checklist

AI tool decommissioning checklist for small teams

A practical checklist for retiring an AI tool, covering shutdown decisions, user access, connectors, data exports, retention, deletion, billing, employee communication, evidence, and follow-up review.

Audience: Founders, operators, IT owners, workspace admins, finance owners, security leads, and team managers retiring AI tools Risk: Medium Evidence: NIST AI RMF, NIST Cybersecurity Framework 2.0, NIST Privacy Framework, NIST SP 800-88 Rev. 2, and Cybergiz AI tool operations templates

Use this checklist when an AI tool is being retired, replaced, downgraded, blocked, or removed from an approved list.

Small teams often approve tools more carefully than they remove them. That creates quiet risk: active accounts after cancellation, OAuth connectors that still reach source systems, browser extensions still installed, meeting transcripts still retained, exported files in personal drives, and billing owners who cannot prove what was shut down. If the reason for removal is a risk change, rerun the AI Tool Risk Checker before finalizing the shutdown record.

Bottom line

An AI tool is not decommissioned until five things are true:

  1. Users, admins, guests, bots, service accounts, and shared accounts no longer have access.
  2. Connectors, OAuth grants, browser extensions, meeting bots, API keys, webhooks, and automations are removed or transferred.
  3. Retained prompts, files, transcripts, exports, memories, projects, logs, and source-system copies are handled according to the approved rule.
  4. Billing, renewal, procurement, and vendor support paths are closed or transferred.
  5. The team has a short evidence packet proving the shutdown decision and cleanup.

Do not put raw customer records, passwords, API keys, private keys, meeting transcripts, source code, regulated data, dashboard URLs with tokens, or private billing details into the evidence packet.

When to use this checklist

SituationUse this checklist?Why
Tool is not renewedYesCancellation alone does not remove data, accounts, or connectors.
Tool failed a monthly access reviewYesCleanup should be recorded, not assumed.
Vendor changed data, training, retention, or sharing termsYesSettings and exports may need closure before access ends.
Tool is replaced by another AI toolYesPrevent duplicated connectors and unmanaged exports.
Pilot did not graduateYesRemove pilot users, files, and test automations.
Incident or near miss led to removalYesPreserve evidence and close containment actions.
One-time public experiment endedUsually yesUse the lightweight version if no account, connector, or data remains.

For baseline controls, start with the Small Team AI Security Checklist.

Shutdown decision matrix

DecisionUse whenCleanup level
RetireTool is no longer needed.Full access, connector, data, billing, and evidence cleanup.
ReplaceA safer or cheaper tool takes over.Full cleanup plus migration checks.
DowngradePaid plan is no longer justified.Access and billing cleanup; confirm admin controls still match risk.
RestrictTool remains for narrow use.Remove broad users, connectors, and data classes.
BlockTool is unsafe or not approved.Remove access and add block/allowlist controls.
PauseTemporary concern or vendor change.Disable risky use, preserve evidence, set review date.
TransferAnother owner or team keeps the tool.Transfer owner, billing, evidence, and review calendar.

If the decision is restrict or pause, record the tool in the AI tool exception register template.

Decommissioning owner map

OwnerCleanup responsibility
Business ownerConfirms workflow is retired, replaced, or restricted.
Admin ownerRemoves workspace users, admins, guests, groups, bots, and settings.
Source-system ownerRevokes OAuth grants, API access, webhooks, browser extensions, CRM sync, calendar access, storage access, and repo access.
Data ownerDecides retention, deletion, export, and migration handling.
Finance ownerCancels or transfers subscription, renewal, invoices, and procurement records.
Security or operations ownerReviews evidence, exceptions, incidents, and follow-up tasks.
Communications ownerTells users what changes and what replacement workflow to use.

If there is no owner for one row, do not call the shutdown complete.

Pre-shutdown inventory

ItemCheckOwner
Approved use caseWhat workflow is ending or changing?Business owner
Current usersUsers, admins, guests, groups, shared accounts, and service accounts.Admin owner
Connected systemsOAuth apps, browser extensions, meeting bots, APIs, webhooks, source-system integrations, and automations.Source-system owner
Data classesPublic, internal, customer, transcript, source code, regulated, financial, or secret data.Data owner
Retained contentPrompts, projects, files, transcripts, memories, summaries, logs, exports, and backups.Data owner
BillingPlan, renewal date, payment owner, cancellation window, and refund path.Finance owner
Open obligationsIncident, exception, legal hold, customer promise, vendor support ticket, or migration need.Operations owner

Use the AI tool audit evidence packet template to store the final record.

Access removal checklist

ActionDoneEvidence
Export or record current users before removal.
Remove active users who no longer need access.
Remove admins, billing owners, workspace owners, and delegated admins.
Remove guests, external collaborators, contractors, and personal accounts used for work.
Remove service accounts, bots, shared accounts, and test accounts.
Remove group membership or identity-provider assignment.
Disable SSO app assignment if the tool is fully retired.
Confirm departed employees have no retained access.
Store a final access export or redacted setting note.

Do not paste private user exports into a public ticket or public repository.

Connector and automation cleanup

Connector typeCleanup action
OAuth appRevoke app access and confirm source-system scopes are gone.
Browser extensionRemove from allowlist, push block policy if needed, and check sensitive host permissions.
Meeting botRemove calendar access, recording permissions, transcript sharing, and CRM sync.
API keyRevoke the key, rotate any related secrets, and confirm jobs fail closed.
WebhookDisable endpoint and remove downstream automation.
Code toolRemove repo access, branch integration, CI/CD tokens, and terminal/agent permissions.
Storage connectorRemove Drive, SharePoint, Dropbox, Notion, or internal wiki access.
CRM/helpdesk connectorRemove customer record sync and exported summaries.
Workflow automationDisable scheduled tasks, agents, zaps, scripts, and background jobs.

