Skip to main content

Decommission administrative and privileged access

When a person leaves the organization, changes responsibilities, or no longer requires access:

  1. Identify integrations, credentials, and responsibilities owned by the user.

  2. Transfer required responsibilities to an authorized user.

  3. Disable sign-in when access must end immediately.

  4. Revoke API keys and client authentication certificates.

  5. Remove unnecessary Account Manager and product roles.

  6. Disable or delete the standard user or service user according to your agency’s policy.

  7. Review the platform audit logs to confirm the changes.

Before deleting a user with Account admin, User manager roles, or a custom role containing Manage accounts, or Manage users permission, verify that another authorized administrator can perform the required account-management tasks.