When Your Account Manager Quits: Revoking Access to HubSpot, Intercom, and Customer-Facing Tools
When a CS rep or account manager leaves, their access to HubSpot, Intercom, Zendesk, Calendly, and Gong doesn't disappear. Here's how to revoke it the same day they leave.
When Your Account Manager Quits: Revoking Access to HubSpot, Intercom, and Customer-Facing Tools
When a developer leaves, you hunt down API keys. When a designer leaves, you revoke Figma. But when your account manager or CS rep quits, you're sitting on a different kind of exposure: they have access to your customer relationships, inbox conversations, call recordings, and contact data. HubSpot, Intercom, Zendesk, Calendly, Gong — none of these revoke access automatically when someone exits. Here's how to clean it up the same day they leave.
Why CS Tool Access Is the Highest-Risk Offboarding Category
If your startup has a customer success function — even one person covering 20 accounts — you've got a CS tool stack holding your most sensitive relationship data. A departing rep's HubSpot seat doesn't disappear when they hand in their laptop. Their Intercom inbox assignments stay active. Their Calendly scheduling links keep working. Their Gong call recordings include conversations you've never reviewed.
This isn't theoretical: 90% of companies have found former employees still accessing SaaS applications after their departure date. CS tools are particularly risky because the blast radius isn't your codebase — it's your customer relationships. A former rep with active HubSpot access can export your entire contact database. An active Intercom user account means someone outside your company can message your customers directly. For the full picture of how tool access accumulates across a team, see SaaS access sprawl at startups.
The CS Tool Stack That Survives Offboarding
Most early-stage startup CS stacks look like this:
- CRM: HubSpot (Sales + Service Hub) or Salesforce
- Customer messaging: Intercom, Drift, or Zendesk
- Scheduling: Calendly with embedded booking links
- Call recording: Gong, Chorus, or Loom
- Customer success platform: ChurnZero, Gainsight, or Totango (if you're past 50 accounts)
- Customer-shared docs: Notion pages with external sharing enabled
- Support inbox: Help Scout, Freshdesk, or Front
Every one of these can persist access after an employee exits. Unlike Slack or Google Workspace — which founders remember to revoke — these tools are easy to overlook in the offboarding rush. A common pattern: the founder kills the Google account, assumes access is gone, and doesn't realize HubSpot, Intercom, and Calendly authenticate independently.
HubSpot: The Two-Step You Can't Skip
HubSpot offboarding is a two-step process that many ops leads get wrong.
Step 1: Deactivate first. Go to Settings → Users & Teams → find the user → Deactivate. This immediately blocks login. Do not delete the user yet.
Step 2: Transfer ownership, then remove. Before deleting, transfer all owned contacts, companies, deals, and tickets to another team member. If you delete without transferring, you orphan their CRM records — contacts with no owner, deals stuck in pipeline.
Additional HubSpot-specific checks that most founders miss:
- Email integration: If the rep connected their Gmail or Outlook to HubSpot, deactivating in HubSpot doesn't revoke OAuth access on the email side. Revoke HubSpot's OAuth permission from the rep's Google or Microsoft account directly.
- Active sequences: Any enrolled sequences the rep was running keep firing after deactivation until you explicitly stop them. Check Automation → Sequences → Active.
- Super admin status: If the rep had super admin access (common at early stage when "everyone is an admin"), strip this before deactivating. Super admins can restore their own access.
Intercom: Seats, Conversations, and the Assignment Limbo Problem
Intercom is messier than HubSpot for offboarding because conversations are assigned to individual reps.
Remove the teammate: Settings → Teammates → deactivate the teammate. This removes login access immediately.
Reassign open conversations before or immediately after deactivation. Go to the Inbox and filter for conversations assigned to that teammate. Reassign to active teammates or a team inbox. Conversations assigned to a deactivated teammate fall into limbo — customers reply, nobody sees it.
Intercom-specific risks beyond the obvious:
- Automated workflows: If the departing rep built Intercom Series (automated message sequences), Resolution Bot configurations, or Fin AI custom answers, those continue running under their name. Review the Messenger settings and automation list.
- API keys: Intercom users can generate personal API keys under their profile. These survive deactivation. Check Settings → Developers → API Keys and revoke any tied to their account.
- Help Center articles: Articles authored by the rep remain published and attributed. No security risk, but consider reassigning authorship if they wrote customer-facing documentation.
Zendesk: Tickets, Macros, and Suspension Order
Zendesk uses a suspend-then-reassign flow similar to Intercom.
Suspend first: Admin → People → select agent → Suspend. This blocks new ticket assignments while keeping their ticket history intact for audit purposes.
Reassign open and pending tickets. Filter by agent in the Zendesk view and bulk reassign. Zendesk will surface a warning showing open ticket count during suspension — don't dismiss it without resolving those tickets.
Two Zendesk-specific points worth noting:
- Macros: If the agent built personal macros with your response templates, those become inaccessible after suspension and removal. Before removing the user, export any useful macros and convert them to shared macros.
- Multiple products: If you use Zendesk Sell alongside Support, these are separate seat licenses with separate user management. Suspending in Support does not suspend in Sell. Revoke access in both products separately.
The Long Tail: Calendly, Gong, Loom, and Customer-Shared Docs
These are the tools that get missed because they feel peripheral — but each carries real risk.
