Before You Cancel a SaaS Tool: Twelve Things to Capture

The Admin console goes first. Not the mailboxes and not the files — the console.

Google's page on cancelling a Workspace subscription for Gmail accounts puts it in one clause: with either cancellation option "you lose access to premium Google Workspace services, your Admin console, and any billing records right away" (Google Workspace admin help, checked 21 August 2026). Right away, meaning before the grace period everybody plans around has started counting.

That one sentence reorders the whole job. Pre-cancel advice is mostly about records, because records are the part with an export button. The items below are the other kind: they live in an admin screen, and admin screens close first. Twelve of them, each with the thing you lose when it is missing.

Three clocks, and only one of them is the one you were told about

First the timing, because every item below is governed by whichever of these runs out soonest.

The access clock starts the moment you cancel and can be zero. Admin console, billing pages, audit search — gone with the role, not with the data.

The readable clock is the grace period. Atlassian's documentation says that after the subscription period ends "you'll be able to access your site for 15 more days", the site is then deactivated, and app data enters a retention period of 60 days on Free, Standard, Premium and Enterprise plans, or 15 days on a trial. The same page notes that a failed payment gets you unsubscribed after 15 days, which starts the identical sequence without anybody clicking anything (Atlassian Support, checked 21 August 2026).

The deletion clock is the vendor's own. Zendesk's Service Data Deletion Policy says an automated process that permanently deletes Service Data commences ninety days after an account is cancelled or terminated, then runs over different periods per product: roughly 40 days for Ticketing and Help Center, 120 for Live Chat and Messaging (Zendesk, checked 21 August 2026).

Fifteen days, ninety days, immediately. Same question, three unrelated answers — which is why the last two items on this list are dates rather than files.

The four that are the data, in the sense a lawyer would mean

1. The attachments themselves, downloaded, with a manifest beside them. An export that hands over links rather than files is not one job finished but two started, and the second one is already running against a clock the first one set. Notion's developer documentation gives the tightest version of that clock a number: a file url returned by the API "is a temporary signed link that expires after 1 hour. Re-fetch the page to refresh it" (Notion API docs, checked 21 August 2026). So the fetch belongs in the same sitting as the export, not on the following Tuesday. Write the manifest as you go — path and byte size per file — because a directory of empty files and a directory of real ones look identical in a file browser. Why exports get built to pass addresses around in the first place is the third of five design choices that make a tool expensive to leave; which parts of a Slack archive are links on which plan is in what a Slack export actually contains. Without it: a two-year-old thread that reads perfectly and a paperclip icon that returns nothing, found by a colleague on the day they needed the file.

2. The user and permission list. Every account, with email, role, licence, last login, and a flag on whoever holds owner and billing rights. A CSV, not a screenshot, because you will want to sort it. Without it: no way to answer "who could see the client folder in March", and no way to rebuild roles in the new tool except by asking people what they think they had.

3. The audit log, or as much of it as your tier gives you. These expire on their own schedule, while the account is still open. Google's admin documentation lists most Workspace audit logs as retained for 6 months, with email log search and the Meet quality tool at 30 days, the Chrome apps-and-extension usage report and the Chrome version report at 12 months, the usage API at 15 months, and Vault logs indefinite (Google Workspace admin help, checked 21 August 2026). Microsoft's audit retention page sets Audit (Standard) at 180 days for records generated on or after 17 October 2023 and 90 days for anything earlier. The Audit (Premium) default policy holds Exchange Online, SharePoint, OneDrive and Microsoft Entra records for one year — but only for activity by users licensed for it, since the page adds that where an organisation has "non-E5 users or guest users, their corresponding audit records are retained for 180 days" (Microsoft Learn, checked 21 August 2026). Without it: no answer to "when was that changed, and by whom" — the question a disputed invoice or a departed employee produces about four months after you stopped paying.

4. Billing history and receipts, as PDFs. See the sentence at the top of this page. The billing screen sits behind the admin role, and cancelling removes the admin role. Without it: no way to produce one specific invoice for one specific month, which is not a migration inconvenience but a hole in the accounting — the shape of that duty is set out in records you still have to produce after you cancel.

The four that are wiring, and have no export button at all

5. API keys, tokens, and the registered webhook receivers. Two lists. The keys you capture not to reuse but to locate — server variables, an automation platform, a colleague's script, an app authorised in 2024. The receivers, because they keep firing. Stripe's webhook documentation says you can register up to 16 event destinations per account, that Stripe "attempts to deliver events to your destination for up to three days with an exponential back off in live mode", that a manual resend works for 15 days from the Dashboard and 30 through the CLI, and — the detail that catches people mid-migration — that a 3xx redirect counts as a failure (Stripe docs, checked 21 August 2026). Without it: three days of events posted at a URL that now redirects, expiring quietly while everyone is congratulating each other on the cutover.

6. An inventory of every external system the integrations touch. The connected-apps page and the OAuth grant list, captured as images and as a typed list, including apps you did not install and cannot identify. The ones nobody writes down are the ones that surface as a renewal charge in March for a tool nobody can name — or, less comfortably, as a third party still holding a live token against a system nobody is watching any more.

7. Custom field and workflow definitions. Not the values. The schema: field label, internal ID or API name, type, whether it is required, and the full option list for every dropdown. Then the automation logic, which almost never has a file format, so it gets screenshotted and written out in sentences. Without it: fields that look identical in the new tool and are not, because a status dropdown quietly lost two options nobody used often enough to remember.

8. Email forwarding, aliases and domain settings. MX, SPF, DKIM and DMARC records copied as plain text from your DNS host rather than from memory, plus forwarding rules, shared mailbox members, catch-all behaviour and every address that exists only as an alias. Without it: mail to an address you forgot about bouncing to a sender who will not tell you it bounced. Longest gap between cause and discovery of anything on this list.

