Skip to main content
Tutorial

Runbook: Offboard a Team Member

Account: VITAG (Vitagen Labs)
Navigation: Configuration → Account → Users


When to Use This Runbook

Use when an employee, contractor, or external party no longer needs access to UltraCart — whether due to departure, role change, or end of contract. Prompt offboarding prevents unauthorized access and ensures open work is handed off.

Who handles this: Owner or account administrator.

Time to complete: 10–15 minutes.


Step 1: Reassign Open Tasks

Before deactivating the account, transfer any work assigned to this person.

  1. Go to Operations → Tasks

  2. In the Users filter, select the departing person's name

  3. Set Status filter to Open

  4. Review the list of open tasks

  5. Select all tasks (top checkbox)

  6. Click Batch Edit

  7. In the dialog, update Assign to → select the person's replacement or the owner

  8. Save

Do this before deactivating the account. Once deactivated, filtering by that user still works, but it's cleaner to do it while they're still an active user in the system.


Step 2: Check for Open CRM Conversations (If CRM Is Enabled)

If the person handled chat or phone support:

  1. Go to CRM → Conversations

  2. Filter by agent: select the departing person

  3. Review any open conversations — are there active customer threads that need handoff?

  4. Transfer or close each open conversation appropriately


Step 3: Deactivate the UltraCart Account

  1. Go to Configuration → Account → Users

  2. Find the departing person's user account

  3. Click Edit (or click their name)

  4. Find the Active toggle or Account Enabled checkbox

  5. Set it to Inactive / Disabled

  6. Save

Do not delete the account. Deactivating preserves the audit trail — their name remains on past tasks, orders they processed, and notes they added. Deletion would remove that history. Deactivated accounts cannot log in.


Step 4: Rotate Shared Credentials (If Any)

UltraCart accounts are individual — there are no shared UltraCart logins. However, check whether this person had access to any external accounts connected to UltraCart:

ServiceWhat to Change
Payment gateway (Stripe, Braintree, http://Authorize.Net )Remove their user access from the gateway dashboard; rotate API keys if they had access
Shipping accounts (UPS, FedEx, USPS/Stamps.com)Remove their user from the carrier account
Email provider (Klaviyo, Mailchimp, etc.)Remove their account from the ESP
Domain registrarRemove their user if they had DNS access
Hosting / SSLRemove if applicable
Google Analytics / GA4Remove their Google account from property access
Meta Business ManagerRemove from ad account access
Social media accountsChange passwords if they had direct login access
Any shared passwords stored in a password managerRotate those passwords

Critical: If this person had admin-level access to Stripe, Braintree, or your bank account, rotate credentials the same day they leave — not the following week.


Step 5: Cancel or Reassign Scheduled Reports

If the departing person was a recipient of any scheduled reports:

  1. Go to Operations → Reporting → Schedule Reports

  2. Review each scheduled report for their email address as a recipient

  3. Remove their email or replace it with the appropriate new recipient


Step 6: Update Order Task Generation Rules

If this person was assigned as the recipient for any automated task rules:

  1. Go to Configuration → Order Management → Order Task Generation

  2. Review each rule — check the "Assign to" field

  3. If any rule points to the departing person, update it to their replacement

  4. Save

See configure-order-task-rules.md for the full rule configuration.


Step 7: Remove from Chat Departments (If CRM Is Enabled)

If the person was a human chat or phone agent:

  1. Go to Configuration → Account → Users → [their account]

  2. Find their Conversations Chat Departments assignment

  3. Remove them from all departments

  4. In CRM → Calls → Settings → Agents (if phone agent), deactivate their agent profile and remove from all queues


Step 8: Confirm Access Is Removed

Have someone else (or use an incognito browser session) attempt to log in with the departing person's credentials. Confirm the login fails.

If they ever accessed UltraCart from a shared device, clear the browser's saved passwords or sessions for that device.


Offboarding Checklist

  • [ ] Open tasks reassigned to replacement or owner

  • [ ] Open CRM conversations reviewed and handed off (if CRM enabled)

  • [ ] UltraCart user account deactivated (not deleted)

  • [ ] Payment gateway access removed / API keys rotated

  • [ ] Shipping account access removed

  • [ ] Email provider access removed

  • [ ] Scheduled reports updated (remove their email from recipient lists)

  • [ ] Order Task Generation rules updated if they were assigned

  • [ ] Chat departments / call queues updated (if CRM agent)

  • [ ] Social media passwords changed (if they had direct access)

  • [ ] Login confirmed as non-functional after deactivation

Was this page helpful?