Skip to content

Offboarding a teammate from shared email safely

A runbook for removing a departing teammate from shared email: access, connected apps and AI tokens, owned threads, forwarding rules and their old address.

Koltrix Team4 min read
Gold padlock sitting on a keyboard
Photo by Towfiqu barbhuiya on Unsplash
On this page(7 sections)
  1. Before the last day (friendly departures)
  2. Hand over open threads
  3. Capture knowledge
  4. Decide what happens to their address
  5. On the last day (or immediately, if unplanned)
  6. 1. Remove mailbox access
  7. 2. Revoke connected apps and AI assistant access
  8. 3. Remove forwarding and rules they created
  9. 4. Security housekeeping
  10. After the last day
  11. Unplanned departures
  12. Keep history with the team
  13. A one-page checklist
  14. Key takeaways

When someone leaves the team, their laptop gets returned and their chat account gets deactivated. Their email access is often the thing that lingers: a forwarding rule nobody noticed, a connected app still holding a token, a set of customer threads that just stop.

This runbook covers offboarding from shared email specifically, in the order that matters. It applies whether the departure is friendly or not, though the timing changes.

Before the last day (friendly departures)

If you have notice, use it. A smooth handover protects customers far more than any access change.

Hand over open threads

  • Ask the departing person to list threads they own that are still open: customer, link, status, next step.
  • Reassign each one to a named teammate, and have the new owner confirm.
  • For important customers, have the departing person introduce the new owner in the thread: "I'm moving on at the end of the month; Priya will look after you from here."

Capture knowledge

  • Ask them to update any snippets, help articles, or playbook sections they maintain.
  • Ask what they know that isn't written down: difficult accounts, informal promises, recurring issues.

Decide what happens to their address

Their personal work address (for example jordan@) will keep receiving mail from customers and vendors after they leave. Choose one approach in advance:

Option How it works Good for
Keep it as a mailbox, reviewed by a teammate Account stays, a teammate checks it Roles with lots of external contacts, for a transition period
Turn it into an alias to a shared mailbox Mail goes to support@ or the manager Most departures
Auto-reply, then close Senders are told where to write instead Low external contact

An auto-reply is useful in any option:

Thanks for your email. Jordan is no longer with [Company].
For support, please write to support@[domain]. For anything else,
contact [name] at [address].

Keep the transition period limited, typically a few months, and put a reminder on the calendar to review it.

On the last day (or immediately, if unplanned)

Do these in order. For an unplanned or difficult departure, do them before or at the moment the person is told.

1. Remove mailbox access

  • Remove the person from every shared mailbox they could access. With per-mailbox permissions, this is a list to work through, so check each mailbox, not just the obvious ones.
  • Suspend or remove their account in your email system, so they can't sign in at all.
  • Sign them out of active sessions on all devices, if your system supports it.

2. Revoke connected apps and AI assistant access

This is the step most teams miss. If the person connected third-party apps or an AI assistant to their mailbox using OAuth, those connections hold tokens that may keep working until they are revoked or the account is removed.

  • List connected apps for their account and revoke them.
  • Check workspace-level integrations they set up (helpdesk connectors, automation tools, CRM syncs) and transfer or revoke them.
  • Confirm that AI assistant connections (for example, an assistant connected through MCP) stop working when the member is removed. Well-designed systems cut access immediately; verify yours does.

3. Remove forwarding and rules they created

  • Check for forwarding rules on their account and on any shared mailbox, especially anything forwarding to an external address.
  • Review filters and auto-label rules they created. Keep the useful ones (reassign ownership in your notes), delete the ones that only made sense for them.
  • Check delegated access they granted to others, or that others granted to them.

4. Security housekeeping

  • Rotate any shared credentials they knew, such as an API key used by the team or a password for a shared tool. Shared passwords for email accounts shouldn't exist; if they do, this is the moment to remove them.
  • Invalidate their 2FA recovery codes and devices along with the account.
  • Review the audit log for unusual recent activity, particularly before an unplanned departure: bulk exports, new forwarding rules, unusual connected apps.

After the last day

  • Review their former address on the schedule you chose: what's arriving, who needs to be told about the change.
  • Update contact info wherever their address appears: website, docs, invoices, vendor accounts, domain or billing contacts for services.
  • Check vendor and service accounts registered with their email. Password resets for important services may go to a mailbox nobody reads. Move them to a role address like billing@ or admin@.
  • Close the transition after the agreed period: remove the alias or mailbox, keep the history if your retention policy says so.

Unplanned departures

Everything above assumes a friendly exit with notice. When someone leaves suddenly, or the departure is contentious, the order changes. Do the last-day steps first, in one sitting, before the conversation with the person if possible: remove mailbox access, revoke connected apps, end active sessions, and check for forwarding rules. Then handle open threads without their help. Search the shared mailboxes for threads where they sent the last reply and the customer is waiting, and send a short note from the team address: "I'm picking this up from my colleague, here's where things stand." Customers rarely need to know why; they need to know someone has it.

Keep history with the team

One reason to work from shared mailboxes rather than personal ones is that customer history stays with the team when people leave. If the departing person handled customers from their personal address, export or transfer those conversations before the account is removed, according to your retention policy and any applicable obligations.

A one-page checklist

BEFORE (if notice)
[ ] Open threads listed, reassigned, customers introduced
[ ] Knowledge captured (snippets, playbook, informal promises)
[ ] Decision made for their personal address + auto-reply text

LAST DAY / IMMEDIATELY
[ ] Removed from every shared mailbox
[ ] Account suspended, sessions signed out
[ ] Connected apps and AI assistant access revoked
[ ] Forwarding rules and personal filters removed or reassigned
[ ] Shared credentials rotated; 2FA devices and recovery codes invalidated
[ ] Audit log reviewed

AFTER
[ ] Former address reviewed on schedule
[ ] Contact details updated on site, docs, vendor accounts
[ ] Service accounts moved to role addresses
[ ] Transition closed after agreed period

Key takeaways

  • Hand over open threads before access changes, so customers aren't left mid-conversation.
  • Remove access from every shared mailbox and suspend the account on the last day, or immediately for unplanned departures.
  • Revoke connected apps and AI tokens; they're the most commonly forgotten access path.
  • Delete forwarding rules, especially to external addresses.
  • Decide what happens to the person's address and review it on a schedule.

Start with Koltrix

Your domain, one inbox, and an API that sends.

A team inbox where AI sorts and drafts (nothing is sent without your click), plus the transactional API and SMTP relay your product sends with. 7 days free, no card.

SharePost on XLinkedIn