SaaS Access Offboarding Checklist Template

Disabling the directory account is the easy part. The leaver’s API tokens, the CRM records they owned, the design tool on their own card and the seat you keep paying for until renewal all sit outside it.

This free SaaS offboarding checklist covers the application layer of a departure. IT teams, security teams and MSPs run it alongside their main leaver process to find every app the person used, inside and outside single sign-on, then close each account, revoke tokens, rotate shared credentials, move data to a new owner, reclaim the licence and keep the evidence.

Use This Template Free See Live Example
No Credit Card Required

The App Layer of a Leaver, Not the Whole Leaver

Blocking sign-in at the identity provider stops new logins to apps connected through SSO. It does nothing to a local password in an app outside SSO, a personal access token, an OAuth grant to a third-party tool or a billing account in the leaver’s name. Those need work in each app, and that work goes missing when one line on the leaver checklist says “remove from SaaS apps”.

IT offboarding

The person and their devices

Covers: identity provider disable, sessions, MFA, laptop return, building access.

Owner: IT, triggered by HR.

Done when: the directory account is blocked and the hardware is back.

SaaS access offboarding

This checklist

Covers: each app the leaver used, its tokens, shared logins, data, licence and bill.

Owner: IT or the SaaS owner, with each app admin.

Done when: every app row is closed, transferred and reclaimed, with evidence.

Periodic review

Catching what was missed

Covers: stale accounts and access that should no longer exist.

Owner: IT and system owners, quarterly.

Done when: each account is kept, changed or removed and signed off.

The identity, device and HR steps live in CheckFlow’s IT offboarding checklist software and in the IT offboarding security guide, which sets the order for voluntary and involuntary exits. Accounts that survive a departure turn up in the Active Directory & Entra ID Account Cleanup Checklist and the quarterly User Access Review Checklist. This page goes app by app instead.

What the SaaS Offboarding Checklist Covers

Seven phases take one leaver from inventory to evidence. The leaver type on the first task adds an urgent cut-off phase for a hostile or urgent exit and admin tasks for privileged leavers, and data is not deleted until the new owner confirms the handover.

Phase 1

Phase 1: Leaver, Type & Owners

The leaver type on the first task decides whether Phase 2 appears and whether the admin tasks in Phase 5 appear.

  • Record the leaver, the last working day and the leaver type — Standard, Admin or privileged, or Hostile or urgent
  • Name the SaaS owner, the data recipient and the finance contact — the data recipient is usually the leaver’s manager or successor
  • Link the IT offboarding record for the same leaver — the identity provider disable, device return and HR steps run there, not here
  • Agree the timing with HR — a standard leaver keeps access until the last day; a hostile exit loses it during the conversation
  • Set the rule for this run: suspend or deactivate first, delete last — deleted accounts often take their files, calendars and history with them
Phase 2 — Urgent

Phase 2: Urgent Cut-Off

Tasks appear only when the leaver type is Hostile or urgent. They run at the agreed minute, before the full inventory.

  • Revoke refresh tokens and sessions at the identity provider — in Entra ID, Revoke-MgUserSignInSession; access tokens already issued keep working until they expire, typically about an hour
  • Revoke the leaver’s OAuth tokens and app passwords in Google Workspace — the user’s security page lists connected applications and app passwords
  • Revoke tokens in source control and cloud consoles — GitHub organisation owners can revoke fine-grained tokens under Active tokens, filtered by owner
  • Suspend the leaver in the password manager — suspending keeps the vault recoverable; removing it can delete their items for good
  • Take the leaver off billing, DNS, payment and social media admin roles — the apps outside SSO where one person often holds the only login
Phase 3

Phase 3: SaaS Inventory

Each app found becomes a row in the app table on the last task.

