Plan an arrival around the employee’s role; plan a departure around access to remove and work to hand over. In both Microsoft 365 and Google Workspace, separate access removal, data retention and account deletion. They serve different purposes and do not necessarily belong on the same schedule.

A small business or nonprofit can manage this with a checklist shared by the manager, human resources and the technology administrator. Every action needs an owner, authorization and confirmation that it was completed.

Before arrival: define the role and access

The manager confirms the start date, responsibilities, required tools and people authorized to approve access. Avoid copying all of a colleague’s permissions: that account may have accumulated exceptions over time.

Prepare:

  • a named account and a licence that fits the role;
  • relevant groups, teams, shared mailboxes and calendars;
  • appropriate SharePoint, OneDrive or Google Drive locations;
  • business applications and their owners;
  • the computer, peripherals and remote connection where needed;
  • MFA, recovery methods and a secure activation channel.

Temporary and external roles should have an access review date. Do not grant administrator privileges simply to make software installation easier.

On day one: test actual work

Check sign-in, email, the calendar, a team file and a meeting. Confirm that information is saved in the intended locations rather than only on the desktop or in a personal account.

Explain how to get help, report a suspicious message and use approved tools. Practise MFA and recovery according to the organization’s procedure. During the first week, have the manager confirm that permissions are sufficient without being excessive.

Prepare the departure with proper authorization

The timing of access removal is an authorized decision coordinated with human resources or leadership. A planned departure and an urgent interruption require different timing. Do not communicate the removal plan only through the mailbox that will be disabled.

Inventory files, mailboxes, active projects, devices, groups and external applications. Identify who takes over each responsibility. Specify retention requirements, restrictions on access to records and communications needed for colleagues or clients.

At departure: remove access without erasing the work

At the agreed time, block or suspend sign-in as appropriate and revoke applicable sessions or tokens. Check third-party applications: disabling a Microsoft or Google identity does not necessarily close every independent account. Verify remaining access instead of assuming everything stops instantly.

Remove privileged roles, sensitive group membership and remote access. Recover devices and follow the approved process for managed equipment. Handle personal devices under the agreed rules; distinguish business information from private content.

Reassign administrative responsibilities and replace shared secrets the person could access where necessary. Notification and billing addresses may also need to change.

Transfer and retain data before deletion

In Microsoft 365, review email, OneDrive, groups and responsibilities in Teams or SharePoint. In Google Workspace, examine Drive files, calendars, groups and resources the person managed. Transfer methods and recovery periods vary by service, licence and configuration.

Grant only authorized handover access; do not pass along the former employee’s password. Have the business owner validate the transfers. Check retention features and particular obligations before removing a licence or deleting the account. Microsoft’s employee departure documentation provides a reference to adapt to your environment.

Nonprofits can also use the Google Workspace setup guide to anticipate changes among volunteers and board members.

Close the checklist and revisit exceptions

Keep confirmation of completed actions, who validated the data and what remains outstanding. Check licence billing, temporary email forwarding and delegated access that needs to end later.

This routine connects Microsoft 365 and Google Workspace administration with IT support for devices and access. Include it in the technology roadmap if it still depends on one person remembering every step.