checklist
AI tool decommissioning checklist for small teams
A practical checklist for retiring an AI tool, covering shutdown decisions, user access, connectors, data exports, retention, deletion, billing, employee communication, evidence, and follow-up review.
Use this checklist when an AI tool is being retired, replaced, downgraded, blocked, or removed from an approved list.
Small teams often approve tools more carefully than they remove them. That creates quiet risk: active accounts after cancellation, OAuth connectors that still reach source systems, browser extensions still installed, meeting transcripts still retained, exported files in personal drives, and billing owners who cannot prove what was shut down. If the reason for removal is a risk change, rerun the AI Tool Risk Checker before finalizing the shutdown record.
Bottom line
An AI tool is not decommissioned until five things are true:
- Users, admins, guests, bots, service accounts, and shared accounts no longer have access.
- Connectors, OAuth grants, browser extensions, meeting bots, API keys, webhooks, and automations are removed or transferred.
- Retained prompts, files, transcripts, exports, memories, projects, logs, and source-system copies are handled according to the approved rule.
- Billing, renewal, procurement, and vendor support paths are closed or transferred.
- The team has a short evidence packet proving the shutdown decision and cleanup.
Do not put raw customer records, passwords, API keys, private keys, meeting transcripts, source code, regulated data, dashboard URLs with tokens, or private billing details into the evidence packet.
When to use this checklist
| Situation | Use this checklist? | Why |
|---|---|---|
| Tool is not renewed | Yes | Cancellation alone does not remove data, accounts, or connectors. |
| Tool failed a monthly access review | Yes | Cleanup should be recorded, not assumed. |
| Vendor changed data, training, retention, or sharing terms | Yes | Settings and exports may need closure before access ends. |
| Tool is replaced by another AI tool | Yes | Prevent duplicated connectors and unmanaged exports. |
| Pilot did not graduate | Yes | Remove pilot users, files, and test automations. |
| Incident or near miss led to removal | Yes | Preserve evidence and close containment actions. |
| One-time public experiment ended | Usually yes | Use the lightweight version if no account, connector, or data remains. |
For baseline controls, start with the Small Team AI Security Checklist.
Shutdown decision matrix
| Decision | Use when | Cleanup level |
|---|---|---|
| Retire | Tool is no longer needed. | Full access, connector, data, billing, and evidence cleanup. |
| Replace | A safer or cheaper tool takes over. | Full cleanup plus migration checks. |
| Downgrade | Paid plan is no longer justified. | Access and billing cleanup; confirm admin controls still match risk. |
| Restrict | Tool remains for narrow use. | Remove broad users, connectors, and data classes. |
| Block | Tool is unsafe or not approved. | Remove access and add block/allowlist controls. |
| Pause | Temporary concern or vendor change. | Disable risky use, preserve evidence, set review date. |
| Transfer | Another owner or team keeps the tool. | Transfer owner, billing, evidence, and review calendar. |
If the decision is restrict or pause, record the tool in the AI tool exception register template.
Decommissioning owner map
| Owner | Cleanup responsibility |
|---|---|
| Business owner | Confirms workflow is retired, replaced, or restricted. |
| Admin owner | Removes workspace users, admins, guests, groups, bots, and settings. |
| Source-system owner | Revokes OAuth grants, API access, webhooks, browser extensions, CRM sync, calendar access, storage access, and repo access. |
| Data owner | Decides retention, deletion, export, and migration handling. |
| Finance owner | Cancels or transfers subscription, renewal, invoices, and procurement records. |
| Security or operations owner | Reviews evidence, exceptions, incidents, and follow-up tasks. |
| Communications owner | Tells users what changes and what replacement workflow to use. |
If there is no owner for one row, do not call the shutdown complete.
