Skip to main content
Workspace owners and admins can disable ordinary members. Only an owner can change elevated roles, and the final active owner is protected.

Before disabling someone

Review their active connections, group membership, shared responsibilities, and personal-vault delegates. Export or file any knowledge you are already authorized to manage and need to retain. Organization administration does not grant access to an otherwise private personal vault.

Disable the member

  1. Open Team and the person’s Actions → Disable.
  2. Review the person and select the personal-vault handling option.
  3. Confirm the intended disposition.
  4. Check the person’s connections and remaining delegates afterward.
The member is disabled rather than erased, preserving attribution. Their owned connections and credentials are revoked, and their group memberships are removed. The historical personal-vault owner is not transferred to someone else’s identity.

What still needs review

Disabling a creator does not revoke share links they created; shares belong to the vault. Inspect and revoke any links that should no longer work. Revocation stops future authorized requests but does not erase local Markdown already downloaded to a machine. Handle device return and retained copies through your organization’s device process. An eligible owner or Northern Logic administrator can restore archived personal-vault metadata, but restoration does not automatically recreate revoked content grants. Ask support if the restoration is not available in your current controls. See connection revocation for removing one endpoint without disabling a person.