TerrierTerrier

The SaaS Offboarding Checklist: Every Subscription to Cancel When Someone Leaves Your Company

Last updated: June 2026


When an employee leaves, cancel or reassign access across eight categories: identity and access, communication tools, project management, finance and expense, CRM and sales, recruiting tools, AI tools, and design or development tools. After completing the known-tool checklist, run a Google OAuth audit and card statement review to catch shadow software that never went through procurement. Copy this checklist and run it within 48 hours of every departure.


How to Use This Checklist

This checklist covers the tools most commonly missed during employee offboarding. Work through it in order — identity and access first (Google Workspace or Microsoft 365), then communication tools, then everything else. Suspending the Google or Microsoft account cuts email and file access, but does NOT automatically deactivate Slack, Zoom, LinkedIn, or other tools — each needs to be handled separately, which is exactly what the rest of this checklist covers.

Two important distinctions before you start:

Deactivate vs. delete. For most tools, deactivate the user (blocks access, preserves data and history) rather than deleting them (permanent, may remove records). Delete only after confirming data has been transferred or is no longer needed.

Account owner transfer. If the departing employee was the account owner or admin for any tool, transfer ownership before deactivating their account — otherwise you may lose admin access entirely.

Annual contracts. Finding a ghost seat on an annual contract does not mean immediate savings. Flag these for renewal-cycle action. Focus immediate cancellations on monthly-billing tools.


Section 1 — Identity and Access (Do This First)

These are the master keys. Start here.

Important clarification: Suspending a Google Workspace or Microsoft 365 account blocks the user from Gmail, Drive, and Microsoft apps — but it does NOT automatically cut off access to Slack, Zoom, LinkedIn, Salesforce, or other third-party tools. Each tool on this checklist still needs to be deactivated manually. Automatic propagation only happens if your company specifically configured SCIM provisioning between Google/Microsoft and each tool — which most companies at 50-250 employees have not done.

Google Workspace

  • Admin Console → Directory → Users → find user → More actions → Suspend user
  • Before suspending: transfer Drive file ownership, transfer calendars (starting 2026, calendar deletion is permanent when the account is deleted)
  • After data is transferred: delete the account to stop billing (note: Annual Plan billing continues until renewal even after deletion)
  • After suspension, run the Google OAuth audit to find and revoke third-party app connections: Admin Console → Reporting → Audit and investigation → OAuth log events → filter by their email

Microsoft 365 / Entra ID

  • Microsoft 365 Admin Center → Users → Active users → select user → Block sign-in
  • Then: transfer OneDrive files, reassign mailbox if needed, delete after data handling

SSO / Identity Provider (Okta, JumpCloud, OneLogin)

  • Most companies at 50-250 employees do not use a standalone identity provider like Okta or JumpCloud. If your company does: Admin panel → People or Directory → find user → Deactivate. For apps that support SCIM provisioning to your IdP, deactivating here will propagate automatically. For apps that do not support SCIM, you still need to deactivate manually in each tool.
  • If you are unsure whether your company uses an IdP: you almost certainly don't. Move on to Google Workspace above.

Shared Password Manager (1Password, LastPass, Bitwarden)

  • Remove the user from the team vault immediately
  • Rotate any shared passwords or credentials they had access to — especially admin accounts, social media logins, and vendor portals

Section 2 — Communication Tools

Slack

  • Settings & administration → Manage members → find user → Deactivate
  • Messages and files remain accessible after deactivation
  • Seat is freed for reassignment upon deactivation

Zoom

  • User Management → Users → click the three dots beside the user → Delete (or change User Type to Basic to downgrade to a free seat without full deletion)
  • If they owned recurring meeting links used by the team, transfer those before removing

Microsoft Teams

  • Handled by Microsoft 365/Entra ID deactivation if on M365

Email (if not handled by Google/Microsoft suspension)

  • Set up an out-of-office auto-reply with redirect contact
  • Set up email forwarding to their manager or a team inbox (30-90 day window is standard)
  • Deactivate after the forwarding period

Loom / video messaging

  • Admin workspace settings → Members → remove
  • Download any videos owned by the user that the company needs to retain

Section 3 — Project Management and Collaboration

For all tools in this section: before removing the user, reassign any open tasks, projects, or documents they own to a current team member.

