Retention without the Archived User bill
Export from Vault, verify the copy, delete the account, and reclaim the license, all within your retention requirements.
Three facts most IT teams haven't added up
Archiving feels like the safe default, and deleting a user feels risky. Here is what that default costs.
Suspended accounts bill at the full rate
Suspending a former employee stops sign-in, not the invoice. On Annual and Flexible plans, a suspended account is billed at the same rate as an active one.
Archived accounts bill for the whole retention period
Each archived account needs an Archived User license for as long as it stays archived. A seven-year retention period means a seven-year bill for every departure.
Deleting removes the data from Vault
Deleting a user removes their data from Vault and ends retention rules and holds on it. That is why most teams never delete anything.
Sources from Google: suspended accounts are billed the same as active accounts, archiving assigns an Archived User license, and deleting a user removes their data from Vault.
Departures stack up for the whole retention period
Take 150 departures a year and a seven-year retention period. By year seven that is about 1,050 archived accounts, each with its own Archived User license. In a 1,000-person organization, that is more archived accounts than people.
Illustrative arithmetic, not a measurement: 150 departures a year multiplied by seven years. The headcount line is an example.
Estimate what you could reclaim
Pick your Google Workspace edition or enter your own rate. The result updates as you type, and we don't ask for your email.
Enter your archived accounts and your monthly rate to see a result.
Add departures per year and a retention period to see how the bill grows.
The result uses only the numbers you enter. List prices come from Google's add-ons page, and the growth figures are illustrative arithmetic, not a measurement. Whether a saving shows up right away depends on your plan, and on Annual plans license changes often apply at renewal.
Export, verify, delete, reclaim
-
1
Export from Vault
Run the Vault export for Gmail, Drive, and the other services in scope.
-
2
Copy to your own storage
Move the files to your Google Cloud Storage or AWS S3 bucket. Vault export files are available for 15 days from when the export starts.
-
3
Verify and log
Check the counts against the search preview, then record what was exported, by whom, and where it lives.
-
4
Delete and reclaim
Delete the account and reclaim the license. Accounts under a legal hold stay archived.
Source from Google: export files are available for 15 days after the export starts.
What a verified export has to show
A copy only counts if you can prove it is whole and that you can find things in it. A verified export shows five things.
Complete
The counts match the Vault search preview.
Intact
The files open and match after the copy.
Secure
It sits in your own bucket, with access limited to the people who need it.
Retrievable
Someone can find and open a message when it is requested.
Governed
A log shows who exported what, when, and where it lives.
How the metadata search works
Each export comes with a metadata file that lists the sender, subject, and date of every message. Load it into an index in your own storage and your team can search by sender, subject, and date, then open the matching file. It is not the Vault interface, and it does not replace Vault search for accounts that stay archived.
Who stays archived, who gets exported
| Stays archived | Gets exported, then deleted |
|---|---|
| Accounts under a legal hold | Former employees with no hold, once the export is verified |
| Accounts where a regulation prescribes a specific storage system | Accounts where a verified export in your own storage meets your retention requirement |
| Data you still need to search in Vault | Accounts kept only to wait out a retention period |
Confirm the final call with your compliance team. Some regulations prescribe specific storage systems, and an export in your own bucket may not satisfy them.
A workflow your team builds and runs
Teams build this workflow in Zenphi without code. It starts from a form, a Google Directory event, or an offboarding flow. It creates the Vault export, checks the status until it completes, copies every file to your bucket, and writes each step to the run history.
- Create Export, List Exports, and Find Export actions handle the Vault side.
- A loop waits for the export and copies each file to Google Cloud Storage or Amazon S3.
- An approval step in Gmail or Google Chat can sit before the account is deleted.
- Every step lands in the run history, so the audit trail is a by-product.
Read the Google Vault export guide →
Compare suspend, archive, delete, and export →
See your own numbers before you change anything
Book a free account audit and we will look at how your former-employee accounts are set up. We flag four things:
Suspended accounts that are still billed at the full rate
Archived accounts that may no longer need an Archived User license
Accounts under a legal hold that must stay archived
Departed users with no verified export yet
Archived User licenses: common questions
What do Archived User licenses cost?
Google lists Archived User licenses at $2 per user per month for Business Starter, $3 for Business Standard, $4 for Business Plus, $5 for Enterprise Standard, and $7 for Enterprise Plus. Your contracted rate may differ if you buy through a reseller, so check the billing page in your Admin console. What matters more is the count: each archived account needs an Archived User license for as long as it stays archived, so the bill grows with every departure you keep. The calculator on this page presets these list prices by edition, and you can type your own rate instead. Teams build a workflow in Zenphi that exports the data, verifies the copy, and deletes the account, so the license is released.
Can I delete a user and keep their data?
Not in Vault. Deleting a user removes their data from Vault and ends retention rules and holds on it. What you can do is export the data first, copy it to your own storage, verify it, and then delete the account. Teams build that export, verify, delete sequence as one workflow in Zenphi, so the delete step waits for the verification.
Does exported data still meet retention requirements?
Often, when the export is verified: complete, intact, secure, retrievable, and governed. Whether it satisfies your specific rules depends on the regulation, because some prescribe particular storage systems, so confirm with your compliance team first. Accounts under a legal hold stay archived. Zenphi logs each step of the export, so you have the record to show them.
How do exports stay searchable?
Each export comes with a metadata file that lists the sender, subject, and date of every message. Load it into an index in your own storage, search by those fields, and open the matching file. It is not the Vault interface. A Zenphi workflow can write that metadata to a Google Sheet or a Zenphi table as part of the same flow.
Which accounts should stay archived?
Accounts under a legal hold stay archived. So do accounts where a regulation prescribes a specific storage system, and data you still need to search in Vault. Everything else is a candidate for export, then deletion. In Zenphi you can add a hold check before the delete step, so those accounts are skipped.
What does Zenphi cost?
Zenphi plans are based on workflow packages, not users or runs. Each tier includes a number of workflows, and there is no charge per user or per flow run, so a cleanup workflow that processes hundreds of accounts does not cost more per account. See the Zenphi pricing page for the current packages.