Somebody is leaving and you have their Google Workspace account open in front of you. Do this. Suspend the account on their last day, move the work off it, then pick an ending: delete it, archive it, or leave it suspended. Suspending is reversible, and it locks the person out without touching a single file. Everything else can wait a week.
The ending is the part that costs money, and it is the part people forget. Google’s billing rule is blunt: “Suspended accounts are still charged at the same rate as active accounts on both the Annual billing plan and the Flexible plan”. A suspended account nobody comes back to is a full-price seat, paid every month until somebody decides otherwise. On the Annual plan, deleting the account does not fix that either. More on both below.
The short version, if you are doing this today.
- Suspend the account. It blocks sign-in, keeps the data, and starts signing them out, though Gmail can take up to an hour.
- Transfer the Drive files, the calendars and the mail, in that order, while the account is suspended.
- Revoke the leftovers: app passwords, security keys, recovery phone and email, connected apps.
- Then decide the ending, and do it on purpose rather than by forgetting.
- The thing that goes wrong: deleting first. That is what makes calendars, mail and untransferred files unrecoverable, and Google’s 20-day undo comes with conditions.
Every fact below is Google’s own admin help, and Google dates its own pages. Eleven of the twelve pages quoted here carry the line “Last updated 2026-08-26 UTC” at the foot. The exception is the archiving page, stamped “Last updated 2026-09-09 UTC”. Check each menu path against your own Admin console rather than against this page.
Suspend the account first, on their last day
Suspending is the safe first move because it is the only step here that changes nothing you might want back.
Google’s description of what a suspended account keeps: “Email, documents, calendars, and other data aren’t deleted.” Colleagues keep what was shared with them in Docs, Sheets and Drive, because “Collaborators who have been granted access to shared documents will retain their ability to view, edit, and collaborate on those documents.” Shared Keep notes are the exception on Google’s own list: “Shared Keep notes are not available to collaborators.” What stops is arrival: “New email and calendar invitations are blocked.” And you can put it back whenever you like, since “After suspending a user or guest, you can restore the account at any time.”
Suspending is also the first step of Google’s own file transfer procedure, which is the real reason it goes first. On the page for moving somebody’s Drive files to a new owner, step one reads: “Suspend the current owner’s account. This action prevents them from creating or moving content during the transfer.” If you transfer files while the person can still open Drive, you are copying a moving target.
It quietly does a security job as well. One of the seven items on Google’s security list after somebody leaves is resetting the user’s sign-in cookies, which forces them out of every browser and device. Google’s note on that setting: “If you suspended a user, you don’t need to do this. Suspending a user resets their sign-in cookies.” One click, two jobs, though neither finishes the second you click: the lockdown section below carries the timings. One carve-out sits on the suspension page itself: “If you suspend a user’s account while they’re in a chat in Google Chat, the user can continue to participate until the session is over.”
Two things to know before you click, because both surprise people.
You lose the 2-Step Verification switch. Google states it plainly: “You can’t turn off 2SV for a user if their account is suspended”. 2-Step Verification is the setting that asks for a phone or a key on top of the password. If you were planning to turn it off for this account so you could get into it yourself, do that before you suspend, or better, do not do it at all and move the data properly instead.
Their meetings stay in everybody’s calendar. Suspending does not clear the diary. Google: “If a user is suspended (not deleted), their events remain in Calendar, and only super administrators can modify them.” So the weekly project meeting the leaver organised keeps appearing, and only a super administrator can change it. The calendar section below is how you deal with that.
Suspend, archive or delete: pick the ending before you forget
There are three endings here, not two. The middle one is worth a minute of your time, because it is the only one that keeps the mailbox and gives the licence back.
Archiving is Google’s own answer for keeping the data without paying for the seat. In its page on archiving former employee accounts: “When an employee leaves your company, you can archive their user account to securely retain their data and prevent them from accessing Google Workspace services.” The account cannot sign in, drops out of the address book colleagues search, and cannot receive new mail or invitations. It does not vanish from your own view: “In user directory listings, the user appears with the archived status.” The licence comes back: “When you archive a user account, their active Google Workspace license becomes available to reassign to another user within 24 hours.”
