Skip to content

Wind-downs and transitions

Shutdown data inventory template: every system, owner and export status

By SourceX Editorial · Updated

Short answer

A shutdown data inventory template is a single sheet with one row per system that records who owns it, who holds admin access, what records it contains, when it renews and whether its export is verified. Build it before cancelling anything; a system is not ready to shut off until its export status reads verified.

Key takeaways

  • Use one row per system or archive, not per vendor, so a Microsoft 365 tenant and its SharePoint sites can be tracked separately.
  • Record the admin holder by name and whether the login belongs to the company or to a person.
  • Export status moves from not started to requested, exported and verified; only verified clears a system for cancellation.
  • Give each row a reason to keep, such as tax, claims, legal hold or licensing assessment, before any deletion date is set.
  • The inventory holds only metadata, so advisors can review it without seeing a single customer or employee record.

What a shutdown data inventory is for#

A shutdown data inventory is the wind-down officer's control sheet for every system that holds company records. For each system it answers four questions: what is in it, who can get in, when it goes away, and whether a usable copy exists outside it.

Most closing companies run on more systems than anyone can name from memory. Accounting, payroll, email, file storage, the CRM, a help desk, project tools and line-of-business software each renew on their own cycle, and any one of them can lapse with years of records inside.

Build the inventory before cancelling subscriptions, closing the corporate card or releasing IT staff. The sheet then drives the order of operations, the retention schedule and any assessment of which records could be licensed instead of deleted.

The column set to copy#

The column set below covers ownership, access, content, timing, export and disposition. Copy the headers into a spreadsheet; each row is one system or one distinct archive, such as an old office server or a retired database.

The column set to copy
ColumnWhat to enterWhy it matters
SystemProduct name and instance, such as QuickBooks Online or the support help deskSeparates tools that share a vendor
Record familiesTickets, invoices, job history, email, drawings, codeShows what would be lost
Date rangeEarliest and latest records still accessibleAccessible history drives both retention and value
Business ownerThe person who used and understands the recordsSomeone must answer questions after staff leave
Admin holderNamed admin and whether the login is company-ownedPersonal logins cause the most lockouts
Billing and renewalPayment method, renewal date and notice termsShows which systems lapse first
Vendor deletion termsWhat the vendor says happens to data after cancellationSets the real deadline
Export methodNative export, API, backup file or vendor requestSome exports depend on the vendor's own processing time
Export statusNot started, requested, exported or verifiedOnly verified clears a system for cancellation
Export locationWhere the copy is stored and who controls itKeeps copies off personal laptops
Personal data flagsCustomer, employee, health, payment or other sensitive fieldsDrives access limits and disposal
Contract limitsCustomer, vendor or license terms on use or returnFlags records that must be returned or carved out
Reason to keepTax, payroll, claims, legal hold, licensing assessment or noneLinks each row to the retention schedule
DispositionKeep until a confirmed date, assess for licensing, or delete after exportRecords the decision and who approved it

How to fill the inventory, in order#

Filling the inventory works best from the money trail inward, because every system someone pays for leaves a billing record. Start with what can be found without anyone's memory, then interview the people who used each tool.

Re-sort the sheet by renewal date once the first pass is complete. The rows at the top are the ones that will disappear first, and they set the order of work for the whole wind-down.

  • Pull card statements, payables history and app marketplace bills to list every paid tool.
  • Add unpaid and legacy systems: old servers, retired databases, shared drives and former employees' devices.
  • Check the identity provider or email admin console for connected apps and single sign-on tiles.
  • Confirm the admin holder for each row and move personal logins to a company account.
  • Fill in renewal dates, deletion terms and export methods from the vendor's documentation and account pages.
  • Assign each row an owner responsible for moving its export status to verified.

Export status values and what verified means#

Export status values should be few and strictly defined, so everyone reads the sheet the same way. A row marked verified means someone opened the exported copy on a different machine, confirmed it covers the full date range, and checked that attachments, comments and linked records came through.

Requested is a separate status because some vendors fulfill full exports on their own schedule, and that wait can collide with a renewal date. Exported but not verified is the most dangerous state: it looks finished, and it is often where missing attachments or truncated history are discovered after the account is gone.

Check what an export actually contains before calling it verified. Gorgias, for example, emails a CSV link that stays active for 14 days, and the file lists fields such as ticket ID, tags, channel, subject, dates, survey score and assignee, so confirm whether full message bodies are included. Zendesk archives closed tickets 120 days after they close, and archived tickets do not appear in views, so an export built from a view can silently miss years of history.

