How to Offboard a Contractor in Google Workspace

Ulises Paiz

Ulises Paiz is the owner and sole engineer at Ghosxt, a Salinas, CA managed IT and cybersecurity provider. He holds an M.S. in Cybersecurity and Information Assurance (WGU, 2026) and nine industry certifications including CompTIA SecurityX, CySA+, and Microsoft AZ-104, with prior DoD and federal contractor infrastructure experience. More about Ulises →

Contractors do not offboard the same way employees do, and Google Workspace does not treat them the same way either. A contractor rarely has one tidy account you can disable and walk away from. They often carry shared drive membership from one project, delegate access to a shared inbox from another, a personal phone or Mac enrolled for basic access, and an OAuth connection to a script nobody remembers approving. Remote and overseas contractors add another layer: they typically work from personal devices, on their own schedule, and outside the HR process that normally triggers an offboarding ticket.

For the wider picture across every platform, see our employee offboarding IT security checklist. This post is narrower: exactly what to do inside the Google Workspace Admin console, in order, when a contractor's engagement ends, including the parts of the process that only apply to non-employees and to people working outside your building or your country.

Before the last day

The best contractor offboarding starts before the engagement ends. Waiting until the last day to figure out what a contractor can touch means reconstructing their access footprint from memory, under time pressure, after they have already logged in for the last time.

Inventory what they can actually access. Pull up the contractor's account in the Admin console and treat it as a discovery exercise, not a formality. Check their organizational unit and any groups they belong to, since group membership often carries access to shared drives, mailing lists, and third-party tools that are easy to forget once the original project wraps up.

Shared drive membership. Shared drives are the most common blind spot with contractors, because membership is granted at the drive level and persists independently of the contractor's own account. A contractor given content-manager access to a shared drive for one engagement keeps that access until someone removes them from the drive's membership list, whether or not their overall account is later suspended or deleted. Check every shared drive the contractor was added to, not just the one tied to their current project.

OAuth and third-party app grants. Contractors who write code, run marketing automation, or manage a CRM often connect their Google identity to third-party tools, scripts, or Marketplace apps. Google's guide to controlling which third-party and internal apps access Google Workspace data shows where to review what has been authorized, both organization-wide and on the contractor's own account. Flag anything tied to their identity for removal on their last day.

Forwarding rules. If a contractor had a company inbox, or access to a shared one, check their Gmail forwarding settings before they leave. A forwarding rule that quietly sends copies of incoming mail to a personal address is easy to miss on the Admin console's basic user list, so remove it as its own step rather than assuming suspending the account clears it.

Delegated mailboxes. Mailbox delegation is separate from the contractor's own account and does not disappear automatically. If a contractor was made a delegate on a shared support inbox or a scheduling calendar, that delegation needs to be pulled explicitly, by checking the mailbox itself, not just the contractor's account settings.

On the last day

This is the part that has to happen the day the engagement ends, not the day someone remembers to do it.

Suspend before you delete. Use the Admin console to suspend the account first. Suspension blocks sign-in immediately while preserving the contractor's mail and files, which matters if you still need to review their work or transfer file ownership. Deleting the account starts a limited recovery window and then removes the data for good, so save it for after the rest of this checklist. Google Workspace also offers an option to archive a former user's account at a lower cost than a full license.

Sign the user out of every active session and reset their sign-in cookies. Google's guide to maintaining data security after an employee leaves lists both as deliberate cleanup steps once someone is gone, alongside changing the password and revoking OAuth tokens. Use the Admin console action to sign a user out of a managed Google Account, which closes active sessions immediately.

Reset 2-Step Verification, backup codes, and security keys. A contractor's 2SV enrollment, including backup codes and registered security keys, was set up on hardware and phone numbers that belong to them, not you. Clear their 2SV enrollment in security settings so a personal device or number they keep afterward cannot satisfy a second factor while you finish the rest of this list.

Revoke app passwords and OAuth tokens. Contractors doing technical or integration work often generate application-specific passwords or API tokens tied to their own Google account to connect a script or piece of infrastructure. These credentials work independently of normal sign-in, so treat revoking them as a deliberate cleanup step, the same way Google recommends changing the password and reviewing authorized access as part of offboarding. Revoke them individually, alongside anything flagged in the third-party app review.

Wipe or remove them from managed mobile devices and Macs. Many remote and overseas contractors only touch your systems from a personal phone or Mac enrolled for basic access rather than a company-issued device. For a personal device, wipe corporate data from the device rather than the whole device, removing your mail, files, and profiles without touching their personal content. For company-owned hardware being returned, a full wipe is appropriate. Confirm the device is removed from your managed devices list afterward.

