checklist

Browser extension offboarding checklist

A practical offboarding checklist for removing AI browser extensions, OAuth grants, Chrome policies, password manager access, and sensitive-site permissions when employees leave or change roles.

Audience: Startup founders, IT owners, Google Workspace admins, operations leads, HR partners, and managers who need a repeatable browser-extension offboarding process Risk: Medium Evidence: Chrome Enterprise extension policies, Google Workspace third-party app access controls, Chrome extension management documentation, Google Account third-party app access controls, and Cybergiz extension allowlist templates

Bottom line

Browser extension offboarding is not just removing a Chrome extension. For AI extensions, you also need to revoke OAuth grants, remove role-based policy exceptions, check password manager and SSO exposure, and update the allowlist record so the same access is not silently inherited by the next employee.

Use this checklist for employee departures, contractors finishing work, role changes, failed extension reviews, and any incident where an AI extension had too much access.

Offboarding trigger matrix

TriggerRiskRequired action
Employee leaves companyHighRemove managed profile, extension access, OAuth grants, password manager access, and SaaS sessions.
Contractor finishes projectHighRemove extension exceptions, OAuth app grants, shared vault items, and project SaaS access.
Employee changes roleMediumRemove role-specific extensions and blocked-site exceptions that no longer apply.
Extension fails reviewHighMove extension to blocked status, remove from allowlist, revoke OAuth, and notify affected users.
Extension vendor changes owner or permissionsMedium to highRe-score, pause rollout, and remove access until reviewed.
Security incidentHighDisable extension, preserve evidence, revoke sessions, rotate exposed credentials, and update policy.
Device lost or unmanagedHighRevoke browser profile/session access and connected app grants immediately.

If the extension could read Gmail, Docs, Drive, CRM, source code, support tickets, password manager pages, or admin consoles, treat offboarding as a security control, not a paperwork task.

Pre-offboarding inventory

Before the last working day or access change, collect:

ItemWhy it matters
Employee or contractor nameTies evidence to HR or vendor record.
Role and teamDetermines which extensions and sites were allowed.
Browser profile typeManaged work profile, personal profile, contractor profile, or unmanaged browser.
Approved extensionsPull from the Browser Extension Allowlist template.
AI extensions installedInclude extension ID, vendor, version, and status.
OAuth or connected appsExtension may still access data after browser removal.
Password manager vaultsShared credentials and recovery access must be removed.
Sensitive sites usedGmail, Docs, Drive, CRM, helpdesk, GitHub, finance, HR, admin, production.
Devices and sessionsOffboarding fails if the browser session remains active elsewhere.
ExceptionsTime-limited extension exceptions must be closed or reassigned.

If you cannot inventory the browser reliably, start with account-level revocation: SSO sessions, Google Workspace access, OAuth grants, password manager access, and SaaS sessions.

Extension removal checklist

Run these steps for each departing employee or role change:

  1. Confirm the offboarding trigger and effective time.
  2. Identify all approved browser extensions assigned to the person or group.
  3. Remove the user from Chrome policy groups that allow role-specific AI extensions.
  4. Remove one-off extension policy exceptions.
  5. Confirm the extension is no longer force-installed for that user or group.
  6. Confirm blocked extensions remain blocked after the user leaves.
  7. Revoke extension-related OAuth grants and connected app access.
  8. Remove the user from vendor workspaces for AI browser tools.
  9. Remove shared password manager vault access.
  10. Revoke active browser, SSO, and SaaS sessions.
  11. Check whether the extension synced data to Gmail, Docs, Drive, CRM, Slack, Notion, GitHub, or helpdesk tools.
  12. Record completion in the Small Team AI Security Checklist.

Do not rely on uninstalling the extension alone. OAuth grants and vendor-side accounts can survive browser cleanup.

OAuth and connected apps

AI browser extensions often combine browser permissions with cloud account permissions. Check both layers:

LayerWhat to remove
Google Workspace third-party app accessRevoke or restrict apps that can access Gmail, Drive, Docs, Calendar, or profile data.
Individual Google Account accessRemove third-party access granted by the user where relevant.
Microsoft 365 connected appsRemove Graph/API app grants, Teams integrations, and SharePoint/OneDrive access.
CRM/helpdesk connected appsRevoke app tokens and integration user access.
Slack/Notion/project toolsRemove bot/app access and user-level authorizations.
Extension vendor accountRemove user from the vendor workspace and rotate shared API tokens.
Browser syncDisable or remove the managed profile/session on offboarded devices.

If the tool touched customer data, run the workflow through the AI Tool Risk Checker before reassigning access to another user.

