Administration
Export and delete an organization
Complete an operator-assisted organization exit without confusing active deletion, retained records, or backup expiry.
Who can perform the task
An organization administrator can prepare and verify customer exports. A named service operator and independent verifier perform organization deletion through the controlled exit procedure; there is no self-service delete-organization button in the first-customer product.
Before you begin
Obtain an authenticated exit request and approved retention decision. Confirm legal, audit, litigation, regulator, invoice/tax/bank, incident, and backup requirements. Record separate dates for export review, active service deletion, and backup expiry. Unresolved scope or dates block deletion.
Quick path
- Stop new filing work and confirm who is authorized to approve the organization exit.
- Export the organization data and reconcile the delivered files.
- Resolve billing, retention, legal-hold, backup, and active-access obligations.
- Request the operator-assisted deletion and retain its reference.
- Verify the deletion outcome and any records or backups that remain under a documented retention rule.
Detailed guidance
- Revoke pending invitations and stop schedules, reminders, ingestion, new billing, and other writes.
- Create a fresh encrypted portable bundle for every filing. Store each unique passphrase separately and record bundle and taxonomy checksums.
- Download required artifacts, attachments, review/approval evidence, authority receipts, invoices, and reconciliation evidence.
- Restore a representative bundle sample in a clean approved environment and verify entity, period, values, attachments, audit sequence, snapshot, and regenerated export.
- Confirm the approved accounting archive contains financial records that must outlive the active SaaS copy.
- Ask the operator to generate the read-only organization inventory. Review its counts, artifact checks, active jobs, and checksum.
- After the approved waiting date, give the operator explicit confirmation of the exact organization ID, verified export, financial archive, deletion reason, and backup-expiry date.
- Retain the value-safe deletion receipt and later backup-expiry evidence.
Expected result
All database-referenced organization objects are checksum-verified and removed before the exact unchanged organization rows. A changed inventory, active job, missing object, failed checksum, incomplete confirmation, or invalid backup date stops deletion. Operator-wide regulatory and approved accounting/bank records remain only under their separate retention policies.
How to verify
Confirm the organization, filings, jobs, downloads, calendar entries, billing views, and artifacts are unavailable. Confirm the deletion receipt says active data was deleted but backups remain pending until the recorded expiry date. After that date, obtain independent storage/key-destruction evidence.
Important limitations
- A portable bundle is customer data and remains subject to retention/deletion.
- Authority portals and recipients are outside the product deletion boundary.
- Active deletion does not erase an independent backup immediately.
- The product cannot determine statutory retention periods.
- Organization deletion is operator-assisted for the first 10 customers; enterprise self-service administration remains deferred.