Calendly: A departing rep's Calendly links remain active and bookable after they leave. Customers clicking "Book a call with [Name]" will book a calendar that's no longer monitored. Remove the rep from your Calendly team: Team → Members → remove. Then check for any embedded booking links on your website or in email signatures that still route to their profile.
Gong and Chorus: Call recording platforms capture every customer conversation, including strategic discussions, pricing negotiations, and implementation calls. Remove the user from the workspace directly — don't rely on SSO revocation alone. If the rep ever generated a Gong-specific password (non-SSO login), that credential survives IDP suspension.
Loom: If the rep shared Loom videos with customers (product demos, onboarding walkthroughs), those videos stay live unless you transfer workspace ownership. Remove them from the workspace under Workspace → Members.
Notion with external sharing: If your CS team uses Notion for customer-shared documents — shared roadmaps, onboarding portals, or SOPs — audit which pages were shared externally. Removing the rep's Notion membership doesn't revoke access for external guests they invited. Review those pages' sharing settings manually.
Running CS Tool Offboarding in One Session
Here's the sequence that handles a typical startup CS stack in under 30 minutes:
1. HubSpot/CRM (15 min):
- Stop all active sequences enrolled to the departing rep
- Deactivate the user (not delete yet)
- Transfer all owned contacts, companies, deals, and tickets
- Strip super admin status if applicable
- Revoke email OAuth from rep's Google/Microsoft account
- Then delete the user from HubSpot
2. Customer messaging — Intercom/Zendesk (8 min):
- Deactivate/suspend the user
- Reassign all open conversations and tickets to active teammates
- Check for and revoke any personal API keys
3. Call recording — Gong/Chorus/Loom (3 min):
- Remove user from workspace in each tool
- Confirm removal is direct, not just SSO-dependent
4. Calendly (2 min):
- Remove from team
- Update or remove any embedded booking links on website or email signatures
5. Notion and shared docs (2 min):
- Remove rep from Notion workspace
- Audit customer-shared pages and remove external guest access where the rep was the inviting party
After completing the sequence: run a search in HubSpot for any sequence emails that fired after the departure date. If any went out from the rep's account post-exit, decide whether to send a follow-up from a current team member.
Build the Checklist Before You Need It
The real cost of CS tool offboarding isn't the 30 minutes you spend doing it — it's the week you spend figuring out what needs to be done after someone has already left. The typical scenario: founder kills the Google account, assumes access is gone, then discovers three months later that HubSpot sequences were still running under the former rep's name.
The fix is a role-specific tool map. Before anyone starts in a CS role, document every tool they'll be provisioned with. That list is your offboarding checklist when they leave. If you're already using an access lifecycle platform, role-based access templates are the mechanism — define what a CS rep gets on day one, and the same template drives the exit sequence.
Optserv ties your tool connections directly to employee records. When you trigger an offboarding flow for a CS rep, it walks you through every tool they were provisioned with — including the ones your ops lead didn't add to the manual checklist. The CS tool stack (HubSpot, Intercom, Calendly, Gong) is part of a role template, so when that role exits, the revocation checklist is already scoped. Start an Optserv trial at app.optserv.ai/signup — there's a free tier that covers teams up to 10 people.
FAQ
Does deactivating a HubSpot user revoke their email integration automatically?
No. Deactivating in HubSpot blocks HubSpot login, but if the rep connected their Gmail or Outlook to HubSpot, that OAuth connection persists in their email account. Revoke HubSpot's OAuth permission directly from the rep's Google (myaccount.google.com → Security → Third-party apps) or Microsoft account settings.
What happens to Calendly meetings already booked with a departing rep?
Existing bookings remain on the calendar unless you cancel them. Remove the rep from Calendly, then check their calendar for any future bookings that need to be reassigned or cancelled. Reach out to those customers proactively — a missed meeting from an employee no longer at the company is a customer experience failure.
Can a deactivated Intercom user still see customer conversations?
A deactivated Intercom teammate cannot log in through the normal UI. However, if they previously generated API tokens tied to their Intercom account, those tokens remain active. Always check Intercom's API Keys settings and revoke any found after deactivation.
Is there a risk with Gong if I only suspend the employee's SSO identity?
Yes. If your Gong access goes through Google Workspace or Okta SSO, suspending the IDP account blocks SSO login. But if the rep ever set a Gong-specific password (non-SSO path, sometimes set during initial onboarding before SSO was configured), that credential still works. Always deprovision directly in Gong in addition to the IDP.
How do I handle customer-shared Notion docs when a CS rep leaves?
Remove the rep from your Notion workspace: Settings → Members → remove. This removes their editing access to all workspace pages. But external guests they personally invited — customers given guest access to shared Notion pages — retain that access until you manually remove them from those specific pages. Go through any pages the rep managed and audit the "Share" settings on each.
Sources
- How to Automate Access Revocation During Employee Offboarding — InvGate
- Employee Offboarding: Guide to Secure Access Revocation in 2026 — Passwork
- Remove HubSpot Users — Knowledge Base — HubSpot
- Intercom vs HubSpot Service Hub 2026: The Operations Lead's Guide — ClonePartner
- Secure & Seamless Employee Offboarding: A Complete Access-Centric Guide — SecureEnds
Run your entire team from one place.
Optserv handles hiring, onboarding, access management, and offboarding — built for startups that want to operate like grown-ups without the enterprise overhead.
Try Optserv free