Skip to content

AI uses for records

Former employees' mailboxes: what to keep, archive or delete

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

Former employee mailbox retention should follow three checks in order: is the mailbox under a legal hold, what does your retention schedule require, and does it hold business threads someone still needs. Held mailboxes are preserved unchanged, business-critical ones are archived with access controls, and the rest are deleted on schedule rather than kept by default.

Key takeaways

  • A legal hold overrides every other rule: preserve the mailbox unchanged and involve counsel.
  • Converting a mailbox to shared access is a convenience for the team, not a retention method.
  • Archive mailboxes that hold customer, vendor or project threads the business still relies on, and record who may open them.
  • Deleting on schedule reduces cost and exposure, but only after holds and retention requirements are cleared.
  • Business-purpose threads in retained mailboxes may have licensing value, subject to rights review and removal of personal content.

What should happen to a departed employee's email?#

A departed employee's email should get a deliberate decision, made in a set order, rather than lingering on a paid license or disappearing when the account is removed. The order matters: legal holds first, retention requirements second, business need third, and deletion only when all three are cleared.

In many companies nobody owns that decision. HR closes the employee record, IT disables the sign-in, and the mailbox sits in a default state that may remove it after a platform grace period or keep it indefinitely on a paid seat. Both outcomes can be wrong: one destroys records you may need, the other keeps sensitive content with no purpose and no owner.

Microsoft 365 and Google Workspace both offer ways to keep mail after someone leaves, such as shared or delegated access, holds, retention policies and archive exports. The mechanics that most often catch IT teams out are summarized in the platform table below; vendors change options, license rules and limits over time, so confirm current behavior in your admin documentation before setting policy.

Keep, archive or delete: a decision table#

The keep, archive or delete decision depends on the mailbox's legal status and its role in the business. Use the table as a starting rule set and adapt it to your own retention schedule.

Keep, archive or delete: a decision table
SituationDecisionHow to handle it
Mailbox subject to a legal hold or an expected disputeKeep, unchangedApply a platform hold before any license change; log the hold and its owner
Role-based inbox such as billing, support or dispatchKeep as shared accessConvert to a shared or group mailbox owned by a team lead
Owner of active customer, vendor or project relationshipsArchiveGive a successor delegated access for a defined period, then move to a restricted archive
Executive, founder or finance approverArchive in fullPreserve everything; these mailboxes often hold contract approvals and board correspondence
Mail covered by a regulatory or contractual retention requirementArchive until the period endsTag the requirement and end date in your records register
Short-tenure role with no open matters and no retention requirementDelete on scheduleConfirm no hold, notify the manager, document the deletion

Legal holds come first because deleting or altering a mailbox after a dispute is reasonably anticipated can create serious problems in litigation. If a departed employee was involved in a customer complaint, an employment claim, a contract disagreement or a regulatory inquiry, preserve the mailbox before anything else happens to the account.

Coordinate scope and duration with counsel. A hold usually needs to reach beyond the mailbox to related chat history, file storage and managed mobile devices. Record who placed the hold, when and on whose instruction, and do not release it until counsel confirms.

Preservation duties depend on the facts and the jurisdiction, so the scope of any hold is counsel's call; IT's job is to apply it completely and to record it.

Shared mailbox, hold, export or third-party archive?#

Converting to a shared mailbox, placing a hold, exporting to an archive file and moving to a third-party archive solve different problems. Mixing them up is how companies end up with mailboxes that are neither searchable nor protected.

Whichever option you choose, write it down. A register entry naming the mailbox, the option used, the owner and the review or deletion date is what lets the next IT director understand decisions made years earlier.

Shared mailbox, hold, export or third-party archive?
OptionGood forWatch out for
Shared or delegated mailboxLetting a successor answer ongoing customer or vendor mailAnyone with access can delete items, so it does not preserve anything
Platform hold or retention policyPreserving content for legal or retention reasonsHolds need an owner and a release decision, or they last forever
Export to an archive fileKeeping a copy before the account is deletedFiles drift onto laptops; store them in controlled storage and log them
Third-party archiveSearchable long-term retention across many leaversExport and deletion terms if you later leave the archive vendor

Platform details to confirm before removing a license#

Platform details decide whether a former employee's mail survives offboarding, and Microsoft, Google and Slack each document behavior that is easy to miss. The points below reflect vendor documentation at the time of writing; plans and editions differ, so check your own tenant before relying on them.

The common thread is timing. Retention policies and holds protect content only if they are in place before the account or mailbox is deleted, and export packages are temporary, so the download and the register entry need a named owner on the day the export runs.

Platform details to confirm before removing a license
PlatformWhat the vendor documentsWhat it means for a leaver
Microsoft 365 retentionDeleting the mailbox of a user covered by an active Teams retention policy turns it into an inactive mailbox that keeps the Teams dataApply retention or a hold before deleting the account; without one, the data may not survive
Microsoft Teams filesFiles shared in Teams chats are stored in the sharer's OneDrive; channel files sit in the team's SharePoint siteDeleting a leaver's OneDrive can remove files colleagues still open from old chats
Microsoft Purview eDiscoveryExports search results as .pst or .msg files; export packages expire 14 days after creationDownload, store and log the export within two weeks
Google VaultExports Gmail as PST or mbox; export files are deleted 15 days after the export starts; users need Manage Matters, Manage Searches and Manage Exports privilegesGive Vault privileges to a named records owner and download promptly
Google Workspace Data ExportDoes not export deleted data unless Vault retention rules or holds kept itSet Vault retention as standing policy, not during offboarding
Slack legal holdsOn plans with legal holds, messages and files are saved regardless of retention settings, even if members edit or delete themA mailbox hold does not cover chat; place a matching hold where your plan allows

An offboarding checklist for mailboxes#

An offboarding checklist for mailboxes turns a one-off judgment into a routine step that HR and IT complete together when someone leaves.

