Offboarding in Google Workspace: The Drive Access Checklist

8apps Team·

Suspend, transfer, verify – in that order. The admin checklist for a leaver's Google Drive: what Google's deletion flow handles, the 20-day trap, and the shares everyone forgets.

Offboarding is a Drive problem wearing an HR badge

The account gets suspended on time. The laptop comes back. And six months later somebody notices the ex-employee's spreadsheet is still shared with a personal Gmail address, or a client folder they set up still has an outside agency in it.

Google's own offboarding flow handles the ownership problem well. What it does not do is tell you what the leaver had shared, with whom, before they left. Here is the checklist that covers both.

Step 1 – suspend first, delete later

Google's guidance distinguishes the two: suspension blocks access immediately and reversibly; deletion is for when the person has actually left and you have dealt with their data. Suspend on day one. Delete when the checklist below is finished – not before.

Step 2 – transfer Drive ownership during deletion

When you do delete the account, the Admin console's deletion flow offers to transfer the user's Drive and Docs files to another account – typically the manager or a team archive account. Take the offer every time.

The trap is documented and unforgiving: Drive files the leaver owned that you do not transfer are saved for 20 days, and even then only if you restore the user. After that window, they are gone. If a leaver owned anything that mattered – and you rarely know that they didn't – the transfer step is not optional.

Step 3 – the part the deletion flow never mentions: their shares

Transferring ownership moves the files. It does not answer the sharing question: what did this person share externally, which links did they open up, and which of their old shares should have died with their employment?

This is the part that resurfaces months later – suspending an account does not touch it. And it is a state question – what is shared right now – which the deletion flow, and the activity log, are not built to answer.

Run an org-wide sharing audit as a standard offboarding step: scan the transferred files and the team's Drives for external access, public links and legacy access, and clear what the leaver leaves behind while the context is still fresh. Drive Guard for Admins does this from one dashboard – one admin install covers every user, scans span all users' My Drives and Shared Drives, and the results export cleanly for the offboarding record. US$4.80 per user per year launch price, 7-day trial, free for education institutes.

Step 3b – remove them from shared drives and groups

While the account is suspended, take the leaver out of the places that grant access by membership rather than by file. In Menu → Apps → Google Workspace → Drive and Docs → Manage shared drives, check every drive they belonged to – and run the No managers filter, because if they were the only Manager on a drive nobody left can add members to it. Remove them from Google Groups too: a group that still lists them is a standing grant on everything shared with that group.

Step 4 – verify, and file the proof

Close the ticket with evidence, not memory: the transfer confirmation, and an export showing the leaver's externally shared items were reviewed and dispositioned – kept deliberately, or restricted. The export is what turns "we offboarded them" into something you can show an auditor a year later.

The checklist, compressed

  1. Day one: suspend the account.
  2. Before deletion: transfer Drive/Docs ownership in the deletion flow – untransferred owned files survive only 20 days, and only via restore.
  3. Same week: remove them from shared drives and groups, and run the No managers filter; then run the sharing audit – external shares, public links, legacy access tied to the leaver's work.
  4. Close: export the results into the offboarding record.

Print it, or steal it into your runbook. The order is the point: suspend before you audit, audit before you delete.

Sources

  • Delete or remove a user from your organization – suspend-vs-delete guidance; "During the deletion process, super admins can transfer the user's Drive and Docs files"; "Drive files the user owns—These files are saved for 20 days but are only accessible if you restore the user". Re-read 2026-09-09.
  • Manage shared drives as an admin – Admin console path; the No managers filter; only Managers add members. Re-read 2026-09-09.