  • Export the apps assigned to the leaver in the identity provider — direct and group assignments in Entra ID, Okta or Google Workspace
  • Pull 90 days of the leaver’s SSO sign-in events — they show which apps were used, not just assigned
  • Search expense claims and card statements for SaaS charges — tools bought on a personal or team card never touch SSO
  • List the third-party apps the leaver granted OAuth access — a grant to a note-taker or AI assistant can keep reading mail and files
  • Ask the manager which tools only the leaver used — one-person tools are the ones with no second admin
  • Record each app in the table — app, SSO or not, account action, new data owner and licence reclaimed
Phase 4

Phase 4: Deprovision Each Account

  • Deprovision SCIM-connected apps from the identity provider — Entra ID provisioning runs about every 40 minutes, so check each app instead of assuming
  • Confirm the app account is deactivated, not just unassigned — Okta deactivates the downstream account rather than deleting it, and some apps still bill a deactivated seat
  • Disable local logins on apps that also use SSO — password fallbacks and accounts created before SSO was enforced
  • Deactivate accounts by hand in apps outside SSO — in each admin console, with the date recorded against the app row
  • Freeze first where an app blocks deactivation — Salesforce will not deactivate a default lead or case owner; freeze, reassign, then deactivate
  • Remove the leaver’s guest access in client and partner tenants — shared channels and client portals
Phase 5

Phase 5: Tokens, Shared & Admin Accounts

The last two tasks appear when the leaver type is Admin or privileged, or Hostile or urgent.

  • Revoke personal access tokens and API keys the leaver created — source control, Atlassian, CI, monitoring and cloud tools
  • Move integrations that authenticate as the leaver to a service account — Slack legacy bot users stop working when the member who created them is deactivated
  • Rotate every shared vault item the leaver could open and revoke their sharing links — 1Password advises assuming leavers copied shared passwords
  • Transfer owner and super-admin roles to a named successor in each app — every app should keep at least two admins, neither of them the leaver
  • Review each app’s admin audit log for the last 30 days — new admins, new API keys, bulk exports and changed SSO or MFA settings
Phase 6

Phase 6: Data Ownership Transfer

The data recipient records Approved or Not approved on the last task. The checklist halts there, and no account is deleted until they decide.

  • Transfer Google Drive and Looker Studio content before deleting the account — shared drive files already belong to the organisation
  • Transfer secondary calendars and hand over meetings the leaver organised — Google now deletes an owner’s secondary calendars with the account; Exchange Online’s Remove-CalendarEvents needs the mailbox to still exist
  • Confirm the manager can open the leaver’s OneDrive and set the retention period — 30 days by default, configurable up to 3,650
  • Reassign CRM records, queues and tickets — Salesforce’s Mass Transfer tool moves accounts, leads and custom objects
  • Reassign automations, recordings, canvases and channels — Power Automate flows, Zoom meetings and recordings, Slack canvases and lists
  • Confirm the handover with the data recipient — Approved or Not approved, with anything missing listed
Phase 7

Phase 7: Licences, Billing & Evidence

Answering Yes to “Did the leaver pay for any app?” shows the billing transfer task.

  • Remove or reassign each licence and mark it in the app table — reuse the seat for the next joiner before buying another
  • Reduce seat counts where the contract allows — many annual plans only shrink at renewal, so put the reduction against the renewal date
  • Record whether the leaver paid for any app themselves — Yes or No, from the expense and card search in Phase 3
  • Move billing ownership to a company account — billing contact, payment card and account owner email, then cancel or merge into the company plan
  • Recheck seven days after the last day — no sign-ins in the identity provider logs and no active account in any app row
  • Attach the evidence and sign off — exports, screenshots and provisioning logs for each app, approved by the SaaS owner

What to Do Before You Remove the Account, App by App

Most offboarding data loss comes from deleting an account before its content has a new owner. These steps come from each vendor’s admin documentation as of 6 October 2026; recheck before relying on a default.

App Before removing the account What goes wrong if you skip it
Google WorkspaceTransfer Drive, Looker Studio and calendar data; transfer secondary calendars and future eventsFrom 5 October 2026, deleting an owner also deletes their secondary calendars, and they can no longer be transferred
Microsoft 365Give the manager OneDrive access; convert the mailbox to a shared mailbox if it must stayOneDrive is deleted after the retention period, 30 days unless changed; an unlicensed shared mailbox is capped at 50 GB
SalesforceFreeze the user, transfer records, then deactivateDeactivation is blocked for default owners; a frozen user still holds a licence
SlackReassign canvases and lists; move bots and integrations to an active ownerLegacy bot users created by the leaver stop working on deactivation
GitHubReassign repository admin; review fine-grained tokens; remove from the organisationRemoved members lose private forks; access can be reinstated for three months, so record the removal
ZoomUse Transfer Data Then Delete for meetings, webinars and cloud recordingsPersonal Meeting ID meetings cannot be transferred; tell attendees of a new link
Power AutomateChange the owner of solution flows; add a co-owner or copy other flowsFlows that use the leaver’s connections fail once the account is disabled
1PasswordAsk the leaver to move work items, suspend the account, then rotate shared itemsRemoving a member permanently deletes items in their Employee vault