Pre-shutdown inventory
| Item | Check | Owner |
|---|---|---|
| Approved use case | What workflow is ending or changing? | Business owner |
| Current users | Users, admins, guests, groups, shared accounts, and service accounts. | Admin owner |
| Connected systems | OAuth apps, browser extensions, meeting bots, APIs, webhooks, source-system integrations, and automations. | Source-system owner |
| Data classes | Public, internal, customer, transcript, source code, regulated, financial, or secret data. | Data owner |
| Retained content | Prompts, projects, files, transcripts, memories, summaries, logs, exports, and backups. | Data owner |
| Billing | Plan, renewal date, payment owner, cancellation window, and refund path. | Finance owner |
| Open obligations | Incident, exception, legal hold, customer promise, vendor support ticket, or migration need. | Operations owner |
Use the AI tool audit evidence packet template to store the final record.
Access removal checklist
| Action | Done | Evidence |
|---|---|---|
| Export or record current users before removal. | ||
| Remove active users who no longer need access. | ||
| Remove admins, billing owners, workspace owners, and delegated admins. | ||
| Remove guests, external collaborators, contractors, and personal accounts used for work. | ||
| Remove service accounts, bots, shared accounts, and test accounts. | ||
| Remove group membership or identity-provider assignment. | ||
| Disable SSO app assignment if the tool is fully retired. | ||
| Confirm departed employees have no retained access. | ||
| Store a final access export or redacted setting note. |
Do not paste private user exports into a public ticket or public repository.
Connector and automation cleanup
| Connector type | Cleanup action |
|---|---|
| OAuth app | Revoke app access and confirm source-system scopes are gone. |
| Browser extension | Remove from allowlist, push block policy if needed, and check sensitive host permissions. |
| Meeting bot | Remove calendar access, recording permissions, transcript sharing, and CRM sync. |
| API key | Revoke the key, rotate any related secrets, and confirm jobs fail closed. |
| Webhook | Disable endpoint and remove downstream automation. |
| Code tool | Remove repo access, branch integration, CI/CD tokens, and terminal/agent permissions. |
| Storage connector | Remove Drive, SharePoint, Dropbox, Notion, or internal wiki access. |
| CRM/helpdesk connector | Remove customer record sync and exported summaries. |
| Workflow automation | Disable scheduled tasks, agents, zaps, scripts, and background jobs. |
If any connector remains, document why and who owns the next review date.
Data and retention cleanup
| Data location | Cleanup question | Decision |
|---|---|---|
| Chat history | Should prompts and responses be deleted, retained, exported, or archived? | |
| Projects or workspaces | Are files, memories, custom instructions, or shared project artifacts still present? | |
| Uploaded files | Were customer files, source code, transcripts, or regulated documents uploaded? | |
| Meeting transcripts | Should raw transcript, summary, recording, and CRM copy be deleted or retained? | |
| Browser extension storage | Did the extension retain page content, screenshots, or local state? | |
| Developer tool index | Did the tool index repos, terminals, logs, or codebase context? | |
| Source-system copies | Did the tool write summaries or exports back into CRM, helpdesk, Drive, GitHub, or wiki? | |
| Local exports | Did users export CSVs, PDFs, markdown files, screenshots, or notebooks? | |
| Vendor logs | Is deletion, export, or support confirmation needed? |
If deletion cannot be confirmed, record the limitation and the remaining owner.
Billing and vendor closure
| Item | Check |
|---|---|
| Renewal date | Confirm cancellation happens before the renewal window closes. |
| Plan owner | Transfer or remove billing owner access. |
| Payment method | Remove payment method if no longer needed. |
| Invoices | Store only normal accounting records, not private payout or tax details. |
| Refund or credit | Record non-sensitive public status only. |
| Vendor support | Close deletion, access, export, or incident support tickets. |
| Contract note | Record whether the tool can be reactivated without a new review. |
| Replacement cost | Record whether spend moved to another approved tool. |
Do not commit Stripe keys, dashboard links with tokens, private invoices, tax records, or payment details.
User communication template
Copy this into internal chat or email.
Subject: AI tool shutdown: [tool name]
[Tool name] is being retired/restricted on [date].
What changes:
- Stop using [tool name] for [workflow].
