Offboard a leaver
This guide builds an offboarding request that someone in IT or a manager submits on a person’s last day. After an approver agrees, the workflow suspends the person’s Google Workspace account, which blocks their access to mail and files, and reassigns their open Jira issues to their manager. It then emails the manager and the person who asked a record of what changed, and of what still needs doing by hand.
Google Workspace has no built-in action in KloudMate, so the workflow calls Google’s Admin SDK API through an OAuth 2.0 connection, the same way the Gmail guide calls Gmail.
The finished workflow has these steps:
Before you start
Section titled “Before you start”- You need the Developer role in a KloudMate workspace whose plan includes workflows.
- You need a Jira Cloud connection with the Workflows capability.
- You need a Google Workspace administrator account that can manage users, and a Google Cloud project where you can create an OAuth client.
- The people who submit the form need to be members of your KloudMate workspace, because the form has Sign-in required turned on.
Step 1: Connect Google as an administrator
Section titled “Step 1: Connect Google as an administrator”-
In the Google Cloud console, enable the Admin SDK API, and create an OAuth client the way the Gmail guide describes in Step 1: Create an OAuth client in Google Cloud. Make the consent screen Internal to your organization, so its tokens don’t expire after 7 days.
-
In KloudMate, open Workflows → Connections, click Connect, and pick OAuth 2.0. Name the connection
Google Admin, and fill in the form:Field Value Grant type Authorization code Token URL https://oauth2.googleapis.com/tokenAuthorize URL https://accounts.google.com/o/oauth2/v2/auth?access_type=offline&prompt=consentScopes https://www.googleapis.com/auth/admin.directory.userClient ID and Client secret The values from your OAuth client. Send client credentials In the body -
Click Connect, and sign in to Google as the administrator.
The connection acts as that administrator, so the workflow can suspend any user in your Google Workspace organization. Only people with the Developer role can use or change the connection in KloudMate.
Step 2: Import the workflow
Section titled “Step 2: Import the workflow”- Copy the YAML below.
- Open Workflows, click Import, paste the YAML, and click Import.
- Click Open workflow, and set these before you publish:
- On Suspend the Google account, pick your
Google Adminconnection. - On every Jira step, pick your Jira connection and the Site.
- On Approve the offboarding, add the people who can approve an offboarding under Approvers.
- On Suspend the Google account, pick your
How each step works
Section titled “How each step works”The form and the approval
Section titled “The form and the approval”The Form submission trigger asks for the leaver’s work email, their manager_email, and optional notes. Sign-in required is on, so the approval request can name the person who submitted it, as {{ trigger.submitted_by.name }}.
Suspending an account can’t wait for someone to notice a mistake, so an Approval step asks a second person first. Its message says exactly what will happen to whom. If the approver rejects the request, or nobody answers within 24 hours, the run ends without changing anything.
Suspend the Google account
Section titled “Suspend the Google account”An HTTP Request step with Authentication set to OAuth 2.0 connection sends a PUT to Google’s Directory API:
Its JSON body is {"suspended": true}. Google changes only the fields in the body, so the rest of the account stays as it was. A suspended user can’t use Gmail, Drive, or other Google Workspace services, and new mail to them is blocked. Their data stays in place, people they shared files with keep their access, and the account still counts toward your Google bill until you delete it.
url_encode makes the address safe to put in a URL, by turning the @ into %40.
Reassign their open Jira issues
Section titled “Reassign their open Jira issues”The Jira branch of the Parallel step runs at the same time as the Google branch:
-
A Jira Find User step finds the leaver by email. A Branch checks that it found an account, so someone who never used Jira is skipped.
-
Another Find User step finds the manager.
-
A Jira Search Issues step finds the leaver’s open issues, with this JQL:
-
A Loop assigns each issue to the manager. Run at once is
5, because the issues don’t depend on each other.
A search returns at most 100 issues. Someone with more than that keeps the rest, and you can run the workflow again to move the next 100.
Carry on when a tool fails
Section titled “Carry on when a tool fails”Suspend the Google account and Assign it to the manager both have On failure set to Go to the next step, under Settings. If Google refuses the request or one issue can’t be reassigned, the other changes still happen, and the email reports the failure.
Email what changed
Section titled “Email what changed”A Send Email step emails the manager and the person who submitted the form, with a line for each tool. It reads the results of the steps that ran in the parallel branches:
Some of these values exist only in some runs. steps.suspend.error is set only when the Google request failed, and steps.reassign only when the leaver had a Jira account. Reading them with assign keeps a missing one from showing up as an unresolved reference in run history. When the request failed, the email includes Google’s error, such as a missing permission.
The email also lists what the workflow can’t do. KloudMate’s Slack actions can’t deactivate a user, so a Slack admin does that by hand.
Step 3: Test and publish
Section titled “Step 3: Test and publish”Test with an account you can afford to lose, such as a test user in your Google Workspace:
- Click Publish. The first publish also switches the workflow on, and the form goes live.
- Open the trigger, copy the Public form URL, and submit the form for the test user, with your own address as the manager.
- Approve the request from the email.
- Check that the test user is suspended in the Google Admin console, and read the email the workflow sent.
To undo the test, unsuspend the user in the Google Admin console.
Adapt the workflow
Section titled “Adapt the workflow”- Transfer their files. Add an HTTP Request step that calls Google’s Data Transfer API to move the leaver’s Drive files to their manager. Add the scope
https://www.googleapis.com/auth/admin.datatransferto the connection, and click Reconnect on it. - Offboard from another identity provider. Replace Suspend the Google account with a call to your provider’s API, through an OAuth 2.0 connection or with a token stored as a secret.
- Open a ticket for the manual steps. Add a Jira Create Issue step after the email, for the Slack account and the equipment, and assign it to your IT team.
Related
Section titled “Related”- Approvals and collected input for the approval email.
- Parallel for running independent branches together.
- HTTP Request for calling an API through an OAuth 2.0 connection.