guest access in client and partner tenants — shared channels and client portals
Phase 5
Phase 5: Tokens, Shared & Admin Accounts
The last two tasks appear when the leaver type is Admin or privileged, or Hostile or urgent.
Revoke personal access tokens and API keys the leaver created — source control, Atlassian, CI, monitoring and cloud tools
Move integrations that authenticate as the leaver to a service account — Slack legacy bot users stop working when the member who created them is deactivated
Rotate every shared vault item the leaver could open and revoke their sharing links — 1Password advises assuming leavers copied shared passwords
Transfer owner and super-admin roles to a named successor in each app — every app should keep at least two admins, neither of them the leaver
Review each app’s admin audit log for the last 30 days — new admins, new API keys, bulk exports and changed SSO or MFA settings
Phase 6
Phase 6: Data Ownership Transfer
The data recipient records Approved or Not approved on the last task. The checklist halts there, and no account is deleted until they decide.
Transfer Google Drive and Looker Studio content before deleting the account — shared drive files already belong to the organisation
Transfer secondary calendars and hand over meetings the leaver organised — Google now deletes an owner’s secondary calendars with the account; Exchange Online’s Remove-CalendarEvents needs the mailbox to still exist
Confirm the manager can open the leaver’s OneDrive and set the retention period — 30 days by default, configurable up to 3,650
Reassign CRM records, queues and tickets — Salesforce’s Mass Transfer tool moves accounts, leads and custom objects
Reassign automations, recordings, canvases and channels — Power Automate flows, Zoom meetings and recordings, Slack canvases and lists
Confirm the handover with the data recipient — Approved or Not approved, with anything missing listed
Phase 7
Phase 7: Licences, Billing & Evidence
Answering Yes to “Did the leaver pay for any app?” shows the billing transfer task.
Remove or reassign each licence and mark it in the app table — reuse the seat for the next joiner before buying another
Reduce seat counts where the contract allows — many annual plans only shrink at renewal, so put the reduction against the renewal date
Record whether the leaver paid for any app themselves — Yes or No, from the expense and card search in Phase 3
Move billing ownership to a company account — billing contact, payment card and account owner email, then cancel or merge into the company plan
Recheck seven days after the last day — no sign-ins in the identity provider logs and no active account in any app row
Attach the evidence and sign off — exports, screenshots and provisioning logs for each app, approved by the SaaS owner
What to Do Before You Remove the Account, App by App
Most offboarding data loss comes from deleting an account before its content has a new owner. These steps come from each vendor’s admin documentation as of 6 October 2026; recheck before relying on a default.
App
Before removing the account
What goes wrong if you skip it
Google Workspace
Transfer Drive, Looker Studio and calendar data; transfer secondary calendars and future events
From 5 October 2026, deleting an owner also deletes their secondary calendars, and they can no longer be transferred
Microsoft 365
Give the manager OneDrive access; convert the mailbox to a shared mailbox if it must stay
OneDrive is deleted after the retention period, 30 days unless changed; an unlicensed shared mailbox is capped at 50 GB
Salesforce
Freeze the user, transfer records, then deactivate
Deactivation is blocked for default owners; a frozen user still holds a licence
Slack
Reassign canvases and lists; move bots and integrations to an active owner
Legacy bot users created by the leaver stop working on deactivation
GitHub
Reassign repository admin; review fine-grained tokens; remove from the organisation
Removed members lose private forks; access can be reinstated for three months, so record the removal
Zoom
Use Transfer Data Then Delete for meetings, webinars and cloud recordings
Personal Meeting ID meetings cannot be transferred; tell attendees of a new link
Power Automate
Change the owner of solution flows; add a co-owner or copy other flows
Flows that use the leaver’s connections fail once the account is disabled
1Password
Ask the leaver to move work items, suspend the account, then rotate shared items
Removing a member permanently deletes items in their Employee vault
Licence timing is the other trap. On a Google Workspace Annual/Fixed-Term Plan the payment stays the same until the contract renews; on the Flexible Plan the next monthly bill falls. Microsoft’s new commerce annual subscriptions only allow reductions within seven days of buying, renewing or adding licences. A leaver in March can free a seat you pay for until the anniversary, so reassign it to the next joiner and note the renewal date in the app table. Whether a seat deactivated by SCIM still counts towards the bill depends on the vendor, which is why each row records the licence outcome separately.
Why Run SaaS Offboarding in CheckFlow?
1
One row per app, nothing implied
The inventory task holds a table with a row per app: SSO or not, account action, new data owner and licence reclaimed. A data set of your company’s apps, with admin and SSO status, keeps the list consistent between leavers.
2
The leaver type sets the pace
A required dropdown on the first task records the leaver type. Hostile or urgent shows the cut-off phase; Admin or privileged shows the role transfer and audit log tasks. The Members picker assigns the SaaS owner, the data recipient and finance before any work starts.
3
Nothing is deleted before the handover
The data recipient’s approval halts the checklist until files, records and automations have moved. Exports attach to the tasks they prove, the audit trail shows who closed each app and when, and tags keep each client separate for MSPs.
Does disabling a user in the identity provider remove access to every SaaS app?
+
No. It stops new sign-ins through SSO, and with SCIM it deactivates the account in connected apps on the next provisioning cycle. It does not touch local passwords, accounts in apps outside SSO, personal access tokens, API keys or OAuth grants, and access tokens already issued work until they expire.
How do you find SaaS apps a leaver used outside SSO?
+
Combine four sources: the leaver’s SSO sign-in history, expense claims and card statements, the OAuth grants on their account in Google Workspace or Entra ID, and the manager’s knowledge of tools only that person used. A discovery tool such as Defender for Cloud Apps Cloud Discovery adds apps seen in firewall, proxy or endpoint traffic.
What happens to a leaver’s Google Drive or OneDrive files?
+
In Google Workspace, a super admin can transfer Drive files, Looker Studio assets and calendar data to another user while deleting the account; if you skip it, those files go with the account. In Microsoft 365, deleting the user gives their manager access to the OneDrive by default, and the OneDrive is deleted when the retention period ends. That is 30 days unless an admin sets a longer value in the SharePoint admin center, up to 3,650 days.
Can you cut SaaS licences as soon as someone leaves?
+
You can unassign the licence straight away, but the bill may not fall. Google Workspace Annual/Fixed-Term Plans only reduce at renewal, and Microsoft’s new commerce annual subscriptions only allow reductions within seven days of a purchase or renewal. Monthly and flexible plans usually drop on the next invoice. Record the renewal date for each app so the reduction is made when the contract allows it.
Should you delete or deactivate SaaS accounts?
+
Deactivate or suspend first, then delete once the data has a new owner and any legal hold question is settled. Some apps do not allow deletion at all: Salesforce users can only be deactivated. Deleting early is how shared calendars, recordings and automations get lost, which is why this checklist halts for the data recipient’s approval first.
Is CheckFlow free for this template?
+
14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.
Close Every App, Not Just the Directory Account
Free trial — no credit card required.
Do you like cookies? 🍪 We use cookies to ensure you get the best experience on our website. Learn more