AI offboarding checklist: removing a leaver's AI access
AI offboarding means checking the leaver’s actual accounts, removing access through the right provider process, handing over shared work and reviewing keys they could use. Check paid seats separately: removing access does not establish that billing has stopped.
Before their last day
- Start with your AI tool register, then confirm the leaver’s accounts against provider membership and access records. A tool owner field does not establish every person who used it.
- Find shared work they own, such as team projects, custom assistants, prompt libraries and automations. Identify a new owner and any running workflow that depends on it.
- List keys they could use and the systems that depend on those keys. Record key names or locations, not secret values, in the checklist.
On their last day
- Remove their access using the process for the actual workspace and grant. Confirm its effective time; cancelling a paid seat is not always immediate access removal.
- Remove admin roles they held in any AI tool, following your company’s authorised leaver process.
- Hand over shared work through the provider’s supported process. Confirm the replacement owner can use the projects or automations.
- Review and replace credentials they could use. Check the provider’s key status and update dependent systems when rotating a needed key; retire keys that are no longer needed. Do not assume member removal has revoked every credential.
- Make a separate seat decision: reassign available capacity or schedule a reduction where appropriate. Record the effective billing date.
After they leave
- Verify the provider membership and access outcomes, and confirm shared workflows have the intended owner.
- Check retired credentials are disabled. Where activity reports exist, review their period and delay; silence alone does not prove revocation.
- Check the invoice covering the scheduled seat-change date. If you reassigned a seat or the change is due at annual renewal, an unchanged next monthly bill may be expected.
- Record the checks, responsible person and completion date, and set a review for any outstanding billing change.
Removing access and stopping the seat bill
ChatGPT Business requires an Owner to reduce paid seats separately from removing a member. Claude Team allocation reductions apply at renewal. GitHub Copilot seats remain billed through the current cycle.
For an organization-assigned GitHub Copilot seat, cancelling the seat may leave access until cycle end. GitHub documents immediate loss of access when the user is removed or suspended from the granting organization or enterprise; enterprise-team grants have their own removal path. Confirm which grant applies before treating offboarding as complete.
Use the plan-specific leaver seat guide for the billing follow-up and the unused-seat review for capacity you may keep or reassign.
Company sign-in helps, but it is not the whole job
Disabling a work identity can prevent sign-in through that identity, but it does not by itself establish the status of existing provider sessions, other login methods, paid capacity, shared work or API keys. Verify the outcome in each tool’s actual access process.
Personal accounts
If someone used a personal AI account for work, you cannot remove it from the company side. Your AI policy should say which accounts are allowed for company work, and your leaver process can ask people to remove company material from any personal accounts.
Billing and access sources checked 7 October 2026
The linked official OpenAI, Claude and GitHub pages were rechecked for the specific seat and access distinctions above. Provider instructions and your agreement determine the actual timing. This is a working checklist, not proof that any company’s access or billing has changed.
Common questions
Does switching off someone's work account remove their AI access?
It does not establish that every AI account, active session or key is disabled. Check the provider’s membership and access outcome, shared work and paid capacity separately.
What happens to API keys when someone leaves?
Check the actual credential status rather than assuming member removal revoked it. Retire unneeded keys and rotate credentials the leaver could use, updating any dependent systems as part of the change.