- Use [replacement workflow/tool] instead.
- Do not create new exports, connectors, bots, extensions, or automations for this tool.
- If you have customer data, source code, transcripts, files, or exports from this tool, tell [owner] by [date].
What we are cleaning up:
- User and admin access
- Connectors and automations
- Retained files, transcripts, prompts, exports, and summaries
- Billing and renewal records
Questions:
Contact [owner].
Keep the message specific. If employees do not know the replacement workflow, they will recreate the risk elsewhere.
Decommissioning record
Copy this into the evidence packet.
AI tool decommissioning record
Tool:
Vendor:
Decision: retire / replace / downgrade / restrict / block / pause / transfer
Decision date:
Shutdown target date:
Business owner:
Admin owner:
Source-system owner:
Data owner:
Finance owner:
Reason:
Replacement workflow:
Access cleanup:
Connector cleanup:
Data and retention cleanup:
Billing and vendor closure:
User communication:
Open exceptions:
Open incidents:
Remaining risk:
Final status:
Next review date:
Evidence links:
The record should contain links to controlled internal evidence, not raw sensitive content.
Final verification checklist
| Verification | Done |
|---|---|
| No active users, admins, guests, bots, shared accounts, or service accounts remain unless documented. | |
| No OAuth grants, extensions, meeting bots, APIs, webhooks, or automations remain unless documented. | |
| Retained prompts, files, projects, transcripts, summaries, exports, and logs were deleted, archived, or assigned an owner. | |
| Source-system copies in CRM, helpdesk, storage, calendar, code hosting, or wiki were reviewed. | |
| Billing, renewal, and vendor support were closed or transferred. | |
| Employees were told the replacement workflow. | |
| Exceptions, incidents, and legal/privacy escalations were linked. | |
| Review calendar and tool inventory were updated. | |
| Evidence packet was stored in the approved internal location. |
If any row is incomplete, leave the tool status as closing, not closed.
Metrics to track
| Metric | Why it matters |
|---|---|
| Tools retired | Shows whether the team can remove unused tools. |
| Tools with leftover users | Shows access cleanup weakness. |
| Tools with leftover connectors | Shows hidden source-system risk. |
| Tools with unresolved data retention | Shows deletion and export gaps. |
| Tools with billing still active | Shows wasted spend. |
| Average days to close | Shows whether shutdown is operationally manageable. |
| Repeat shutdown blockers | Shows where policy, ownership, or admin controls need improvement. |
If decommissioning repeatedly fails on the same connector type, review the allowlist and intake process.
Evidence checked
- NIST: AI Risk Management Framework
- NIST: Cybersecurity Framework 2.0
- NIST: Privacy Framework
- NIST CSRC: SP 800-88 Rev. 2, Guidelines for Media Sanitization
- Cybergiz: AI Tool Risk Checker
- Cybergiz: Small Team AI Security Checklist
- Cybergiz: AI tool renewal decision checklist
- Cybergiz: AI tool audit evidence packet template
FAQ
Is canceling the subscription enough?
No. Cancellation may stop billing, but it does not prove that users, connectors, exports, transcripts, files, logs, bots, or source-system copies were removed.
Should we delete all data immediately?
Not always. Follow your approved retention, legal, privacy, customer, and accounting rules. The checklist is meant to force a recorded decision, not automatic deletion in every case.
What if the vendor does not support deletion?
Record the limitation, restrict future use, preserve the vendor response, and decide whether the tool can be approved again. Do not invent deletion proof.
Who owns decommissioning?
The business owner owns the decision. The admin owner removes access and settings. Source-system owners revoke connectors. The data owner handles retention and deletion. Finance closes billing.
What if users still need old outputs?
Move approved outputs into an approved internal system, record the owner and retention rule, and remove the tool access. Do not keep the tool alive only as an unmanaged archive.
How does this connect to the main checklist?
The Small Team AI Security Checklist defines the baseline controls. This decommissioning checklist proves those controls are closed when an AI tool leaves the environment.