Start with the leaver's main work account: reset its password, sign it out everywhere and suspend or block it, which cuts off every AI tool they reach through it. Then remove them from each AI workspace, change every shared password and authenticator they held, revoke their API keys and app connections, and reassign their chats, projects and automations.
The work account is the easy part. Leaks come from everything that isn't tied to it: a ChatGPT Plus subscription opened with a personal email and paid on the company card, the social media login the whole office shares, an authenticator app on the leaver's own phone, an API key pasted into an automation, or a meeting-notes bot still connected to their calendar. Suspending the account touches none of those.
Build an access register before anyone hands in notice
An offboarding can only remove what you know about. The fix is a simple register: one row per tool, recording how each person signs in and what they hold there. It takes about an hour to build the first time and five minutes to update when someone joins or a new tool arrives. Keep it in the same place as your staff files, not in the leaver's own Drive.
Here is an illustrative register for a 14-person cleaning company whose operations supervisor is leaving. It is the kind of list most small firms discover they need halfway through their first messy departure.
| Tool | How the supervisor signs in | What they hold there | Offboarding action |
|---|---|---|---|
| Google Workspace | Company account | Gmail, Drive, Calendar, Gemini | Reset, sign out, suspend, transfer Drive, delete later |
| ChatGPT Business | Work email | 3 projects, including the shared "Quote replies" project | Remove member, then remove the seat |
| Claude Pro | Personal Gmail, company card | Unknown | Ask them to cancel; stop the card |
| Rota and scheduling app | Work email and password | Admin role | Remove admin, delete user |
| Instagram and Facebook | Shared password | Admin; two-step codes go to their phone | Move two-step verification first, then change password |
| Zapier | Work email | 4 Zaps running on their Gmail connection | Reconnect to the shared bookings mailbox |
| AI meeting note-taker | Work Google account | Joins client walk-throughs automatically | Disconnect calendar, delete account |
| OpenAI API key | Created under their login | Powers the website quote form | Create new key, update form, delete old key |
Three rows on that list would have been missed without the register: the personal Claude subscription, the authenticator on the supervisor's phone and the API key. Each of those survives the work account being switched off, and each one belongs to the company, not the person.
First hour: close the work identity properly
The order matters more than the speed. Changing a password without signing out existing sessions leaves the leaver logged in on their phone; suspending an account before you have reconnected automations breaks them mid-week. Work in the sequence below, ideally in the hour after the leaving conversation or at the end of their last shift.
If your business runs on Google Workspace
Google's own checklist for a departing employee, published in Workspace Admin Help, covers seven actions. In practice they run like this:
- Remove work data from their phone. In the Admin console you can wipe the whole device (company phones) or only the account's data (personal phones). Verify: the device shows as wiped or removed in the device list.
- Remove their recovery email and phone number so nobody can reset the password from outside. Verify: the user's security page shows no recovery details.
- Change the password. Use a long random one and store it in your password manager, not in an email.
- Revoke OAuth tokens, the permissions they gave apps such as AI email assistants, note-takers and scheduling tools. Verify: the user's connected-apps list is empty.
- Reset sign-in cookies, which signs them out of browsers and devices where they were still logged in.
- Revoke security keys and app passwords. App passwords are easy to forget and bypass normal sign-in.
- Suspend now, delete later. Suspension blocks sign-in but keeps mail and files for handover. Transfer their Drive files to a manager, then delete the account and release the licence.
If your business runs on Microsoft 365
Microsoft's guidance in Microsoft Learn starts with the password, and there is a timing reason for that. In the Microsoft 365 admin centre, go to Users, then Active users, select the person and choose Reset password. Then open the Account tab and select Sign out of all sessions. Access tokens last up to an hour, so the leaver is prompted to sign in again within that hour, or sooner if they move to another page.
Block sign-in comes next, but Microsoft warns it can take up to 24 hours to take effect, which is why it is not your first move. If they used email, turn off their mailbox access in the Exchange admin centre (Outlook desktop, Exchange web services, mobile, IMAP, POP3 and Outlook on the web). If you need to keep the mailbox, convert it to a shared mailbox; a shared mailbox usually doesn't need a licence, though archiving settings can change that, so check before you remove it.
A quick sum shows why the last step, removing licences, is worth doing carefully. A Microsoft 365 Copilot Business licence is $21 per user per month on annual billing. Reassigning the leaver's licence to their replacement costs nothing; leaving it attached to a blocked account while buying a new one for the replacement wastes $252 a year on a seat no one can use.
Then work through each AI workspace
Blocking the work account stops sign-in, but the leaver still appears as a member, still holds a seat and may still own content other people use. Each AI tool handles removal differently.
ChatGPT Business
Removing a member ends their workspace access immediately. According to OpenAI's help centre, their chats are kept and flagged for deletion under your workspace's retention policy, while projects and GPTs they owned are reassigned to a workspace owner rather than deleted. If the person later rejoins, ownership moves back to them.
The step people miss is billing. Removing a member does not remove their seat from the billable count; a workspace owner has to remove the seat separately, and billing stops from the next cycle. Two forgotten seats at $25 a month each, the monthly Standard price, cost $600 a year.
If the leaver owned custom GPTs, write down what each one did. OpenAI is retiring custom GPTs anyway (they stop running on 11 December 2026), so treat their GPTs as a list of jobs to rebuild in a shared project, not as assets to preserve.
Claude Team
Once a member is removed, remaining colleagues can no longer open that person's chats, and shared chat links show a "Conversation not found" message. What happens to projects depends on how they were shared, per Anthropic's help centre:
- Projects shared with the whole organisation move to the Team tab, where colleagues can keep using them.
- Projects shared with named people appear under "Shared with me" for those people.
- Private projects become inaccessible to everyone else.
So the useful action happens before the last day: ask the leaver to share any project the team relies on with the organisation. Their data is still included in exports run by your Primary Owner, and if you re-add them with the same email address, their chats, projects and skills come back.
Copilot and Gemini
These sit on the work identity, so blocking the Microsoft or Google account stops them. The remaining job is licences (reassign the Copilot licence as above) and files: Gemini and Copilot can only reach what the account could open, so once Drive or OneDrive files are transferred, the replacement gets the same material for their own AI tools.
AI tools on the leaver's personal accounts
You cannot remove someone from a personal ChatGPT Plus or Claude Pro account. Ask them in writing to cancel anything paid by the company, remove the company card and delete business content from the history. If the card was used and they don't respond within a few days, cancel or replace it. Then close the gap by moving everyone onto company AI accounts instead of personal logins, so the next departure is a single removal.
Shared logins and the authenticator trap
Most small firms share a handful of logins: the Instagram and Facebook pages, a supplier portal, the company Canva, the booking platform's admin view. Every password the leaver knew must change, and the safest place to do that is a password manager, where you can see who had access to each item and change it once. There is a full method in sharing AI tool logins through a password manager.
The trap is two-step verification. If the codes for a shared account go to an authenticator app on the leaver's own phone, changing the password locks you out, because the next sign-in asks for a code only they can see. Picture how that plays out: the cleaning company changes the Instagram password on Monday morning, the login asks for a six-digit code, the supervisor has already left, and recovery through the platform's identity checks takes most of a week, during which nobody can answer booking messages.
Avoid it by moving two-step verification before the last day:
- While the leaver is still present, add a company-owned method (an authenticator stored in the password manager, or a phone number owned by the business).
- Remove their personal device from the account's security settings.
- Change the password and store it in the manager.
- Sign in from a clean browser to prove the new method works.
If your team doesn't yet have two-step verification on every AI and social account, set it up with company-owned methods from the start; turning on two-factor authentication for every AI account covers each major tool.
Keys, connections and bots that keep running
These are the items that break quietly a week later, or keep working when they shouldn't.
- API keys. If the leaver created or could see a key for OpenAI, Anthropic or another AI platform, rotate it: create a new key under a company-owned login, update every automation that uses it, confirm the automation runs, then delete the old key. Doing it in that order avoids an outage. Verify: the platform's usage page shows calls coming only from the new key.
- Automation connections. Zaps and Make scenarios often run on a person's Gmail or Outlook connection. When that account is suspended, they fail. In the cleaning company's case, the auto-reply to website quote requests would have stopped silently on day one. Reconnect them to a shared mailbox such as a bookings address before you suspend the account, then check the run history the next morning.
