The ticket says "suspend", and you do
Friday, 4:55pm. HR's ticket says Priya's last day is today, please suspend the account. You open the Admin console, find the user, click Suspend. The ticket closes. Priya cannot sign in any more.
Here is the claim this article argues: that click changed exactly one thing. It did not touch a single file she shared, and neither will the ownership transfer you run when the account is deleted next month. If part of your offboarding is "make sure nothing of ours is still open to outsiders", suspension is not the step that does it, and nothing in the standard Google flow is.
This is the narrow companion to our full offboarding checklist for Google Drive. That article is the whole procedure; this one is a single point, made properly.
What suspension actually does
Google describes suspending a user as blocking their sign-in, and it is reversible – unsuspend and the account comes back as it was. That is the entire documented effect. Nothing in it mentions permissions, because sharing is not a property of the account. It is a property of the file.
Over four years Priya built up a client folder shared with an outside agency's domain. A pricing sheet set to "anyone with the link" to get it into a supplier's inbox without the sign-in dance. A handful of Docs shared to her personal Gmail so she could work from the sofa. Each of those is a permission attached to a file, granted at the time, and it does not consult whether the person who granted it can still log in.
Suspending Priya removes Priya from the picture. It leaves everyone she let in exactly where they were.
The timeline of a typical leaver
Day 0: suspend. The account sits there for a few weeks while people ask whether they can "just get that one file from her Drive".
Weeks later: delete. Google's deletion flow offers to transfer ownership of the user's Drive and Docs to someone else. Files not transferred are kept for 20 days after deletion and are recoverable only by restoring the user. Miss the window and they are gone.
Look at what each step answers. Suspension answers "can she still get in?" Transfer answers "who owns her files now?" Not one of them answers the question that matters for exposure: what did she share, and with whom?
One thing we will be precise about. Google does not document what happens to the sharing settings on transferred files, and we are not going to guess. Treat every transferred file as sharing-unknown until someone has looked at it.
Where the Drive log helps – and where it stops
The one native place that records sharing changes is the Drive log. In the Admin console go to Menu → Reporting → Audit and investigation → Drive log events. The default view is the last seven days, so widen the date range first. Add a search condition on the Visibility change attribute – it is an attribute in the search conditions, not an event name – then filter on Priya as the actor. What comes back is every time she changed who could see a file.
Run it the week someone leaves, with two limits in mind.
The first is time. Drive log events are retained for six months. A share Priya set up in her first year is not there, and if the question comes up eight months after she left, the log has nothing to say about her at all.
The second is what a log is. It is activity history, not a current permissions map. It tells you what changed and when, not what is open right now. And external viewers who came in through a public link show up as anonymous, so the log will tell you an anonymous user downloaded something, not who.
On Business Starter, Standard and Plus this is where Google stops. The security investigation tool and the file exposure report – the pieces that let you ask "show me everything shared outside the domain" – sit on Enterprise, Frontline and Education Standard and Plus editions. On a Business edition you have the log, your own eyes, and whatever the leaver's manager remembers.
What to do the same week
Do the log pull first, for the full six-month window, and save the export with the ticket.
Then ask the leaver's manager one specific question: which outside organisations and which personal addresses did this person work with? Clients, agencies, contractors, a spouse who helped with a deck. That list is your map of where the shares probably point.
Check whether the leaver was the only Manager on any shared drive. Menu → Apps → Google Workspace → Drive and Docs → Manage shared drives, filter for drives with no managers, and add one – only Managers can add members. We cover this in auditing shared drive permissions org-wide.
Decide the ownership transfer target before deletion, not during it, and write down the date so the 20-day clock is not a surprise.
Then accept that you have answered "what changed recently" and not "what is open now".
The org-wide scan as the offboarding step
Drive Guard for Admins is a Workspace Marketplace add-on installed once by an admin. It scans every user's My Drive and every Shared Drive across the organisation and puts public links, external shares and legacy access on one dashboard, with exports. Run the scan as the last step of offboarding and work through the export for the files that belonged to the leaver. Because the scan is org-wide, you will also see what the people who left before Priya left behind – the subject of our piece on legacy access: files still shared with domains you stopped working with.
Today the tool reports and you fix in Drive. Revoking access from inside the dashboard is on the roadmap, not live. For the wider procedure this sits inside, start with auditing Google Drive access across the whole organisation.
Sources
- Delete or remove a user from your organization – read 2026-09-01 (for DGA-B4, re-cited): suspension blocks sign-in and is reversible; deletion flow offers Drive/Docs ownership transfer; untransferred files of a deleted user kept 20 days, recoverable only by restoring the user.
- Drive log events – Admin console path; default 7-day view; Visibility change attribute; external users appear as anonymous unless shared with individually or via a specific group; security investigation tool edition list (not Business editions).
- Data retention and lag times – Drive log events retained 6 months.
- File exposure report – edition list (Frontline Plus; Enterprise Plus; Education Standard and Plus; Enterprise Essentials Plus).
- Manage shared drives as an admin – Admin console path; filter for drives with no managers; admin can add members.
- Shared drive access levels – only Managers add members.