Notion

  • Settings → Members → find user → Remove from workspace
  • Reassign pages they own before removing

Asana

  • Admin console → Members → Deactivate
  • Reassign their open tasks first

Monday.com

  • Admin → Users → Deactivate
  • Reassign boards and items

Jira / Confluence (Atlassian)

  • Atlassian Admin → Managed accounts → find user → Deactivate
  • Deactivating removes product access but preserves issue history and comments

Linear

  • Settings → Members → Remove
  • Reassign open issues

Trello

  • Workspace Settings → Members → Remove from workspace

Airtable

  • Workspace Settings → Members → Remove
  • Reassign bases they own

Section 4 — Finance, Expense, and Payments

Corporate card

  • Notify the card issuer (Amex, Visa, Mastercard) to cancel the physical card immediately
  • Cancel any virtual cards issued to that employee
  • Review the last 90 days of charges on their card for any SaaS subscriptions to add to the rest of this checklist

Expense management (Expensify, Concur, Ramp, Brex, Divvy)

  • Admin → Users or Members → deactivate the account
  • Process any outstanding expense reports before deactivating
  • Ramp and Brex: also cancel any virtual cards issued to the user specifically

Bill payment / accounts payable tools

  • Remove them as an approver from any payment workflows
  • Check if they had signing authority on any vendor contracts

Section 5 — CRM and Sales Tools

Salesforce

  • Setup → Users → find user → Deactivate (do not delete — deletion removes record ownership history)
  • Reassign their accounts, contacts, and open opportunities to another rep before deactivating

HubSpot

  • Settings → Users & Teams → remove user
  • Reassign their contacts and deals first

Pipedrive / other CRMs

  • Admin or Settings → Users → deactivate
  • Reassign open deals and contacts

Section 6 — Recruiting and Staffing Tools

LinkedIn Recruiter

  • Go to LinkedIn Recruiter homepage → hover over profile picture → Manage users in Account Center → Users tab → find user → More → Manage license → No license
  • Critical: removing the license does NOT reduce your billing. You free the seat for reassignment, but must contact LinkedIn separately to reduce the contracted seat count and lower your invoice. If a new hire is starting soon, reassign the seat instead.

Indeed

  • Sign in to employer account → Users page → find user → three dots in Actions column → Remove

ZipRecruiter

  • Contact ZipRecruiter support to remove individual users on paid accounts: support@ziprecruiter.com or 855-813-0288

ATS (Bullhorn, Greenhouse, Lever, Crelate)

  • Admin → Users → Deactivate
  • Reassign their open reqs and candidate pipelines before deactivating
  • Check whether they were the account owner for any job board integrations connected to the ATS

Section 7 — AI Tools

This section catches the most commonly missed subscriptions. AI tools are frequently purchased individually without going through procurement — check both admin panels and card statements.

ChatGPT Team (OpenAI)

  • Admin settings → Members → remove

Claude Team (Anthropic)

  • Admin panel → Members → remove

Otter.ai

  • Account Settings → Members → deactivate
  • Note: Otter.ai integrates with Google Calendar to auto-join meetings. After deactivating, verify the Google Calendar integration has been removed so the bot no longer joins team calls

Fireflies.ai

  • Admin → Members → remove or deactivate
  • Same Google Calendar integration note as Otter.ai

Grammarly Business

  • Admin panel → Members → remove

AI writing tools (Jasper, Copy.ai, Writesonic)

  • Admin or workspace settings → Users or Members → remove

GitHub Copilot

  • If the user's GitHub organization membership is removed (see Section 8), their Copilot license is freed automatically
  • If they had an individually purchased Copilot license, it is tied to their personal GitHub account and will not appear in your org admin — only catchable via card statement

Section 8 — Design, Development, and Creative Tools

Figma

  • Admin → Members → remove
  • Seat is freed immediately upon removal
  • Transfer ownership of files they own before removing

Canva for Teams

  • Admin → People → remove from team
  • Download or transfer any brand assets they created

Adobe Creative Cloud

  • Adobe Admin Console → Users → find user → Remove from organization
  • The license is freed for reassignment immediately

GitHub

  • Organization Settings → Members → Remove from organization
  • Review any repositories they owned and transfer or archive as appropriate
  • Revoke any API tokens or SSH keys associated with their GitHub account (they should have been using organization-level access, but verify)

Cursor / AI coding tools

  • Admin or team settings → remove user
  • If purchased individually on a personal or company card, cancel the subscription directly

Other development tools (Linear, Jira, Sentry, Datadog, etc.)

