Your CloudM Automate licensing tier determines how many distinct offboarding workflows you can configure. Each workflow is a sequence of steps you assemble yourself, so the process fits how your organisation works. Most workflows follow the same broad shape: initial requests such as approval and resource allocation, locking the user out, changing account settings, transferring data to active users, archiving data, and a final step that suspends the user, or deletes them.
Before you start
Work through this checklist before configuring your workflows:
- Map out sets of users. Identify whether you need different offboarding steps by department (for example, C-suite versus general staff) or location. Simply, this means using OUs, or for more granular targeting, Smart Teams (CloudM's enhanced Google Groups).
- Choose your executors. Identify who the default decision makers are for each offboarding workflow.
-
Confirm data residency requirements. Decide where archived data needs to sit, for example:
- Separate GCS buckets for C-suite versus other staff.
- Local GCS buckets for UK staff versus US staff. Using more than one bucket can bring location-based egress costs; see the Google Cloud Storage FAQs for details.
- Identify required steps. List the mandatory security actions, such as revoking OAuth tokens, transferring file ownership, or triggering approval requests.
- Check your Automate tier. Confirm your current plan covers the number of custom workflows your business needs.
Choosing your tier
Your CloudM Automate licensing tier determines how many distinct offboarding workflows you can configure:
- Essential: 1 offboarding workflow. Suits small to medium businesses with flatter organisation structures and a single, unified offboarding process for all users.
- Pro: up to 3 offboarding workflows. Suits small to medium businesses managing more distinct sets of users, such as standard employees versus executives, or multi-region compliance.
- Enterprise: unlimited offboarding workflows. Suits larger organisations that need a dedicated workflow per department, location, or subsidiary.
Feature comparison
| Capability | Essential | Pro | Enterprise |
|---|---|---|---|
| Max workflows | 1 | Up to 3 | Unlimited |
| GCS archive bucket options | 1 | Up to 3 | Unlimited |
| Role-based customisation | Single workflow | Up to 3 tailored paths | Unlimited tailored paths |
| Regional compliance support | Single region | Multi-region (up to 3) | Multi-region / global |
Note on Workflows vs workflow steps: Each offboarding workflow can combine any of the available offboarding steps in any order, regardless of tier. Your tier only limits how many distinct workflows you can set up - not how sophisticated each one is. So an Essential customer with one workflow can still build it to handle multiple scenarios with conditional logic, approval gates, and the full range of steps.
Example workflows
Four typical ways to combine offboarding steps in CloudM Automate. See the full list of available offboarding steps for what each one does and where it can go in a workflow.
Standard employee offboarding
Best for: the everyday leaver departing on ordinary terms, whose account can be removed once their data is preserved and handed over.
Goal: quick access revocation, data preservation, license release and user deletion.
Access is cut first. Suspending the user and changing the password locks them out, then revoking 2-step verification, recovery methods, application-specific passwords, OAuth tokens and delegate access closes every remaining way back in, including live sessions and connected apps. The mailbox is then tidied so senders are redirected and nothing forwards onward, and the account is hidden from the directory. Data is archived for retention before documents, calendar and email are transferred to colleagues who still need them. The account is then wound down: suspended, its license unassigned to stop billing, and finally deleted.
- Preemptively Suspend User
- Change Password
- Revoke 2-Step Verification
- Remove Recovery Methods
- Revoke Application Specific Passwords
- Revoke OAuth Tokens
- Revoke Existing Delegate Access
- Set Out of Office Message
- Remove Email Forwarding Settings
- Hide User
- Archive
- Purge Backup
- Transfer Ownership of Documents
- Migrate Calendar Events
- Migrate Emails
- Suspend User
- Unassign Licenses
- Delete User
Executive and C-suite offboarding (high security, in a Google Vault-enabled Workspace)
Best for: a senior or high-risk departure that needs formal sign-off and a full audit trail, where data must be retained on legal hold rather than removed.
Goal: controlled sign-off with strict oversight before any data movement or account changes, ending with the user as an Archived User whose data is retained in Google Vault.
Nothing runs until Legal or HR approve, and a prompt to reallocate resources settles who inherits the person's assets before anything moves. Because executives hold sensitive data on managed devices, mobiles are wiped early, alongside the same full lock-out used for a standard leaver. A wider set of transfers then hands over everything a senior user typically owns (documents, calendars, groups, contacts and shared drives) and removes them from groups so they receive nothing new. Their email is migrated, and rather than deletion the account becomes an Archived User, keeping its data on legal hold in Vault.
- Request Approval (from Legal or HR)
- Preemptively Suspend User
- Prompt for Resource Allocation (ensure resources are correctly reallocated)
- Wipe Mobile Devices
- Change Password
- Revoke 2-Step Verification
- Remove Recovery Methods
- Revoke OAuth Tokens
- Revoke Existing Delegate Access
- Remove Email Forwarding Settings
- Transfer Ownership of Documents
- Migrate Calendar Events
- Transfer Ownership of Groups
- Transfer Contacts
- Transfer Shared Drives
- Remove From Groups
- Migrate Emails
- Apply Google Archived User (AU) License
Regional and compliance-driven offboarding
Best for: leavers whose data must stay in a particular region or jurisdiction and be retained rather than deleted.
Goal: meet data residency requirements (for example, GDPR in the UK/EU versus US data privacy standards) by keeping each region's data in its own GCS bucket and parking the account in a region-specific leavers OU rather than deleting it.
This flow is about where the data lives, not just closing the account. The user is locked out with the same full security sequence as a standard leaver, then their account is archived to that region's own GCS bucket so residency is preserved, moved into a region-specific leavers OU, and suspended - which parks it for the retention window instead of deleting it.
- Preemptively Suspend User
- Change Password
- Revoke 2-Step Verification
- Remove Recovery Methods
- Revoke Application Specific Passwords
- Revoke OAuth Tokens
- Move User (to a region-specific leavers OU)
- Archive (to a region-specific GCS bucket, for example US staff to a US bucket, UK staff to a UK bucket)
- Purge Backup
- Transfer Ownership of Documents
- Migrate Calendar Events
- Migrate Emails
- Suspend User
Vault-enabled Workspaces: reducing redundant Archived User costs
Best for: Vault-enabled Workspaces where Archived User licenses are being used inefficiently for users who do not require long-term legal hold in Google Vault.
Goal: delete the user account and migrate their data to GCS, replacing Google's expensive Archived User licenses with CloudM's lower-cost Archive and storage model while maintaining full compliance and retention.
For Vault-enabled organisations with users who don't require long-term legal hold in Google Workspace, this workflow trades Google's expensive Archived User license model for CloudM's more cost-efficient Archive infrastructure. The user is locked out with a full security sequence, then all data - including Vault archives - is migrated to GCS for compliance and retention. The account is then suspended, licenses unassigned, and the user deleted, eliminating the recurring Google Archived User license cost while maintaining full data preservation and auditability.
- Preemptively Suspend User
- Change Password
- Revoke 2-Step Verification
- Remove Recovery Methods
- Revoke Application Specific Passwords
- Revoke OAuth Tokens
- Revoke Existing Delegate Access
- Set Out of Office Message
- Remove Email Forwarding Settings
- Hide User
- Archive
- Archive Vault
- Purge Backup
- Transfer Ownership of Documents
- Migrate Calendar Events
- Migrate Emails
- Suspend User
- Unassign Licenses
- Delete User