AI data market
After layoffs: what to do with departed employees' email and Slack
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
After layoffs, departed employees' email and Slack should be preserved first, access-restricted second and documented third. Stop any automatic deletion, check for legal holds, limit reading to named roles, and record the policies that cover each account. Only then decide what to keep or delete, using your retention schedule rather than the cost of unused licenses.
Key takeaways
- Preservation comes first: pause deletion scripts, license clean-up and retention rules that could erase departed accounts.
- Preserved accounts should be readable only by named roles, with every access logged.
- Record the policies, agreements and notices that cover each account while the people who know them are still around.
- Shared customer channels and personal content need separate handling from ordinary business threads.
- Keep-or-delete decisions should follow your retention schedule and any legal hold, not the cost of an idle license.
What should happen first to departed employees' accounts?#
The first step for departed employees' email and Slack is to stop anything that could delete them automatically. In many companies offboarding runs on autopilot: an identity provider deprovisions the user, a license clean-up script removes the mailbox, and retention policies quietly purge what is left.
After a layoff, that automation can erase years of customer threads, approvals and project discussions before anyone decides whether they matter. Ask IT to list every automated step that touches departed accounts in Google Workspace or Microsoft 365, Slack, the identity provider and backup tools, and pause the ones that delete.
Then check for legal holds. A reduction in force can lead to claims or disputes, and once litigation is reasonably anticipated, relevant records generally must be preserved. Counsel decides whether a hold applies and which accounts it covers. A short first-week list keeps the work in order:
- List every departed account with role, manager, departure date and the systems each person used.
- Pause license removal, deletion scripts and deprovisioning rules that delete data rather than block sign-in.
- Block sign-in and reset credentials, so preserved accounts cannot be used.
- Record counsel's hold decision and the accounts it covers.
- Note the shared drives, channels, mailboxes and repositories each person owned.
Preserve: a system-by-system triage#
Preservation options differ by system, and the right choice depends on your plan, your retention settings and the vendor's current documentation. The table lists common patterns to check, not exact product behavior, so confirm each one before acting.
| System | Common risk after layoffs | What to check |
|---|---|---|
| Google Workspace | Deleting a user can remove their mail and Drive files | Transfer file ownership first, and consider suspending or archiving instead of deleting |
| Microsoft 365 | Removing a license can start mailbox deletion | Whether a hold, inactive mailbox or shared mailbox conversion fits your plan |
| Slack | Retention settings can purge messages and files | Workspace retention rules, export options on your plan, and who owns shared channels |
| Identity provider | Deprovisioning cascades to connected apps | Which apps delete data on deprovisioning and which only block sign-in |
| Laptops and phones | Devices are wiped and reissued | Whether local or synced folders hold records stored nowhere else |
| Personal accounts | Work happened outside company systems | Shared documents or repositories owned by personal accounts |
Restrict: who may read a departed employee's account?#
A departed employee's account should be readable only by people with a defined business reason, and every access should be logged. Former managers often ask for full mailbox access to pick up customer threads; a narrower option is to delegate a specific folder or forward specific threads.
Work accounts hold personal content: medical appointments, family messages, benefits questions and sometimes complaints about the company. Browsing that content creates privacy and employment risk. Employment and privacy laws may apply; for example, the CCPA can cover California employees' personal information at businesses within its scope. Which laws apply is assessed with counsel.
- Name the roles allowed to open preserved accounts, such as IT security, HR and legal.
- Grant access per request with a stated purpose, not as standing permission.
- Prefer delegating a folder or a customer thread over opening the whole mailbox.
- Log every access and review the log whenever an account's status changes.
- Do not auto-forward a departed employee's mail to any personal address, including the former employee's own.
Record rights: what governs these records?#
Recording rights means writing down which policies, agreements and notices covered each departed employee's records, while the people who know are still employed. That note decides what the company may later do with the accounts, from internal review to licensing.
Shared Slack Connect channels and email threads with customers deserve their own entry. The messages your former employees exchanged with customers sit in your systems, but customer contracts may restrict how that content is used.
| Document | What to note | Why it matters later |
|---|---|---|
| Acceptable use policy and handbook | Whether work accounts are company property and how monitoring is described | Shapes expectations about review and use |
| Confidentiality and invention agreements | Who owns work product and confidential information | Supports company ownership of business content |
| Separation agreements | Return-of-property, confidentiality and non-disparagement terms | May contain terms that touch the records |
| Employee privacy notices | Stated purposes for processing employee data | New uses may need to fit within those purposes |
| Customer and vendor contracts | Confidentiality terms covering shared threads | Customer content may be restricted even in your systems |
Keep, archive or delete?#
Keep, archive or delete decisions belong after preservation, access rules and rights notes are in place, and they should follow your retention schedule. The cost of a license on an idle account is a poor basis for a permanent decision.