There is a catch on Business editions, and it is a purchase. Archiving is supported on Business Starter, Business Standard and Business Plus. Getting to it is a different question. Google’s requirement: “To archive a user, you need an Archived User subscription or the Flexible Plan for billing”. For Business editions the wording turns cautious, “You might be able to buy an Archived User subscription in your Admin console”, and the console steps end with a warning: “If prompted, click Buy archived user subscription and follow the prompts. If this option isn’t available, you can’t buy an Archived User subscription in your Admin console.” That is not the end of it. The next line on the same page gives the way round: “Instead, contact a Google Sales representative or a Google Cloud partner.” The page says it again higher up, for every edition: “Alternatively, for all editions, you can contact a Google Sales representative or a Google Cloud partner.”
So archiving is either free or a new line on your bill, depending on your plan.
On the Flexible Plan there is a way to check whether you need to buy one. Google’s test sits under a heading that names the condition, “Archive users without a separate subscription”, and that section opens: “If you don’t have an Archived User subscription, you can still archive users if you’re on the Flexible Plan for billing.” Go to Billing, then Subscriptions. Google’s test: “On the Subscriptions page, if the Archived User edition is not listed, then you can archive a user without a separate Archived User subscription.” The option then appears inside the deletion flow rather than as a button of its own, because “you can archive a user when you delete their account”.
On any other plan the test is not yours to run. It belongs to the no-separate-subscription case above, and the Flexible Plan condition that case opens with is why an empty Subscriptions page is not a green light on the Annual Plan. What binds you there is the requirement quoted earlier, from the page’s Before you begin section: an Archived User subscription, or the Flexible Plan for billing. That leaves the subscription, and what decides it is whether the console will sell you one, with the sales and partner route above as the way in if it will not.
One more thing about archived data, because it lands on a different bill. Google: “Data for archived users counts toward your organization’s pooled storage limit.” Archiving five leavers with full mailboxes takes their storage with them into your shared pool, so it is worth knowing what your pooled storage limit actually covers.
| Ending | What it costs | What happens to the data | Use it when |
|---|---|---|---|
| Suspend | Full price, on both plans, for as long as it stays suspended | Nothing is deleted. Colleagues keep access to shared files. New mail and invitations are blocked | The last day, and the two or three weeks after it while you sort out the handover |
| Archive | The Workspace licence frees up within 24 hours. Needs an Archived User subscription, or the Flexible Plan. The stored data counts against your pooled storage | Kept, and searchable where the licence includes Vault. The account cannot sign in and drops out of the address book. A delegate can be assigned when you archive during the deletion flow | You have a reason to keep the mailbox, such as a client-facing role or a records requirement, but not a reason to pay a full seat |
| Delete | Flexible Plan: the monthly rate drops straight away. Annual Plan: the bill does not change until renewal | Anything the user solely owned and you did not transfer is gone. Files in shared drives stay with the organisation. Some data is held for 20 days so you can restore the user, then it is not | The handover is finished and nobody needs the mailbox again |
Google publishes a short list of reasons not to delete somebody, and one of them is the money. Its own “When not to delete a user” section names four: resolving a conflicting account, changing a username, blocking somebody temporarily (“Block a user temporarily from accessing your organization’s Google services”), and this one, quoted whole: “Save the cost of a license. To keep the user’s data and reduce costs, assign an Archived User license to their account, instead.”
Our advice to our own clients is to suspend on the last day and put a date in the calendar three weeks out to make the real decision. Suspended-and-forgotten is the expensive state, and it is expensive quietly, which is what makes it easy to leave alone.
Move the data before you delete, and the order matters
Transfer while the account is suspended, not after it is deleted. Once the account is gone you are working against a clock and a list of conditions.
Google’s own summary of the awkward version: “Before transferring data for a deleted user, you need to restore that user within 20 days of deletion. If you want to retain a user’s data, you can suspend or archive them.” Restoring somebody just to move their files is a job you can avoid entirely by moving the files first.
If your business uses Google Vault, check for a litigation hold before you start. A litigation hold is an instruction to freeze somebody’s data because of a legal dispute or an investigation. Vault is the add-on that retains and searches company data for legal purposes. Google: “You can’t transfer data or delete a user who is on litigation hold.” Clearing one is not instant either, because an admin with Vault privileges “must first lift the hold (can take up to 48 hours to take effect)”. If that is your situation, the offboarding starts two days earlier than you thought.
