Offboarding must remove the user's account from your organization. In the current product, clearing Active is not a sign-in suspension for an identity that has already been provisioned: it prevents an unprovisioned account from being sent for identity provisioning and affects some active-user selectors, but authenticated tenant resolution does not filter an existing account on this field. Use the Users-list Delete action for access removal, after preserving the person's work and reclaiming their license seats.
Deleting here is tenant-scoped and soft-deletes the xMatix user row. It does not erase business records the person owned or created, and it does not remove a shared sign-in identity that may also be used with another organization.
Prerequisites
- The user-administration capability (
setup.security.users.manage) on one of your own security profiles. - A reviewed inventory of what the person is responsible for: live records they own, approvals that route to them, teams where they act as an approver, company access, and assigned license seats.
- A replacement owner or approver for every item that must continue after the person leaves.
Procedure
Step 1 — Verify the exact account
Open Setup → Access Control → Users and search by the person's verified corporate email. Confirm the display name, email, audience and Sign-in status before changing anything. Never edit or delete System Process, System Agent or System Anonymous: these are built-in service identities, not people, and the UI intentionally hides their Edit and Delete actions.
Step 2 — Re-route live work and approvals
Open work does not move automatically when its owner is removed. Reassign records that still need action, especially leads, opportunities, orders, cases, visits, service work and approval requests. Check the user's delegated approver, role position and approval teams as well: replace a named approver and remove the person from any team that supplies an approval pool. Keep historical records with their original creator or owner when that attribution is required; only move work that still needs an active operator.
Step 3 — Reclaim license seats
Open the user's License Allocations tab and revoke every active product, feature or package seat that should return to the tenant pool. A seat remains counted while its allocation has no revocation timestamp, even if the account's Active field is cleared or the user is later removed. Confirm each row changes to revoked and verify the available-seat count before assigning the seat to a replacement. See Licensing.
Step 4 — Clean up access assignments
Review Profile Assignments, Role Assignments, Team Assignments and multi-company access. Remove assignments your policy requires you to retire, and record any retained assignment history before deleting the account. The account deletion itself stops tenant identity resolution, but it does not use the Active field as a security gate and should not be substituted with a checkbox change.
Step 5 — Remove the tenant account
Return to Setup → Access Control → Users, find the verified row, and select Delete in its Actions column. Read the confirmation carefully and confirm only after the reassignment and seat checks are complete. This operation soft-deletes the user account in this organization and invalidates its cached identity and access snapshots; the external sign-in identity is not deleted.
- 1
Search and verify the exact account; names, email addresses and phone numbers are intentionally hidden in this documentation image.
- 2
Active and Sign-in are separate states; Active alone is not a suspension control for a provisioned identity.
- 3
Use the row Delete action only after reassignment and seat-revocation checks are complete.
- 4
The confirmation is the last non-destructive review point; Cancel leaves the account unchanged.
Step 6 — Verify the outcome
Refresh the Users list and confirm the account no longer appears. Verify that the replacement owners can open the transferred work, approval queues no longer point to the leaver, and reclaimed seats are available. If you have an authorized test process, confirm that a new request for this organization can no longer resolve the removed account; a still-valid identity-provider session by itself is not proof of tenant access.
Expected result
The user no longer appears in the organization's Users list or resolves as a live tenant account. Required license seats are revoked, active work and approvals have responsible replacements, and historical business records retain their audit attribution.
Common problems
The user can still sign in after Active was cleared. That is the implemented behavior for an already provisioned identity; Active is not the tenant sign-in gate. Complete the offboarding checklist and use the Users-list Delete action.
Seats are still counted against the license. Account-state changes do not revoke seat rows. Revoke the allocations explicitly in Step 3; if a seat ceiling blocks the replacement, reclaim the leaver's seat first.
A System account appears in the list. System Process, System Agent and System Anonymous are platform identities. They cannot sign in as people, and the UI deliberately prevents editing or deleting them.
Common questions
Can I temporarily suspend a provisioned user with Active?
No. Clearing Active alone does not stop an already provisioned account from resolving during sign-in. You can strip profiles, roles, teams, company access and seats to reduce what the user can do, but that is not a reliable sign-in suspension and may still allow an empty workspace. If the requirement is to remove access to this organization, use the deletion procedure above. Recreating access later is a fresh onboarding task, including a new review of assignments and licenses.
What happens to the records the user owns?
Nothing changes automatically. Historical references remain, but live records can be stranded with an owner who no longer resolves as a current user. Reassign actionable work before removal so queues, hierarchy-based visibility and follow-up responsibilities stay usable.
What does Active do for a new account?
An unprovisioned account is sent to identity provisioning only while Active is enabled. This lets an administrator prepare an inactive account without sending its welcome message, then enable it at go-live. After the identity has been provisioned, do not treat the same field as an access-revocation control.
