CrossTenant
Home / Use cases / Offboarding a leaver

Offboarding a leaver

Leaver day is a checklist run across half a dozen Admin console tabs, usually under time pressure, and the misses are exactly the ones that hurt: a live forward nobody switched off, a delegate nobody remembered. CrossTenant runs the whole thing as one guided, audited flow.

Prefer email? Get in touch and we run onboarding with you.

What's included

One guided flow

Pick the leaver and the wizard assembles the whole sequence: sign out every session, reset the password to an undisclosed random value, revoke OAuth tokens and app passwords, invalidate 2-Step Verification backup codes, set the leaver auto-reply, forward and delegate the mailbox, remove group memberships, move the account to the leavers OU, start the Drive and Calendar transfers, reclaim licences, and suspend.

drive transfer calendar transfer licence reclaim

Live preview and warnings

Every step shows a preview read live from the tenant before anything runs: the third-party tokens the leaver has granted, the groups they belong to, where mail is about to go. Warnings surface the awkward cases up front (an in-flight data transfer, a truncated group list), so you commit with your eyes open.

live preview warnings first

Safe canonical order

Whatever order you tick the steps in, the server re-sorts them into one safe canonical order: mail steps run before suspension, so the auto-reply, forwarding and delegation actually take effect, and suspend always runs last. The run starts only after you type the leaver's email address in full.

suspend last typed confirmation

Fail-soft execution

One failed step doesn't abandon the run: the flow records the failure and carries on, so an API error at step four doesn't stop the remaining steps. Each step finishes with its own result, and the whole sequence is written to the tamper-evident audit trail.

fail-soft audited sequence

Offboarding handover report

A dedicated offboarding PDF captures what a departure needs handing over: the groups the leaver belonged to, their Drive footprint, mail delegates and forwarding, and recent activity. The run itself is recorded step by step in the audit trail, so what happened and who confirmed it stays answerable.

pdf handover audited run

Optional second approver

Where a leaver is a sensitive event, the whole run can be gated behind a second approver: the request parks as pending, a colleague reviews a fresh preview, and the run executes only once they approve. How the gate works is on the approvals & audit page.

second approver parked request

Forwarding and delegate targets must be internal to the customer's domain, because an external target needs the recipient to verify ownership and that cannot be driven reliably from a console. Licence reclaim revokes the licence rather than moving the account onto an Archived User licence: that mapping is per customer and is roadmap work, so archive in the Admin console if you need it and leave the licence step off. The flow offboards one user per run, which is what makes each run one preview, one confirmation, and one audit record. The Gmail steps (auto-reply, forwarding, delegation) run over domain-wide delegation, a separate, customer-approved grant.

Leaver day

Make leaver day a non-event

Bring the offboarding checklist you run today, and see it become one previewed, confirmed, audited flow.