Drive files, and the transfer that stops at 36 hours
Use the admin transfer tool in the Admin console under Apps, Google Workspace, Drive and Docs, then Transfer ownership. Google’s instructions for transferring Drive files to a new owner set conditions on both accounts first, and they are easy to trip over.
The person receiving the files has to be “in your organization”, have “an active account, not suspended, archived, or deleted”, have “adequate storage space”, and have “Drive turned on”. Read that first requirement twice. The account you are emptying should be suspended. The account you are filling must not be.
Three things do not come across, and one of them is destroyed later. Files in the bin are the important one. Google: “If you want to transfer files that are in Trash, move the files out of Trash. Items in Trash are not transferred. If you delete the user, untransferred files in Trash are deleted, too.” There is no route to an outside address: “For data security reasons, Google doesn’t support direct transfer of ownership to or from an external account.” And a custom map cannot move at all: “You can’t transfer ownership of Google Maps files.” Shared drives are the reassuring case, and it is the deletion page rather than this one that gives it: files there need no transfer, because “Your organization owns these files, not users”.
The transfer has a deadline you cannot extend. “If a transfer takes longer than 36 hours, it’s unsuccessful and will stop. You must attempt the transfer again.” Google’s own tip for a big Drive is that “If you transfer ownership of many files and folders at once, it might take some time to see the changes”. Start it in the morning rather than at five o’clock on a Friday.
Two smaller facts worth having. Everyone finds out: “The new owner, the previous owner, and the admin who started the transfer get a confirmation email.” And ownership is not the same as access: “The previous owner can still edit any transferred files, unless you delete their account or change their permissions.” Suspending them handles that, which is another argument for the order in this piece.
Calendars, where Google’s own deletion page contradicts itself
Transfer or cancel the calendars before you delete the account. That instruction holds whichever way the rule is running in your tenant, which is the honest state of this one.
First, why it matters at all. Google’s page on handling events before deleting a user: “If you delete or suspend a user without managing their Google Calendar events, the events no longer have an organizer that can change, update, or cancel them. The events block other users’ calendars and can block meeting rooms and resources.” That is the recurring meeting nobody can cancel, and the room held every Tuesday for a meeting that no longer happens.
Google’s calendar page says secondary calendars are now deleted with the user. Its wording opens “Starting in early 2026, when a calendar owner is deleted”, and goes on to say that their secondary calendars and the events in them are deleted too. “This update includes group calendars and Classroom calendars.” Then the part with no way back: “You also won’t be able to make any additional transfers once a calendar owner is deleted.”
Google’s deletion page states the same rule three times and disagrees with itself. In its section on what to ask a leaver to transfer, the rule is already running, in the same words the calendar page uses: “Starting in early 2026, when a calendar owner is deleted”. Two other notes on that page put it in the future. One reads: “Group calendars that a user owns aren’t currently deleted when the user is deleted, but this is scheduled to change in early 2026.” The other, in the list of what is not deleted, reads: “Changes to calendar deletion are planned for early 2026.”
Both pages carry the same “Last updated 2026-08-26 UTC” stamp, so this is not one page being older than the other. We are not going to tell you which reading applies to your tenant, because Google’s own deletion page does not agree with itself and guessing here costs somebody their team calendar. What all of those notes agree on is the instruction. The deletion page puts it plainly: “To prevent losing this data, we recommend transferring calendars before you delete users.” The calendar page gives the same instruction in its own words, in the sentence on secondary calendars below.
What the transfer actually moves is narrower than it sounds. From the primary calendar you get “only future, non-private events from their primary calendar with at least one guest or resource”. Everything else is spelled out: “All private events are canceled. Past events don’t transfer. Secondary calendars and their events don’t transfer. If a user is on a litigation hold, their events don’t transfer.”
Secondary calendars are the team ones, the room ones, the project ones, and they move on a separate screen. Google: “If you’re deleting a user and you need to keep their secondary calendars or if others are using them, ensure that you transfer that user’s secondary calendars before deleting.” Both jobs live in the Admin console under Apps, Google Workspace, Calendar, then Event and Secondary calendar management, and neither is instant. For the events job Google gives a figure: “The release or transfer starts approximately 10 minutes later and can last 15 minutes.” For the secondary calendars it gives none, because they go one by one: “If there are several calendars to transfer, the process could take a substantial amount of time.”