- AI note-takers. A meeting bot connected to the leaver's calendar can keep joining recurring client calls while the connection is live. Disconnect it from the calendar, delete its account and tell clients if it sat in on sensitive meetings.
- Browser extensions on shared computers. An AI writing extension on the office PC may still be signed in as the leaver. Sign it out or remove it.
- App permissions they granted. Anything the leaver approved to read company mail or files shows up in your admin console. The walkthrough in checking which apps can access your business accounts takes about 20 minutes.
Hand over the AI work, not only the access
A leaver's AI history is part of their working knowledge: the prompt that writes a decent complaint reply, the project instructions that make quote emails sound like the business, the reference files they curated. Losing it means the replacement starts from nothing. Who owns that history, and what you can keep, is covered in who owns AI chat history when an employee leaves; the practical part is asking for it in time.
Send something like this five working days before the last day:
Subject: Handing over your AI tools before Friday
Hi [name],
Before you finish on Friday, could you please:
1. Share the "Quote replies" and "Complaints" projects with the whole
team (Share > Organisation), or tell me if they're already shared.
2. Copy any prompts you use weekly into the team prompt document.
3. Tell me which tools you signed up for yourself, including any on
your personal email, so we can cancel or transfer them.
4. Let's move the Instagram two-step codes to the office phone on
Thursday at 3pm.
5. Please don't export client details or chats to personal accounts;
they stay with the business under our AI policy.
Thanks for everything,
[owner]
The fifth point is not an accusation. Most people who take material with them do it because nobody told them where the line was, and a written line also protects you if a client later asks how their data was handled.
A timeline for the leaver's final week
| When | What to do | Time it takes |
|---|---|---|
| 5 working days before | Update the access register, send the handover email, list shared logins and keys | 30 minutes |
| 2 days before | Move two-step verification; reconnect automations to a shared mailbox; share projects with the team | 45 minutes with the leaver |
| Last day, final hour | Reset password, sign out all sessions, revoke tokens, suspend or block; remove from AI workspaces; change shared passwords; rotate API keys | 40-60 minutes |
| Next morning | Check automation run history, test the shared logins, remove AI seats, reassign Copilot licence | 20 minutes |
| Within 30 days | Transfer files, convert or export mailbox, delete the account, confirm the next invoice shows fewer seats | 30 minutes |
For an unplanned or difficult departure, collapse the first three rows into the same hour. The two-step move is the only item you cannot do without the leaver, so if they are gone, start the platform's account-recovery process immediately rather than waiting until you need to post something.
How to prove the offboarding worked
Ticking boxes isn't the same as checking. A day or two after the departure, spend 15 minutes on these tests:
- Sign-in status. In the admin console, the account shows as suspended or blocked, and the sign-in log shows no successful sign-ins after the reset.
- Connected apps. The user has no remaining app grants, and no AI note-taker or email assistant is listed under their name.
- Member lists. The leaver is absent from ChatGPT, Claude and any other AI workspace, and the seat count matches your current headcount.
- Automations. Every Zap or scenario from the register has run successfully at least once since the switch.
- Shared logins. Each shared account signs in with the new password and a company-owned second step.
- Keys. Old API keys are deleted, not just unused.
- Invoice. The next bill from each AI vendor charges for the right number of seats.
The signs that something slipped through are predictable. A vendor invoice arrives with the same seat count as last month. An automation starts failing with "connection expired" a week later, usually on a Monday. A client mentions that a note-taking bot joined their call under the old supervisor's name. The shared inbox stops receiving replies because a filter lived in the leaver's mailbox. Each of these maps to a row that was missing from the register, so add it there as soon as you find it.
If you would rather set up the register and the leaver routine with someone who has done it for other small teams, that is part of what my AI implementation consultation covers. Most firms can run it themselves after the first departure; the second one is usually under an hour.
Offboarding questions owners ask about AI tools
Should I suspend or delete a leaver's work account straight away?
Suspend or block it first, not delete. Suspension stops sign-in while keeping mail, files and chat history available for handover. Once you have transferred Drive or OneDrive files, converted or exported the mailbox and checked nothing depends on the account, delete it and free the licence. Google's own guidance treats deletion as the final, most secure step, after the data you want to keep has been moved.