Licence timing is the other trap. On a Google Workspace Annual/Fixed-Term Plan the payment stays the same until the contract renews; on the Flexible Plan the next monthly bill falls. Microsoft’s new commerce annual subscriptions only allow reductions within seven days of buying, renewing or adding licences. A leaver in March can free a seat you pay for until the anniversary, so reassign it to the next joiner and note the renewal date in the app table. Whether a seat deactivated by SCIM still counts towards the bill depends on the vendor, which is why each row records the licence outcome separately.

Why Run SaaS Offboarding in CheckFlow?

1

One row per app, nothing implied

The inventory task holds a table with a row per app: SSO or not, account action, new data owner and licence reclaimed. A data set of your company’s apps, with admin and SSO status, keeps the list consistent between leavers.

2

The leaver type sets the pace

A required dropdown on the first task records the leaver type. Hostile or urgent shows the cut-off phase; Admin or privileged shows the role transfer and audit log tasks. The Members picker assigns the SaaS owner, the data recipient and finance before any work starts.

3

Nothing is deleted before the handover

The data recipient’s approval halts the checklist until files, records and automations have moved. Exports attach to the tasks they prove, the audit trail shows who closed each app and when, and tags keep each client separate for MSPs.

Run this checklist next to the main leaver process in CheckFlow’s IT offboarding checklist software, which handles the identity provider, devices and HR coordination. The IT offboarding security checklist explains why API keys and OAuth grants survive an account disable.

Seats freed here feed the next Software License Audit Checklist. Anything this run missed should surface in the quarterly User Access Review Checklist or Active Directory & Entra ID Account Cleanup Checklist.

Frequently Asked Questions

Does disabling a user in the identity provider remove access to every SaaS app?

+

No. It stops new sign-ins through SSO, and with SCIM it deactivates the account in connected apps on the next provisioning cycle. It does not touch local passwords, accounts in apps outside SSO, personal access tokens, API keys or OAuth grants, and access tokens already issued work until they expire.

How do you find SaaS apps a leaver used outside SSO?

+

Combine four sources: the leaver’s SSO sign-in history, expense claims and card statements, the OAuth grants on their account in Google Workspace or Entra ID, and the manager’s knowledge of tools only that person used. A discovery tool such as Defender for Cloud Apps Cloud Discovery adds apps seen in firewall, proxy or endpoint traffic.

What happens to a leaver’s Google Drive or OneDrive files?

+

In Google Workspace, a super admin can transfer Drive files, Looker Studio assets and calendar data to another user while deleting the account; if you skip it, those files go with the account. In Microsoft 365, deleting the user gives their manager access to the OneDrive by default, and the OneDrive is deleted when the retention period ends. That is 30 days unless an admin sets a longer value in the SharePoint admin center, up to 3,650 days.

Can you cut SaaS licences as soon as someone leaves?

+

You can unassign the licence straight away, but the bill may not fall. Google Workspace Annual/Fixed-Term Plans only reduce at renewal, and Microsoft’s new commerce annual subscriptions only allow reductions within seven days of a purchase or renewal. Monthly and flexible plans usually drop on the next invoice. Record the renewal date for each app so the reduction is made when the contract allows it.

Should you delete or deactivate SaaS accounts?

+

Deactivate or suspend first, then delete once the data has a new owner and any legal hold question is settled. Some apps do not allow deletion at all: Salesforce users can only be deactivated. Deleting early is how shared calendars, recordings and automations get lost, which is why this checklist halts for the data recipient’s approval first.

Is CheckFlow free for this template?

+

14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.

Close Every App, Not Just the Directory Account

Free trial — no credit card required.