Chrome policy cleanup

For managed Chrome environments, review these policy areas:

Policy areaOffboarding action
Extension install allowlistRemove the user or group from role-specific allowed extensions.
Extension install blocklistKeep blocked extensions blocked for future users.
ExtensionSettingsRemove per-user exceptions, force installs, runtime allowed hosts, and runtime blocked-host exceptions.
Force-installed extensionsConfirm only core managed tools remain force-installed.
Runtime allowed hostsRemove sensitive-site access that was granted for the old role.
Runtime blocked hostsConfirm identity, finance, HR, password manager, source-code, production, and customer-data sites stay blocked.
Managed profilesDisable or delete old work profiles on company-managed devices.
Pilot groupsRemove offboarded users from pilots and reassign ownership.

The cleanest process is group-based. If a role loses access by leaving a group, fewer manual policy exceptions survive offboarding.

Password manager and SSO review

Browser extension offboarding should include credential systems:

SystemCheck
Password managerRemove shared vault items, collections, emergency access, and admin roles.
SSO providerRevoke sessions, disable account, remove app assignments, and check MFA recovery methods.
Google Workspace or Microsoft 365Suspend or delete account according to retention policy and revoke third-party apps.
GitHub/GitLabRemove org/team access, deploy keys, personal access tokens, and browser extension access to source-code pages.
Payment and finance toolsRemove admin access and revoke sessions immediately.
Customer systemsRemove CRM/helpdesk/user-admin roles before reassigning accounts.
Device managementConfirm company device wipe, browser profile removal, or contractor device sign-out.

If an AI extension could run on password manager or SSO pages, use the Password managers and AI browser extensions playbook to decide whether credential rotation is needed.

Role-change checklist

Use a smaller version of offboarding when someone changes teams:

  1. Remove old team browser extension allowlist entries.
  2. Remove old Chrome policy group memberships.
  3. Remove old OAuth grants tied to the prior workflow.
  4. Remove old password manager shared vault access.
  5. Remove access to old CRM, helpdesk, source-code, HR, finance, or admin pages.
  6. Add new role extensions only after approval.
  7. Confirm runtime blocked hosts still cover sensitive sites.
  8. Record the new owner and renewal date in the allowlist.

Role changes are where stale extension access accumulates. Treat them like partial offboarding.

Evidence log

Record this for each offboarding event:

Browser extension offboarding record

Person:
Role or contractor project:
Trigger: Departure / Role change / Extension failed review / Incident / Device lost
Effective date:
Browser profile type:
Managed device:
Extensions removed:
Extension IDs:
Chrome policy groups removed:
OAuth grants revoked:
Vendor accounts removed:
Password manager access removed:
Sensitive systems checked:
Sessions revoked:
Credential rotation needed: Yes / No
Customer data exposure review needed: Yes / No
Owner:
Reviewer:
Completed date:
Follow-up date:

Keep the record lightweight, but make it specific enough that a future incident review can reconstruct what happened.

Failed review workflow

When an extension fails review:

StepAction
1Move the extension status to Blocked or Removed in the allowlist.
2Add the extension ID to policy blocklist or remove it from allowlist.
3Remove force-install or allowed-host policy entries.
4Revoke OAuth and connected app grants.
5Notify affected users with a short replacement workflow.
6Review whether the extension accessed Gmail, Docs, Drive, customer data, source code, or admin pages.
7Decide whether credential rotation or customer-data incident review is needed.
8Record why the extension failed and when it can be reconsidered.

Do not leave a failed extension in Pending. Pending is for unanswered questions. Failed review means blocked until something materially changes.

Evidence checked

FAQ

Is removing the employee account enough?

No. It helps, but browser extensions can also have vendor accounts, OAuth grants, synced browser profiles, local device state, and role-based policy exceptions. Check each layer.

Should we delete every extension during offboarding?

For a departing user, remove user-specific access. For a role change, remove only old-role extensions and exceptions. Company-wide approved extensions can remain if they are assigned through correct groups.

What is the most common mistake?

Forgetting connected app and OAuth access. A browser extension may no longer be installed, but the vendor or connected app may still have cloud access.

Do contractors need a different checklist?

Use the same checklist, but be stricter about end dates, project-specific groups, shared vault access, and unmanaged devices.

When should we rotate credentials?

Rotate credentials if an AI extension ran on password manager, SSO, admin, source-code, production, finance, or customer-data pages without approval, or if you cannot confirm what it accessed.

Add this offboarding record to your extension allowlist process. Then review one recent departure or role change and confirm extension access, OAuth grants, password manager access, and Chrome policy groups were actually removed.