The two that other people are holding

9. Shared links and external guests. Every publicly shared document, client portal URL, embedded view and guest account, listed with who is on the other end of it. Some of these are bookmarks in a customer's browser, which means the customer, not you, is the monitoring system, and the way the omission surfaces is a client opening a dead link on a Monday morning — followed by the separate discovery that a guest from a project finished in 2024 still had access to something.

10. Support ticket history. Your correspondence with the vendor contains the workaround an engineer gave you, the confirmation that a limit was raised for your account, and the date you first reported the bug that is about to become an argument. Print each thread that matters to PDF while your login still works. If the help desk is itself what you are leaving, the Zendesk figures above are the clock. Without it: a promise that was made in writing and now exists only in your memory of it.

The two dates, which are not files

11. The retention window and the actual deletion date. Not "about 90 days". A date, the sentence in vendor documentation that produced it, the URL, and the day you read it — vendors revise these pages without announcement. Without it: planning around a grace period the vendor never offered — as the 15, 60 and 90 day figures show, being wrong by a factor of six is ordinary.

12. The contractual last billing cycle. Which day the term genuinely ends, whether notice was required before it, and whether the final invoice is prepaid and non-refundable. Google's page states the two shapes plainly: on the Flexible Plan "you're charged for the days you used the service", and on an annual or fixed-term plan "you're charged for the remaining balance of your commitment, if you have one" (Google Workspace admin help, checked 21 August 2026). Treat that date as the same one the access ends on and you pay to the end of the commitment anyway while surrendering the console on day one — the worst of the available combinations, and the one a fortnight of patience would have avoided.

The format each of these has to be in, and where it goes

A capture nobody can open is not a capture. Formats, per item:

Item Capture as Why that format
Files and attachments The files in a folder tree, plus a manifest of path and size Links expire; folders do not
User and permission list CSV You will sort it while rebuilding roles
Audit log CSV or JSON, one month at a time Full-period exports time out
Billing history One PDF per invoice, YYYY-MM_vendor_invoice.pdf It goes to whoever does your accounts
Keys and webhook receivers Plain text in a password manager, never shared storage It is a secrets inventory
Connected apps PNG screenshots plus a typed list The typed list is the searchable part
Field and workflow definitions CSV for the schema, PNG plus prose for the logic Logic has no interchange format
DNS and mail routing Dated plain text from dig or nslookup Records what was set, not what you meant
Shared links and guests CSV with URL, audience and expiry Becomes the redirect list for the new system
Support tickets One PDF per thread Readable by someone with no account
Retention and billing dates One text file with source URL and date read Two dates, two citations, no ambiguity

One folder per vendor. Name it vendorname_capture_2026-08-21, put a README.txt at the top listing what is inside and what you failed to get, and store it somewhere that is neither the tool you are leaving nor the tool you are moving into — an archive living inside a SaaS account has exactly the problem you are currently solving. Keep checksums for the file tree if nothing else — it is the item most likely to be silently incomplete.

Do all of it while the account is open and paid. Everything above is free then, and several items become impossible thirty seconds after the cancellation confirms. The 30-day switch runbook covers the order the rest of the switch happens in; this list belongs before its last step.


Verified against Google Workspace, Microsoft, Atlassian, Zendesk, Notion and Stripe documentation on 21 August 2026, at the pages linked above. Six vendors appear here for one reason: each one publishes the behaviour in its own words, at a URL you can open yourself. None of them is being recommended and none is being warned against — a company that documents its deletion clock is easier to leave than one that documents nothing, which is the opposite of a mark against it. Every figure above belongs to a named product and a named licence tier, so open the linked page for the tier you actually pay for. And read the date before the number: these pages get rewritten without a changelog, which is the whole reason the date is on them. Corrections reach me through the contact form and go up with a new verification date; why every page is built and dated that way is on the about page.

Frequently asked questions

What should I export before cancelling a subscription?

More than the records. The records are the part with an export button, so they are the part people remember. The twelve items on this page are mostly the ones with no export button at all: the user and permission list, the audit log, the billing history, the registered webhook receivers, the custom field definitions, the DNS and mail routing, the shared links held by people outside your company, and the support ticket history. Each of those lives in an admin screen, and admin screens are frequently the first thing that closes.

Do I get a grace period after cancelling to download my data?

Sometimes, and the length is not consistent enough to guess at. Atlassian's documentation says you can access your site for 15 more days after the subscription period ends, after which the site is deactivated and app data enters a retention period of 60 days on Free, Standard, Premium and Enterprise plans, or 15 days on a trial. Zendesk's Service Data Deletion Policy says the deletion process begins 90 days after an account is cancelled or terminated. Google's cancellation page for Workspace says you lose the Admin console and any billing records right away. Three vendors, three different shapes, all checked 21 August 2026. Read your own and write the date down.

Can I get my invoices back after the account closes?

Often not from the vendor's interface, because billing screens usually sit behind the same admin role that cancellation removes. Google's own page on cancelling Workspace for Gmail accounts says that with either cancellation option you lose access to the Admin console and any billing records right away, checked 21 August 2026. Download every invoice and receipt as a PDF while you can still log in, and file them with your accounting records rather than in a folder named after the tool.

Why capture API keys if I am about to stop using the tool?

You are not capturing the key so you can use it. You are capturing the list so you can find every place it was pasted: server environment variables, an automation platform, a colleague's script, a third-party app authorised two years ago. Vendors normally show a secret key once and never again, so the inventory has to be built while the account is open. The same applies to registered webhook endpoints, which will otherwise keep firing at a URL nobody owns.