Add a short note to the row whenever an export is partial, such as tickets without attachments or mail without calendar items, so the disposition decision reflects what actually survived.

Illustrative example rows#

Illustrative: the rows below come from a fictional roofing and exterior restoration contractor that is closing after its founder retires without a buyer. The wind-down officer is the company's former controller, working with outside counsel and the company's accountant.

The roofing CRM is the priority. The founder's personal login controls it, and its job and warranty history is both a claims record and the strongest licensing candidate. The officer moves admin rights to a company account, requests a full export with photos, and keeps the subscription for one more billing cycle until the copy is verified. The office server is imaged before the lease ends, because nobody yet knows what it holds.

Illustrative example rows
SystemRecordsAdmin holderExport statusReason to keepDisposition
QuickBooks OnlineInvoices, bills, payroll journalController, company loginVerifiedTax and payrollKeep until the accountant confirms
Roofing CRMLeads, estimates, jobs, warranty claims, photosFounder, personal loginRequestedWarranty claims and licensing assessmentAssess for licensing after export
Microsoft 365Mailboxes, shared estimating inbox, SharePointOutside IT contractorExportedLegal hold on one mailboxKeep the held mailbox; review the rest
Office serverOld estimating files, scanned contractsUnknownNot startedContracts and warrantiesImage the drive, then decide
Payroll providerPay stubs, tax forms, employment eligibility formsOffice managerVerifiedPayroll and employmentKeep with restricted access

Mistakes that make the inventory fail#

The most common mistake is listing vendors instead of systems, which hides separate archives inside one row. A single Google Workspace account can hold mail, shared drives and form responses, each with its own export path and owner.

Other failures are quieter: treating a vendor's cancellation email as the deletion date without reading the terms, letting a departing employee keep the only admin login, and storing verified exports on someone's home computer. Each turns a recoverable situation into a permanent loss.

Finally, never leave the reason-to-keep column blank. A row with no reason tends to be deleted by default, and that is how records that deserved a value assessment disappear along with the ones that should go.

Using the inventory beyond the shutdown#

The inventory feeds three other wind-down documents: the retention and deletion schedule, the instructions to whoever stores the final archive, and any records assessment for licensing. Keep the same row identifiers across all of them so a decision in one can be traced in the others.

If a trustee, assignee or receiver takes over later, a current inventory with verified exports is the first thing they will need. Keep the sheet with the company's books and records, and note the date of the last update at the top.

How SourceX uses a shutdown inventory#

SourceX starts its fit check from the same metadata a shutdown inventory holds: systems, record families, date ranges, export routes and known restrictions. Nothing is shared during the initial assessment, so a wind-down officer can learn whether any rows merit a licensing look before deciding what to delete.

If records proceed through the SourceX five-step transaction, the inventory supports the provenance record in the SourceX Evidence Packet, alongside licensing rights, permitted use, the privacy record and release authorization. The company keeps ownership of anything it licenses.

Frequently asked questions

Should the inventory include paper records?

Yes, as separate rows by location and type, such as job folders in a storage unit or signed contracts in a filing cabinet. Paper often duplicates what sits in a system, and noting that in the row helps decide whether the paper can be shredded once the digital copy is verified.

Who should own the inventory during a wind-down?

One person, usually the wind-down officer, controller or operations lead, owns the sheet and its status values. Individual rows can have different owners, but a single editor prevents conflicting updates and keeps the disposition column tied to approvals from counsel and the accountant.

How detailed should record volumes be?

Rough figures are fine. An approximate count of tickets, jobs or mailboxes, or the size of an export file, is enough for planning and for a first licensing assessment. Exact counts matter later, if a set of records moves into preparation for a license.

What about tools paid for on personal cards?

List them too, and flag the payment method. Tools bought on an employee's card and expensed are easy to miss and often hold team files or customer conversations. Confirm that the account and its records belong to the company, and transfer admin rights before the employee leaves.

Can the inventory be shared with a potential licensee?

A high-level version can be, because it contains system names, record types and date ranges rather than records. Remove internal notes about disputes or legal holds first, and share it only under a confidentiality agreement once a fit check suggests a licensing conversation is worth having.

Sources

  • Gorgias view exports are emailed as a CSV download link active for 14 days, with fields such as ticket ID, tags, initial channel, subject, created and closed dates, survey score and assignee. Source
  • Zendesk archives tickets 120 days after they are closed, and archived tickets do not appear in views. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify