Skip to main content

Offboarding Workflows and Tiers: Use Cases and Examples

Your CloudM Automate licensing tier determines how many distinct offboarding workflows you can configure. Each workflow is a sequence of steps you assemble yourself, so the process fits how your organisation works. Most workflows follow the same broad shape: initial requests such as approval and resource allocation, locking the user out, changing account settings, transferring data to active users, archiving data, and a final step that suspends the user, or deletes them.

Before you start

Work through this checklist before configuring your workflows:

  • Map out sets of users. Identify whether you need different offboarding steps by department (for example, C-suite versus general staff) or location. Simply, this means using OUs, or for more granular targeting, Smart Teams (CloudM's enhanced Google Groups).
  • Choose your executors. Identify who the default decision makers are for each offboarding workflow.
  • Confirm data residency requirements. Decide where archived data needs to sit, for example:
    1. Separate GCS buckets for C-suite versus other staff.
    2. Local GCS buckets for UK staff versus US staff. Using more than one bucket can bring location-based egress costs; see the Google Cloud Storage FAQs for details.
  • Identify required steps. List the mandatory security actions, such as revoking OAuth tokens, transferring file ownership, or triggering approval requests.
  • Check your Automate tier. Confirm your current plan covers the number of custom workflows your business needs.

Choosing your tier

Your CloudM Automate licensing tier determines how many distinct offboarding workflows you can configure:

  • Essential: 1 offboarding workflow. Suits small to medium businesses with flatter organisation structures and a single, unified offboarding process for all users.
  • Pro: up to 3 offboarding workflows. Suits small to medium businesses managing more distinct sets of users, such as standard employees versus executives, or multi-region compliance.
  • Enterprise: unlimited offboarding workflows. Suits larger organisations that need a dedicated workflow per department, location, or subsidiary.

Feature comparison

Capability Essential Pro Enterprise
Max workflows 1 Up to 3 Unlimited
GCS archive bucket options 1 Up to 3 Unlimited
Role-based customisation Single workflow Up to 3 tailored paths Unlimited tailored paths
Regional compliance support Single region Multi-region (up to 3) Multi-region / global

Note on Workflows vs workflow steps: Each offboarding workflow can combine any of the available offboarding steps in any order, regardless of tier. Your tier only limits how many distinct workflows you can set up - not how sophisticated each one is. So an Essential customer with one workflow can still build it to handle multiple scenarios with conditional logic, approval gates, and the full range of steps.

Example workflows

Four typical ways to combine offboarding steps in CloudM Automate. See the full list of available offboarding steps for what each one does and where it can go in a workflow.

Standard employee offboarding

Best for: the everyday leaver departing on ordinary terms, whose account can be removed once their data is preserved and handed over.

Goal: quick access revocation, data preservation, license release and user deletion.

Access is cut first. Suspending the user and changing the password locks them out, then revoking 2-step verification, recovery methods, application-specific passwords, OAuth tokens and delegate access closes every remaining way back in, including live sessions and connected apps. The mailbox is then tidied so senders are redirected and nothing forwards onward, and the account is hidden from the directory. Data is archived for retention before documents, calendar and email are transferred to colleagues who still need them. The account is then wound down: suspended, its license unassigned to stop billing, and finally deleted.

  1. Preemptively Suspend User
  2. Change Password
  3. Revoke 2-Step Verification
  4. Remove Recovery Methods
  5. Revoke Application Specific Passwords
  6. Revoke OAuth Tokens
  7. Revoke Existing Delegate Access
  8. Set Out of Office Message
  9. Remove Email Forwarding Settings
  10. Hide User
  11. Archive
  12. Purge Backup
  13. Transfer Ownership of Documents
  14. Migrate Calendar Events
  15. Migrate Emails
  16. Suspend User
  17. Unassign Licenses
  18. Delete User

Executive and C-suite offboarding (high security, in a Google Vault-enabled Workspace)

Best for: a senior or high-risk departure that needs formal sign-off and a full audit trail, where data must be retained on legal hold rather than removed.