  • Admin or Settings → Users → deactivate or remove

Section 9 — Shadow Tools (Run Last)

These steps catch subscriptions and access that did not go through formal procurement and will not appear on any of the lists above.

Google OAuth audit

Go to: Admin Console → Reporting → Audit and investigation → OAuth log events

Filter by the departed employee's email. Extend the date range to 90 days. This shows every third-party tool they ever authorized with their work Google account. For each tool that appears:

  • Check whether the company has a paid account with that tool
  • Revoke the OAuth token directly from the admin panel (Admin Console → Security → Access and data control → API controls → Manage third-party app access)

Card statement review

Pull 90 days of corporate card and expense reimbursement history. Filter for recurring charges associated with the departed employee's name or email. Any SaaS subscription that does not appear in sections 1-8 above is a shadow tool — something they purchased without going through IT or procurement. Cancel directly with the vendor.

Common shadow AI tools found here: OPENAI, ANTHROPIC, OTTER, FIREFLIES, MIDJOURNEY, RUNWAY, PERPLEXITY, GRAMMARLY, JASPER.


One Thing You Can Do Right Now

If you do not have a formal offboarding process for software, create a copy of this checklist in a Google Sheet or Notion page today. Add a column for "Date completed" and "Who handled it." The next time someone leaves, assign the checklist to the ops manager or IT admin before the person's last day. Starting it before the final day — while you still have the departing employee available to answer questions about what tools they used — is the single most effective way to catch shadow tools.


Frequently Asked Questions

Q: Should I complete this checklist before or after the employee's last day?

Start it before their last day wherever possible. The departing employee can tell you what tools they use — which is the fastest way to catch shadow tools that would otherwise only surface in a card statement review weeks later. Complete the identity and access section (Google/Microsoft suspension) on or just after the last day. The card statement review is most practical 30-60 days later, after the final billing cycle clears.

Q: What if the departing employee was the account owner for a tool?

Do not deactivate their Google or Microsoft account until you have transferred ownership on every tool where they were the sole account owner. For each tool: log in while you still have access to their credentials (or contact the vendor's support team to request an ownership transfer), assign a new owner, then deactivate. Deactivating the Google account first can lock you out of any tool where they used Google SSO as the owner.

Q: Do I need IT access to run this checklist?

For Google Workspace and Microsoft 365: yes, you need Super Admin or Global Admin access. For most other tools: you need admin access within each platform, which is often held by a department head, ops manager, or finance person — not necessarily the IT team. For small companies without a dedicated IT function, the operations director or CFO typically handles this. The Google OAuth audit and card statement review require no IT involvement.

Q: What about tools on a personal card that get expensed monthly?

These are the hardest to catch and the most commonly missed. A departing employee may have subscribed to tools using their personal card and submitted monthly expense reports. These will not appear in the card statement review (which covers company cards) and will not appear in the Google OAuth audit (if they used a personal Google account). The only reliable way to catch these is to ask the departing employee directly before they leave: "Are there any tools you subscribe to and expense monthly that the company should know about?" Most people will answer honestly when asked directly in the offboarding conversation.

Q: How long do I have before missing a billing cycle?

For monthly-billing tools: each day you wait is a day that billing cycle moves closer to the next charge. For tools billed on the 1st of the month, a departure on the 15th gives you 15 days before the next charge. Complete the checklist within 48 hours of departure for the best chance of catching the next billing cycle. For annual contracts, the urgency is lower for the current cycle — focus on flagging them for renewal-cycle action rather than immediate cancellation.

Q: What if I find the departing employee still has active access to a tool weeks later?

Cancel immediately regardless of how much time has passed. Then check whether the account was accessed during the gap — most SaaS admin panels show last login timestamps. If the account was accessed after the employee's departure date, document it and escalate to HR or legal depending on what was accessed.


Terrier automates steps 1 and 9 of this checklist — cross-referencing your Google Workspace directory against corporate card transactions to surface ghost seats and shadow tools without you having to run each section manually. terrierops.com