If any connector remains, document why and who owns the next review date.

Data and retention cleanup

Data locationCleanup questionDecision
Chat historyShould prompts and responses be deleted, retained, exported, or archived?
Projects or workspacesAre files, memories, custom instructions, or shared project artifacts still present?
Uploaded filesWere customer files, source code, transcripts, or regulated documents uploaded?
Meeting transcriptsShould raw transcript, summary, recording, and CRM copy be deleted or retained?
Browser extension storageDid the extension retain page content, screenshots, or local state?
Developer tool indexDid the tool index repos, terminals, logs, or codebase context?
Source-system copiesDid the tool write summaries or exports back into CRM, helpdesk, Drive, GitHub, or wiki?
Local exportsDid users export CSVs, PDFs, markdown files, screenshots, or notebooks?
Vendor logsIs deletion, export, or support confirmation needed?

If deletion cannot be confirmed, record the limitation and the remaining owner.

Billing and vendor closure

ItemCheck
Renewal dateConfirm cancellation happens before the renewal window closes.
Plan ownerTransfer or remove billing owner access.
Payment methodRemove payment method if no longer needed.
InvoicesStore only normal accounting records, not private payout or tax details.
Refund or creditRecord non-sensitive public status only.
Vendor supportClose deletion, access, export, or incident support tickets.
Contract noteRecord whether the tool can be reactivated without a new review.
Replacement costRecord whether spend moved to another approved tool.

Do not commit Stripe keys, dashboard links with tokens, private invoices, tax records, or payment details.

User communication template

Copy this into internal chat or email.

Subject: AI tool shutdown: [tool name]

[Tool name] is being retired/restricted on [date].

What changes:
- Stop using [tool name] for [workflow].
- Use [replacement workflow/tool] instead.
- Do not create new exports, connectors, bots, extensions, or automations for this tool.
- If you have customer data, source code, transcripts, files, or exports from this tool, tell [owner] by [date].

What we are cleaning up:
- User and admin access
- Connectors and automations
- Retained files, transcripts, prompts, exports, and summaries
- Billing and renewal records

Questions:
Contact [owner].

Keep the message specific. If employees do not know the replacement workflow, they will recreate the risk elsewhere.

Decommissioning record

Copy this into the evidence packet.

AI tool decommissioning record

Tool:
Vendor:
Decision: retire / replace / downgrade / restrict / block / pause / transfer
Decision date:
Shutdown target date:
Business owner:
Admin owner:
Source-system owner:
Data owner:
Finance owner:
Reason:
Replacement workflow:

Access cleanup:

Connector cleanup:

Data and retention cleanup:

Billing and vendor closure:

User communication:

Open exceptions:

Open incidents:

Remaining risk:

Final status:

Next review date:

Evidence links:

The record should contain links to controlled internal evidence, not raw sensitive content.

Final verification checklist

VerificationDone
No active users, admins, guests, bots, shared accounts, or service accounts remain unless documented.
No OAuth grants, extensions, meeting bots, APIs, webhooks, or automations remain unless documented.
Retained prompts, files, projects, transcripts, summaries, exports, and logs were deleted, archived, or assigned an owner.
Source-system copies in CRM, helpdesk, storage, calendar, code hosting, or wiki were reviewed.
Billing, renewal, and vendor support were closed or transferred.
Employees were told the replacement workflow.
Exceptions, incidents, and legal/privacy escalations were linked.
Review calendar and tool inventory were updated.
Evidence packet was stored in the approved internal location.

If any row is incomplete, leave the tool status as closing, not closed.

Metrics to track

MetricWhy it matters
Tools retiredShows whether the team can remove unused tools.
Tools with leftover usersShows access cleanup weakness.
Tools with leftover connectorsShows hidden source-system risk.
Tools with unresolved data retentionShows deletion and export gaps.
Tools with billing still activeShows wasted spend.
Average days to closeShows whether shutdown is operationally manageable.
Repeat shutdown blockersShows where policy, ownership, or admin controls need improvement.

If decommissioning repeatedly fails on the same connector type, review the allowlist and intake process.

Evidence checked

FAQ

Is canceling the subscription enough?

No. Cancellation may stop billing, but it does not prove that users, connectors, exports, transcripts, files, logs, bots, or source-system copies were removed.

Should we delete all data immediately?

Not always. Follow your approved retention, legal, privacy, customer, and accounting rules. The checklist is meant to force a recorded decision, not automatic deletion in every case.

What if the vendor does not support deletion?

Record the limitation, restrict future use, preserve the vendor response, and decide whether the tool can be approved again. Do not invent deletion proof.

Who owns decommissioning?

The business owner owns the decision. The admin owner removes access and settings. Source-system owners revoke connectors. The data owner handles retention and deletion. Finance closes billing.

What if users still need old outputs?

Move approved outputs into an approved internal system, record the owner and retention rule, and remove the tool access. Do not keep the tool alive only as an unmanaged archive.

How does this connect to the main checklist?

The Small Team AI Security Checklist defines the baseline controls. This decommissioning checklist proves those controls are closed when an AI tool leaves the environment.