Avoid open-ended forwarding of a former employee's address into a manager's own inbox. Forwarding mixes records, makes later retrieval harder, and keeps a channel alive that customers may use for sensitive matters long after the person has gone.

  • Confirm with HR and counsel whether any hold or dispute applies.
  • Classify the mailbox: individual, role-based, executive or relationship owner.
  • Set an automatic reply that names a current contact, with an end date.
  • Grant delegated access to the manager or successor, with a review date.
  • Apply the hold, retention label or archive that the decision table calls for.
  • Record the mailbox, decision, owner and review or deletion date in your records register.
  • Remove the license only after content is preserved where required.
  • Delete on schedule, and log the deletion.

Who may open a former employee's mailbox?#

Only people with a documented business reason should open a former employee's mailbox, because work accounts mix business threads with mail that has nothing to do with the job. Anything touching health, benefits, family matters or a dispute with the company is sensitive even when it sits in a company system.

For California employees, the CCPA's temporary exemptions for employee and business-to-business personal information expired on January 1, 2023, so a covered business's records about former staff can fall within the law. Other state privacy and employment laws may apply depending on where the person worked, and counsel decides which ones do.

IT can make the policy enforceable. Grant access through a ticket that names the requester, the business reason and an end date; prefer exporting specific threads to a successor over full-mailbox access; and keep the access log next to the records register entry for that mailbox.

Illustrative: an engineering firm handles a retiring principal's mailbox#

Illustrative: a fictional civil engineering firm on Microsoft 365 has a founding principal retiring after a long career. Her mailbox holds client negotiations, RFI correspondence with contractors, internal design review threads and some personal mail.

IT confirms with counsel that one project is in dispute, so threads for that project go under hold. The rest of the mailbox is archived with access restricted to the managing principal and the records manager, and a successor receives delegated access for active projects for a defined period.

The firm logs the archive in its data inventory with date range, project list and record types. Months later, when leadership wants to know whether its project correspondence could support an AI licensing conversation, it answers from that metadata without opening a single email.

Why business-purpose threads may have licensing value#

Business-purpose threads in retained mailboxes may have licensing value because they record how work was negotiated, coordinated and resolved: quotes and counteroffers, vendor exception threads, project coordination with clients, and escalations with their eventual answer. Developers building email and workflow agents need examples of that kind of real correspondence.

What makes such an archive usable is clear rights and careful preparation, not the number of messages in it. Licensing would require reviewing customer contracts and employee notices, removing personal and confidential details, and excluding privileged and HR material. A possible licensing use is not a reason to keep mail your retention policy says to delete, but it is a reason to note which archives exist before you delete them.

SourceX starts from metadata only: which mailboxes are archived, their date ranges and the record types they contain. Nothing is opened or shared during the fit check. If the company later proceeds, the SourceX five-step transaction handles employee and customer content during Rights and Preparation, well before the company is asked to approve a package.

Frequently asked questions

How long should we keep a former employee's mailbox?

There is no single answer. The period depends on your retention schedule, contractual commitments, any industry rules that apply and whether a hold exists. Set periods by mailbox type rather than by person, write them into policy, and have counsel confirm them for your industry and the states where you operate.

Does removing a user's license delete their mailbox?

On many platforms, removing the license or deleting the account starts a countdown after which the mailbox is permanently removed, unless a hold or retention policy is in place. Behavior differs by platform and changes over time, so check your vendor's current documentation before removing licenses in bulk.

Can the company read a former employee's email?

Companies often may access work email for business purposes, but the rules depend on your policies, employee notices, state law and where the employee worked. Limit access to people with a business need, log it, and involve HR and counsel for anything beyond routine business continuity.

Should founders' and executives' mailboxes be kept longer?

Usually yes. Executive mailboxes tend to contain contract approvals, financing discussions and board communications that matter in disputes, audits and future transactions. Archive them in full with restricted access, and treat their deletion as a decision for leadership and counsel rather than routine IT cleanup.

What about the chat history and files the employee left behind?

Apply the same decision order. Chat history, personal drive folders and files shared from the departed account may be removed when the account is deleted, so check holds and transfer ownership of business files to a successor before deleting the user.

Sources

  • Microsoft states that deleting the mailbox of a user covered by an active Teams retention policy converts it into an inactive mailbox that keeps the Teams data, and that files shared in Teams chats are stored in the sharer's OneDrive while channel files are stored in the team's SharePoint site. Source
  • Microsoft Purview eDiscovery can export search results as .pst or .msg files, and search exports expire 14 days after creation. Source
  • Google Vault exports Gmail, Groups and Chat messages as PST or mbox files. Source
  • Google Vault export files are available for 15 days after the export starts and are then deleted; exporting requires the Manage Matters, Manage Searches and Manage Exports privileges. Source
  • Google says the Workspace Data Export tool does not export deleted data unless it was retained or held by Google Vault policies. Source
  • Slack states that when a legal hold is in place, messages and files sent by all members in a conversation are saved regardless of retention settings, even if members edit or delete content. Source
  • The CCPA employee and business-to-business personal information exemptions expired on January 1, 2023. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify