> ## Documentation Index
> Fetch the complete documentation index at: https://docs.northernlogic.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Member offboarding

> Revoke future access while deliberately handling personal knowledge and shares.

Workspace owners and admins can disable ordinary members. Only an owner can
change elevated roles, and the final active owner is protected.

## Before disabling someone

Review their active connections, group membership, shared responsibilities, and
personal-vault delegates. Export or file any knowledge you are already
authorized to manage and need to retain. Organization administration does not
grant access to an otherwise private personal vault.

## Disable the member

1. Open **Team** and the person's **Actions → Disable**.
2. Review the person and select the personal-vault handling option.
3. Confirm the intended disposition.
4. Check the person's connections and remaining delegates afterward.

| Option                              | Result                                                                                    |
| ----------------------------------- | ----------------------------------------------------------------------------------------- |
| Retain vault and existing delegates | Disables the person and leaves existing explicit delegates in place. This is the default. |
| Archive vault and revoke delegates  | Archives the personal vault and removes delegated access.                                 |
| Retain vault and add vault admins   | Keeps the historical owner and adds selected active delegates as vault admins.            |

The member is disabled rather than erased, preserving attribution. Their owned
connections and credentials are revoked, and their group memberships are
removed. The historical personal-vault owner is not transferred to someone
else's identity.

## What still needs review

Disabling a creator does not revoke share links they created; shares belong to
the vault. Inspect and revoke any links that should no longer work.

Revocation stops future authorized requests but does not erase local Markdown
already downloaded to a machine. Handle device return and retained copies
through your organization's device process.

An eligible owner or Northern Logic administrator can restore archived
personal-vault metadata, but restoration does not automatically recreate revoked
content grants. Ask support if the restoration is not available in your current
controls.

See [connection revocation](/connections/manage) for removing one endpoint
without disabling a person.