If you do not need the meetings, cancelling is tidier than it sounds, because “When you cancel events, Calendar doesn’t send notifications, so guests don’t get spammed”. Google’s own warning sits at the head of that screen, though: “You can’t undo this operation.” Cancel when you are sure. There is also a standing setting that cleans up after you: tick “Silently cancel future events of deleted users” and, in Google’s words, “21 days after you delete a user, the system automatically cancels their future events”. It only helps from now on, since “This option does not apply retroactively to previously deleted users”.
Mail: redirect is the one you want, not forward
Google has two settings that look identical in a list and are not. The wrong one leaves mail landing in a mailbox nobody is watching.
Redirect is built for this exact situation, and Google’s own example is your situation. On its page for redirecting or forwarding Gmail messages to another user, the option is called “Exclude original recipient (redirect)”, and the example beside it reads: “Someone leaves your organization and you want to redirect their future messages to their replacement, or to an account set up for this purpose. Messages aren’t delivered to the original recipient.”
Forward is built for a holiday. That option is “Include original recipient (forward)”, and its example is “Someone takes a leave of absence.” Google continues: “During their leave, you want them to keep getting their email so they have it when they’re back.” Set that one for a leaver and their old mailbox keeps receiving everything, which is the opposite of what you were trying to achieve.
You set it up in the Admin console under Apps, Google Workspace, Gmail, then Routing, and Google flags the near-miss menu item itself, because the setting sits on Routing and not on Default routing. Look for the section called “Email forwarding using recipient address map”. Two useful details: “Messages you redirect or forward appear to come directly from the original sender”, so the replacement sees a normal inbox rather than a pile of forwards, and “Changes can take up to 24 hours but typically happen more quickly”, so do it before the last day rather than after.
Redirecting handles the mail arriving from tomorrow. The mail already in the mailbox is a separate job, and Google gives you two routes: migrate the messages into another account with the data migration service, or archive the account so it stays searchable. If the leaver was the only person answering a shared address such as accounts@ or support@, that address should not belong to one person’s mailbox at all, and there are cheaper ways to run a shared address than paying for a seat nobody sits in.
Archiving has a small feature here that is easy to miss. When you archive somebody during the deletion flow, “you can assign a delegate to manage access requests to files and future email”, and anyone writing to the old address is looked after: “If an email is addressed to an archived user, the sender gets a notification about who to contact instead.”
Groups, and the four services with no way across
Removing somebody from a group is the small job people leave until it embarrasses them, usually when a client reply lands in a group the leaver still belongs to.
It is one screen, under Directory, then Groups, then Members. Google on removing members from a group: “If you remove a member from a group, they no longer receive email addressed to the group. Removing a member does not delete the user’s account.” And if the person ran the group, nothing breaks: “Also, if you remove the group owner, the group still works.”
Four Google services have no route into somebody else’s account at all, and it is worth knowing before you promise a colleague their files. On Google’s own page of options to preserve a former employee’s data, eight kinds of data each get their own section. Email, Calendar and Drive each have an admin route that puts the data into another account, and Contacts has a manual export and import that Google files under “User or admin options”. Chat, Groups, Keep and Voice have neither. Every admin option under those four is the Data Export tool, Google Vault or an Archived User licence, and all three save a copy rather than hand it over. Keep has the limit stated outright: “While you can use the Data Export tool to export Keep data, there’s no way to import it into Keep.”
So if the leaver kept anything that matters in Keep, held the only record of a decision in a Chat message or a group thread, or had a Voice number staff still ring, sort that out by hand while the account is still suspended and readable. There is no admin button for it.
Lock the account down: Google’s own seven steps
Google publishes a page called Maintain data security after an employee leaves, and it is seven items long. Work it in order.
- Wipe any mobile devices. “Use the Admin console to remotely remove data from the user’s device. You can remote wipe the entire device or only erase your organization’s data.” The second option is the one to use on a personal phone.
- Revoke password recovery access. “Remove the user’s recovery email address and phone number so they can’t use the password recovery feature to access their old account.”
- Change the user’s password. “This can greatly reduce the risk of unauthorized access to their old account.”
- Revoke OAuth 2.0 application tokens. These are the permissions the person granted to third-party apps. “Changing a user’s password also revokes OAuth 2.0 tokens issued for accessing certain products. Review all authorized access and revoke any other authorized applications.”
- Reset the sign-in cookies. “This also reduces the risk of unauthorized access.” Suspending already did this one.