Goal: controlled sign-off with strict oversight before any data movement or account changes, ending with the user as an Archived User whose data is retained in Google Vault.

Nothing runs until Legal or HR approve, and a prompt to reallocate resources settles who inherits the person's assets before anything moves. Because executives hold sensitive data on managed devices, mobiles are wiped early, alongside the same full lock-out used for a standard leaver. A wider set of transfers then hands over everything a senior user typically owns (documents, calendars, groups, contacts and shared drives) and removes them from groups so they receive nothing new. Their email is migrated, and rather than deletion the account becomes an Archived User, keeping its data on legal hold in Vault.

  1. Request Approval (from Legal or HR)
  2. Preemptively Suspend User
  3. Prompt for Resource Allocation (ensure resources are correctly reallocated)
  4. Wipe Mobile Devices
  5. Change Password
  6. Revoke 2-Step Verification
  7. Remove Recovery Methods
  8. Revoke OAuth Tokens
  9. Revoke Existing Delegate Access
  10. Remove Email Forwarding Settings
  11. Transfer Ownership of Documents
  12. Migrate Calendar Events
  13. Transfer Ownership of Groups
  14. Transfer Contacts
  15. Transfer Shared Drives
  16. Remove From Groups
  17. Migrate Emails
  18. Apply Google Archived User (AU) License

Regional and compliance-driven offboarding

Best for: leavers whose data must stay in a particular region or jurisdiction and be retained rather than deleted.

Goal: meet data residency requirements (for example, GDPR in the UK/EU versus US data privacy standards) by keeping each region's data in its own GCS bucket and parking the account in a region-specific leavers OU rather than deleting it.

This flow is about where the data lives, not just closing the account. The user is locked out with the same full security sequence as a standard leaver, then their account is archived to that region's own GCS bucket so residency is preserved, moved into a region-specific leavers OU, and suspended - which parks it for the retention window instead of deleting it.

  1. Preemptively Suspend User
  2. Change Password
  3. Revoke 2-Step Verification
  4. Remove Recovery Methods
  5. Revoke Application Specific Passwords
  6. Revoke OAuth Tokens
  7. Move User (to a region-specific leavers OU)
  8. Archive (to a region-specific GCS bucket, for example US staff to a US bucket, UK staff to a UK bucket)
  9. Purge Backup
  10. Transfer Ownership of Documents
  11. Migrate Calendar Events
  12. Migrate Emails
  13. Suspend User

Vault-enabled Workspaces: reducing redundant Archived User costs

Best for: Vault-enabled Workspaces where Archived User licenses are being used inefficiently for users who do not require long-term legal hold in Google Vault.

Goal: delete the user account and migrate their data to GCS, replacing Google's expensive Archived User licenses with CloudM's lower-cost Archive and storage model while maintaining full compliance and retention.

For Vault-enabled organisations with users who don't require long-term legal hold in Google Workspace, this workflow trades Google's expensive Archived User license model for CloudM's more cost-efficient Archive infrastructure. The user is locked out with a full security sequence, then all data - including Vault archives - is migrated to GCS for compliance and retention. The account is then suspended, licenses unassigned, and the user deleted, eliminating the recurring Google Archived User license cost while maintaining full data preservation and auditability.

  1. Preemptively Suspend User
  2. Change Password
  3. Revoke 2-Step Verification
  4. Remove Recovery Methods
  5. Revoke Application Specific Passwords
  6. Revoke OAuth Tokens
  7. Revoke Existing Delegate Access
  8. Set Out of Office Message
  9. Remove Email Forwarding Settings
  10. Hide User
  11. Archive
  12. Archive Vault
  13. Purge Backup
  14. Transfer Ownership of Documents
  15. Migrate Calendar Events
  16. Migrate Emails
  17. Suspend User
  18. Unassign Licenses
  19. Delete User
Was this article helpful?
0 out of 0 found this helpful