A simple sort works for most companies. Accounts under legal hold stay exactly as they are. Accounts holding active customer, project or approval history are archived with restricted access. Accounts with nothing beyond what colleagues already hold are deleted on schedule, and the deletion is recorded.
Departing staff in estimating, engineering, customer support or account management often carry the most context. Their threads show how quotes were negotiated, why exceptions were granted and how problems were solved, which helps their successors and may later interest AI developers.
Illustrative: a manufacturer's customer service reduction#
Illustrative: a fictional industrial equipment manufacturer reduces its customer service and applications engineering teams. Its offboarding runbook removes Microsoft 365 licenses at month end, and its Slack workspace deletes messages after a set retention period.
The COO pauses the license removal. Counsel finds no general hold is needed but asks that accounts tied to an open warranty dispute be preserved unchanged. IT applies a retention hold to the departed engineers' mailboxes so they survive license removal, exports the applications engineering channels, and limits access to the quality manager and HR, with each request logged.
HR records the handbook version, confidentiality agreements and employee privacy notice in force for each person, and threads covered by customer NDAs are tagged. When leadership later asks whether its service and warranty history could be licensed, the preserved threads, access log and rights notes are already in order.
Where licensing fits, and how SourceX approaches it#
Licensing is a later and separate decision, and departed employees' records reach it only through preparation. Personal content is removed, names and contact details are replaced, and customer-restricted material is excluded. Automated tools help but are not complete: the documentation for Presidio, an open-source de-identification tool, warns there is no guarantee it will find all sensitive information and says additional protections should be used.
At SourceX, departed employees' records enter the SourceX five-step transaction (Supply, Rights, Preparation, Approval and Delivery) only after preservation and rights notes are complete. Nothing leaves the company during the initial assessment, which works from metadata, and each step needs the company's sign-off. A SourceX Evidence Packet then documents where the records came from, the licensing rights, permitted use, the privacy record and who authorized release. This is general information, not legal advice, so review your situation with counsel.
Frequently asked questions
Can former employees ask for their email or Slack messages to be deleted?
Some may have privacy rights depending on where they live and which laws apply, and those rights often have exceptions for business records and legal obligations. Route requests to whoever handles privacy requests, and let counsel confirm what applies. Records under a legal hold should not be deleted in response to any request.
Should we keep departed employees' accounts active so nothing is lost?
Keeping accounts active is the weakest form of preservation. An active account can still be signed into, keeps receiving mail and stays subject to the same retention rules as everyone else. Suspension, holds, archive licenses and exports preserve content while blocking use; choose based on your plan and the vendor's documentation.
Can a former manager keep reading a departed employee's inbox?
Standing access is risky. A manager usually needs specific threads, such as open customer issues, rather than the whole mailbox. Delegate those threads or a shared folder, set an end date and log access. Personal content in the mailbox is the main reason to keep that access narrow.
What about work stored in personal accounts or devices?
Work sometimes lives in personal email, personal cloud drives or personal code repositories. Ask departed employees, through HR, to return company files, and document what came back. Reviewing personal devices or accounts directly raises separate legal issues, so involve counsel before attempting it.
Do layoffs change who owns the records?
Generally no. Work records created in company systems usually remain company records after employees leave, subject to contracts, policies and law. What layoffs change is practical: fewer people remember what the records contain, and automated clean-up can destroy them. Recording rights and context early addresses both problems.
Sources
- Presidio's documentation warns that because it uses automated detection mechanisms, there is no guarantee it will find all sensitive information, and additional systems and protections should be employed. Source
Related resources
- InsightOwner-furnished vs firm-produced documents: what can an AEC firm license?
- QuestionCan SaaS data be licensed?
- QuestionDo AI labs buy legal documents?
- InsightSelling contracts and legal documents to AI companies: what to know
- InsightHow do I de-identify contracts and legal documents for AI training?
- IndustryLegal data
See if your company qualifies
A short company assessment. No data uploads are needed.