- Revoke security keys and app password access. “Revoke any security keys or application-specific passwords that have been granted access to the user’s account.”
- Delete the account. “Move any of the user’s data that you want to save to another account. Then delete their original account completely.”
Four notes on the ones that behave in ways the list does not mention.
Removing an app’s access is not permanent on its own. This is the one that matters most, because the checklist reads like a padlock and the setting is a latch. Google’s page on managing a user’s security settings: “Removing data access for an app doesn’t prevent a user from using the app in the future (if the user has the necessary permissions). Once a user signs into the app again, data access is restored.” Google’s own fix is a setting rather than a sequence, and it sits in the very next sentence: “To permanently restrict user access to applications, you can block access to specific application scopes and set up an allowlist of approved apps for your organization.” Removing one app’s access, on its own, is theatre.
App passwords are a separate list from connected apps. An application-specific password is a separate password you create once for one app or device that cannot handle a 2-Step Verification prompt, such as an old mail client. Google’s rule: “You should revoke an app password if a user loses a device or stops using an app that was authorized with that password.” They sit in their own section on the user’s Security page, and Google’s seven steps list revoking them separately from changing the password, so treat them as their own job.
Signing them out is not instant, and the gap is longer than the click suggests. Resetting sign-in cookies “signs the user out of their Google Account (including any Google Workspace applications) across all devices and browsers”, but “It can take up to an hour to sign the user out of current Gmail sessions. The time for other applications can vary.” There is a second door if your company uses single sign-on, where staff log in through a separate provider rather than to Google directly: “the user’s SSO session may still allow access to their Google Account after resetting their sign-in cookies”. End that session with the provider, not with Google.
Android phones can make a new passkey out of thin air. A passkey is a sign-in that uses the phone’s own screen lock instead of a password. Google’s warning about doing half the job: “If you reset a user’s cookies without resetting their password, they will still be able to sign in to their Android device that will add an automatically created passkey again.” Do both together.
None of this is a substitute for the settings that were meant to be right before anybody resigned. If you have never worked through the account items Google recommends for a business your size, that list is short and we have walked it in plain words.
Getting the licence back depends on your billing plan
Deleting somebody stops you paying for them on one plan and does nothing on the other. It is the fork that decides whether offboarding saves you anything, and it is worth real money.
On the Flexible Plan, deleting is the whole job. Google’s page on reducing user licences: “You don’t need to directly reduce user licenses on the Flexible Plan. Instead, just delete the users who no longer need a license. The number of licenses decreases by one for each user you delete. For paid services, your monthly payment decreases when you delete users.” The deletion page adds that the change is fair to the day: “When you delete a user account, your monthly rate is prorated accordingly.”
On the Annual or Fixed-Term Plan, deleting changes nothing on the bill. Google is direct about it: “Deleting an account doesn’t reduce the number of licenses you have and doesn’t affect your billing.” You committed to a year of seats and you are paying for the year. What deleting gives you is a spare: “You can assign the deleted user’s license to another user, but if you later restore the deleted user, you’ll need another license.”
There is a separate switch, and it only works before your renewal date. Go to Billing, then Subscriptions, click the subscription, and next to Renewal options choose “Auto-renew my contract with fewer licenses”. Then delete the accounts, or move them to a Cloud Identity or Archived User licence, before the contract renews. A Cloud Identity licence goes on the account in place of the Workspace one, so the person stays in your directory without holding a Workspace seat. Google describes what happens on the day: “On the day your contract is set to renew, we renew your annual commitment for the number of user accounts you have that day. We remove any licenses you’re not currently using from your commitment, and your payment goes down.”
Miss the renewal date and you pay for the empty seats for another twelve months. Which plan you are on is worth knowing before anybody hands in their notice, and the two plans differ in more places than this one: we have set out how the Flexible and Annual plans compare separately.
One more branch. If you bought Google Workspace through a reseller rather than from Google directly, the licence steps above are not yours to run. Google’s own licence page opens by sending those customers elsewhere: “If you purchased your service from a reseller, go here instead”. Your billing lives with whoever sold it to you, and the reduction goes through them.
Does your console say Delete, or Remove?
Look at the button before you plan around it. Google runs two different procedures depending on how your organisation signed up, and they end in different places.