Transfer Drive and Calendar ownership. Before the account is deleted, transfer any Drive files the contractor owns to a new owner, a manager or a shared drive, rather than leaving files stranded under a suspended account. Do the same for any calendar events they organize, so recurring project syncs do not lose their organizer.

Handle external shares. Contractors coordinating with their own subcontractors often share files directly with people outside your organization. Before closing the account, check what was shared externally and with whom, and decide whether each share should be revoked or reassigned to an internal owner.

After

A handful of steps do not have to happen on the last day, but they should happen within the same week.

Reclaim the license. Once the account is suspended or deleted, confirm the freed license is reassigned or reflected on your next bill. On a small team, one or two forgotten contractor licenses is a real, avoidable cost.

Review the audit log. Pull the contractor's activity from the Admin console's audit and investigation log for the final days of the engagement. Look for anything out of pattern: a burst of downloads from a shared drive, a new forwarding rule added shortly before departure, or a new external share created close to the end date. This is the step most small businesses skip, and the one most likely to catch a real problem.

Rotate shared credentials. Any shared login the contractor knew that was not tied to their personal Google identity, a vendor portal password, a service account, a shared social media login, needs to be changed, not just left alone. If you keep shared credentials in an enterprise password vault, rotating the entries a contractor had access to should be a standard part of this same pass rather than a separate task someone has to remember later.

Remove them from vendor portals. Contractors are often added directly to systems that have nothing to do with Google Workspace: a client's project management tool, a payment or invoicing platform, or a subcontractor's own systems. Google Workspace offboarding does not touch any of these. Walk your list of outside platforms the contractor touched and remove them from each one individually.

The copy-paste checklist

Copy this into a ticket, a shared doc, or your own offboarding template and check items off as you go.

  • Inventory the contractor's organizational unit, group memberships, and shared drive access
  • Review OAuth and Marketplace app grants tied to their account
  • Check Gmail forwarding rules on any inbox they used
  • Confirm and remove any mailbox or calendar delegation
  • Suspend the account (do not delete yet)
  • Sign the user out of all active sessions
  • Clear 2-Step Verification enrollment, backup codes, and security keys
  • Revoke application-specific passwords and OAuth tokens
  • Wipe corporate data from personal devices, or fully wipe company-owned hardware
  • Remove the device from your managed devices list
  • Transfer ownership of Drive files and Calendar events to a manager or shared drive
  • Review and resolve external file shares
  • Delete the account once the above is confirmed, or archive it if you need to retain the mailbox
  • Confirm the license was reclaimed or reassigned
  • Review the audit log for the final weeks of the engagement
  • Rotate any shared credentials the contractor knew
  • Remove the contractor from vendor and client portals outside Google Workspace

Frequently asked questions

Is offboarding a contractor different from offboarding an employee in Google Workspace?

Yes, in practice. A contractor's access is usually scattered across shared drive membership, mailbox delegation, and third-party app connections rather than one HR-triggered account, and it is rarely tied to a payroll system that flags the end date. That date is also easier to miss, since a contract or project milestone sets it instead of a termination date already on HR's calendar.

Should I suspend or delete a contractor's Google Workspace account?

Suspend first. Suspension blocks sign-in immediately while keeping the contractor's mail and files intact, giving you time to transfer file ownership and confirm nothing was missed. Delete the account only after that review is done, since deletion starts a limited recovery window and then removes the data permanently.

What should I do about a contractor who used their own personal phone or Mac?

If the device was enrolled in Google endpoint management for basic access, wipe your organization's corporate data from it rather than the whole device, removing your mail, files, and profiles without touching personal content. Then remove the device from your managed devices list. Only wipe an entire device if your organization owns the hardware.

What is the biggest access risk with remote or overseas contractors specifically?

Access that lives outside the systems you normally check: OAuth connections to scripts, application-specific passwords used for API access, forwarding rules on a shared inbox, and logins to vendor or client portals that have nothing to do with Google Workspace. Time zone and distance make these easier to overlook, not harder to create.

What if the contractor still needs access to finish a handoff or final invoice?

Set an explicit end date for that access instead of leaving the account active indefinitely, and scope what they can reach during that window to only what the handoff requires. An account left active because "they might still need something" is exactly the kind still active eight months later.

Contractors on Google Workspace and nobody watching the access list?

Ghosxt sets up Google Workspace as an identity provider with phishing-resistant MFA and manages contractor accounts alongside your full-time team, using an enterprise password vault for shared logins. You talk directly to the owner. See current pricing, our managed IT for remote, Mac-first teams, or IT support for nonprofits on Google Workspace.

Book your free assessment

Prefer to talk first? Email sales@ghosxt.com or call (831) 204-0501.

Book free assessment Call (831) 204-0501