Short answer
Offboarding a CRM user is a two-stage job in both Salesforce and HubSpot: stop access on day one (freeze in Salesforce, deactivate in HubSpot), then reassign ownership, blocking roles, scheduling pages and tokens before final deactivation or removal. Keep users inactive rather than deleted so the record trail survives.
Why this is a two-system, two-stage job
Both platforms separate "stop access now" from "clean up ownership later", and both block or punish you if you do them in the wrong order. Salesforce lets you freeze a user to stop logins immediately while you fix the things that block deactivation, and deactivation rather than deletion is the end state so history is kept. HubSpot requires a user to be deactivated before they can be removed, and removal cannot be undone.
For a regulated firm, the first stage is a security control with a same-day target, and the second stage is a supervision and recordkeeping task that should be complete within the notice period.
Stage 1: same day as notice (both systems)
- Confirm the leaver's identity records: Salesforce username, HubSpot login email, SSO identity and any integration or API credentials tied to them.
- Disable the identity in your SSO provider first so every connected app is covered.
- In Salesforce, open the user record and click Freeze. Freezing stops logins but keeps the license and ownership intact, which is what you want for now.
- In HubSpot, deactivate the user from Users and Teams (Super Admin required). The user loses login and notifications within about five minutes, their individual connected inbox is disconnected, and their paid seat stays assigned but no longer counts toward the seat total. Team inboxes stay connected.
- Rotate any personal access tokens, private app tokens or connected-app secrets the person created. In HubSpot, a private app created by a removed user can start failing with permission errors, so plan the replacement now.
- Export the person's open work: open opportunities and deals, open tasks and cases, scheduled sequence emails, and upcoming meetings.
Stage 2: Salesforce ownership and deactivation
- Check the list of roles that block deactivation: default lead owner, default or automated case owner, default lead creator, default workflow user, workflow email alert recipient, custom hierarchy field selection, and customer portal administrator. Reassign each one.
- Remove the user from every approval process or reassign their approval responsibilities. Salesforce requires this before deactivation.
- Transfer record ownership. Use Mass Transfer Records for accounts, leads, service contracts and custom objects; handle opportunities, cases and contacts according to your reassignment plan. Records the user owns stay with them until you move them.
- Reassign ownership of reports, dashboards, list views, email templates, Chatter groups and scheduled jobs. Deactivated users still appear in public groups, default account teams and sales teams until you edit those.
- Review Einstein Activity Capture and email integration settings so the person's captured activity remains visible to the right supervisor.
- Deactivate: edit the user, clear the Active checkbox, save. This releases the license. Keep the record; don't attempt deletion.
- Record the date, who did it, and where ownership went.
Stage 3: HubSpot ownership and removal
- Reassign records they own (contacts, companies, deals, tickets). Records left behind show "Deactivated/Removed" with the user's email in the owner property.
- Remove them from workflows and filters: rotate owner actions skip deactivated users, but workflows triggered by meeting bookings with that user stop working, and any workflow or list that uses them as criteria needs editing by hand.
- Clean up scheduling. Take them out of group and round robin pages and meeting rotations, otherwise meetings can keep being booked with someone who is never notified. The default meeting link can't be deleted or transferred, so the user turns off their scheduling pages before leaving, or you remove the user after deactivation (removal deletes their scheduling pages).
- Have them share sales templates before removal, or they stay inaccessible to the team. Sequences, documents and templates otherwise remain in the account.
- Remove Account and Billing roles. A points-of-contact holder must be removed from the role, and a Primary Account Contact replaced, before removal.
- Reassign the paid seat when prompted during removal.
- Remove the user from the account only after ownership and assets are reassigned. Removal is permanent; the created assets stay, attributed to "Deactivated/Removed".
- Delete the blog author profile if one exists and reconnect any social accounts they administered.
Stage 4: compliance close-out
- Confirm supervised communications (email, chat, text) tied to the person are in the archive and that the supervisor of record has access.
- Note any client records with open complaints, in-flight approvals or pending suitability reviews, and name the new owner on each.
- Update the system of record standard and the integration user inventory if the person held any shared credential.
- File the completed checklist with the HR offboarding record. Both platforms keep the user as inactive, which is the evidence trail you want.
Timing we recommend
| Step | Target |
|---|---|
| SSO disabled, Salesforce frozen, HubSpot deactivated | Same day as notice |
| Tokens rotated, open work exported | Within 1 business day |
| Ownership and blocking roles reassigned | Within 5 business days |
| Salesforce deactivated, HubSpot removed | Within 10 business days |
| Compliance close-out filed | Within 10 business days |
Official documentation
Frequently asked questions
Why can't I deactivate a Salesforce user even though they've left?
Salesforce blocks deactivation while the user is still a default lead owner, default or automated case owner, default lead creator, default workflow user, a workflow email alert recipient, selected in a custom hierarchy field, or a customer portal administrator. Approvers must also be removed from approval processes first. Freeze the user to stop logins right away, reassign each of those roles, then deactivate. Freezing alone does not release the license.
Should we remove a HubSpot user or just deactivate them?
Deactivate first, always. Deactivation stops login, disconnects their personal inbox and skips them in owner rotation, but keeps their profile for reporting and can be reversed. Removal deletes the profile and their scheduling pages, unassigns their conversations, and cannot be undone. Remove only after records, assets, seats and billing roles have been reassigned, and keep a note of the date for your offboarding file.
Salesforce, HubSpot, Anthropic and OpenAI change their products often. Check the official documentation before you rely on a specific setting, limit or price.