The fork is on Google’s own page for deleting or removing a user, which asks you to choose between an organisation that “verified ownership of your organization’s domain” and one that “verified your business email address”. Domain-verified is the ordinary case for a business with its own domain. Email-verified happens where somebody signed up with a business email address and domain verification was never completed. Google gives examples of the services it applies to: “Google Workspace Business or Essentials, or Chrome Enterprise”.
On a domain-verified organisation you get Delete, and it means it. “A deleted user’s data is unrecoverable once it’s deleted”, with the 20-day restore window as the only way back.
On an email-verified organisation you get Remove, and the account survives. Google: “After you remove a user’s account from your Google service, their account is converted to a consumer Google Account.” It becomes a personal Google account, owned by them, and by default it keeps some access to your company. Google’s list of what a removed user can still do:
- “Join any video meetings they’re invited to or meetings they previously created.”
- “Access files in shared drives and other Drive files shared directly with them (not through a group).”
- “Access their direct messages.”
- “Access room tasks assigned to them in Google Chat.”
Those are defaults, and two of the four can be closed. Both settings need a paid Business or Essentials edition, because Google puts them under a heading that says so: “Paid editions of Business and Essentials editions only”. Drive permissions that stop sharing outside your organisation close the shared-file access. Chat permissions that stop people messaging outside your organisation close the direct messages. The meetings and the Chat room tasks stay open either way. Set what you can before you remove anybody, because after the account converts it is a stranger’s account and you are no longer its administrator.
There is one more line on that page worth having in advance, because it stops a Friday afternoon dead: “You can’t delete your own administrator account.” Somebody else with super administrator rights has to do it, which matters if the person leaving is you.
You have 20 days to change your mind, if three things are true
Deleting is reversible for a while. It is less reversible than the headline number suggests, so read the conditions before you rely on it.
The rule on restoring a recently deleted user: “You can restore a user account (including administrator accounts) up to 20 days after deleting it. After 20 days, the data is gone and you can’t restore it.”
Google’s own list of what stops a restore has three entries, and the first is the 20 days running out. Inside the window, two are left. You cannot restore if “You don’t have an available user license for the service or edition that was previously assigned to the user”, which on the Annual plan is the licence you may have just reassigned to somebody else. You cannot restore if the domain has moved: “Your domain is no longer available or has been moved to another Google Workspace account.” One more thing is worth knowing, though it does not stop the restore: if the account had an Archived User licence, the restore is not finished when the button says it is, because “you need to manually reassign that license to ensure that the user’s data and policies are properly restored”.
It is also not quick. “Usually, it takes up to 24 hours for this change to take effect, but in rare cases it can take up to 5 days.” And what comes back may not be an open account: “If the user was previously suspended or had their data transferred, they’ll show as a suspended user”, which you then restore separately.
If you use Vault, the 20 days do not protect the data the way you would expect. Google: “If your organization uses Google Vault, any retention rules or holds placed on the deleted user’s data no longer apply. Data can be purged immediately. It can’t be recovered even if you restore the user within 20 days.” Deleting a Vault-covered account can lose data the restore button cannot bring back, and it is the sharpest example on this page.
The email address has its own clock. “Twenty days after a user’s account is deleted, their email address is removed from Google Workspace. However, you can reassign the address to another managed user before that 20-day period ends.” Reassigning is not instant: “Reassigning an email address may take up to 24 hours to take effect.” And if the plan was to hand the address to somebody’s personal Google account, there is a longer wait: “If you plan to use the email address for an unmanaged personal Google Account, you must wait 30 days to prevent account conflicts”.
One reassurance, because it is the fear that makes people put this off. A transfer that goes wrong does not leave you with half an employee. Google: “If the data transfer can’t be completed for any reason, the user-deletion process stops. The user’s account isn’t deleted, and their data remains untouched. You’ll receive an error message in the Admin console explaining why the transfer failed.”
Where to start
Suspend the account on the last day. That is the whole of what has to happen immediately, and it is reversible.
Then work through the rest in the week after. The order is the one at the top of this page.
Then put a date in your own calendar for the decision. Delete, archive, or keep paying, and make it a choice rather than a default. Check which billing plan you are on first, because on the Annual plan the saving is at renewal and nowhere else.
If your Workspace was set up by somebody who no longer works with you, and nobody is sure who holds the super administrator account or the domain login, that is a bigger problem than one leaver and it is worth fixing before the next one. It starts with a look at what you actually have, and that conversation begins on our Google Workspace page.