Can a leaver take their ChatGPT or Claude work chats with them?
On business plans the chats sit in your company workspace, and removing the member ends their access to it. They should not export client material to a personal account; say so in your AI policy and in the leaving email. If you want their useful prompts or project instructions kept, ask them to share or copy those into a team project before their last day.
What if the leaver signed up for AI tools with a personal email?
You cannot remove a personal account, so ask them in writing to cancel any subscription paid by the company, remove the company card and delete business content from its history. Cancel or replace the card if they don't respond. Then close the gap for the future by moving the team onto company accounts on a business plan.
How fast do I need to act if someone leaves on bad terms?
Reset the password and sign the account out of all sessions within minutes of the conversation, ideally while it is happening. In Microsoft 365, blocking sign-in can take up to 24 hours to apply, so the password reset and session sign-out matter more. Change shared passwords and rotate API keys the same day, then work through the rest of the checklist.
Further reads
- How to Set Up Single Sign-On for Your Team's AI Tools — SSO turns most AI offboarding into one switch in your identity provider.
- Shadow AI: How to Stop Staff Pasting Client Data Into Free Tools — Stops the personal-account sign-ups that make offboarding hard.
- How to Write an AI Usage Policy for Your Small Business — Put the leaver rules in writing before anyone hands in notice.
- AI Security Checklist Before Connecting Tools to Email and Files — The joiner-side checks that make leaver checks shorter.
- Business Data Backup Checklist Before You Connect AI Tools — Keep copies of what a leaver's account held before you delete it.
- ChatGPT Plus vs ChatGPT Business: Which Plan Does a Team Need? — Why a business plan gives you the remove-member controls in the first place.
- Who in Your Team Actually Needs a Paid AI Licence? — A three-question test for deciding who gets a paid AI seat, a two-week usage log, and a florist's before-and-after seat bill with 2026 list prices.
- How to Organise Shared Files So AI Tools Can Use Them — Three afternoons to get a shared drive ready for Copilot, Gemini or ChatGPT, with a wedding planner's folder tree and a ten-question test.
- Automation Audit: Find the Zaps and Scenarios Nobody Owns — An inventory template, platform-by-platform checks and a triage table for finding orphaned Zaps and Make scenarios before one quietly breaks.
- How to Onboard New Hires Onto Your AI Tools and Rules — A first-month plan for new starters on your AI tools: accounts before day one, one-page rules, buddy-checked tasks and a sign-off for wider access.
- How Virtual Assistants Use AI to Manage More Clients — Build a separate, checked workflow for each client and calculate whether the time recovered can support another retainer.
- How to Run Staff Surveys and Exit Interviews With AI Analysis — A 12-question survey, an exit interview script, anonymity settings, a theme-coding prompt with checks, and an online clothing shop's first round of results.
- Business Continuity Planning With AI: A Template for Small Firms — A ten-section continuity plan template with the checks for each item, plus prompts that let AI interview you and run a tabletop test.
- How to Keep Customer Data Private When Your Team Uses AI — Eight steps to keep customer details out of the wrong AI tools, with a filled-in data table, redaction examples, policy wording and a quarterly audit.
- How to Clean Up SharePoint Permissions Before Turning On Copilot — Copilot surfaces whatever each person can already open. A driving school's cleanup shows the reports, settings and tests that close the gaps first.
- How to Set Spending Limits and Alerts on Pay-As-You-Go AI Tools — Where the spend limits live in OpenAI, Anthropic, ChatGPT, Claude, Zapier, Make and n8n, and how to choose caps that stop a runaway without breaking bookings.
- AI Tools and AI Development: The Complete 2026 Guide — the AI hub, including every tutorial in the AI-for-business series.
Sources: Google Workspace Admin Help (maintaining data security after an employee leaves); Microsoft Learn (remove a former employee, step 1); OpenAI help centre (data retention when a member is removed; managing members and seats in ChatGPT Business); Claude help centre (what happens to a user's data when they are removed from a Team or Enterprise organisation). Prices from vendor pricing pages, September 2026.