Agent-readable docs index: /llms.txt. Full docs in one file: /llms-full.txt. Download /docs.zip to grep all markdown files locally.

When someone leaves

  1. If they are an admin who made trust rules that should stay, renew those first, so they become yours: removing someone deletes their rules, and a new rule has a new ID.
  2. On the organization's Members page, in the sidebar, remove them. That removes them from the organization: every project at once, the API tokens, machine tokens and trust rules they created there, and their open invitations. Auto-join doesn't add them back, and neither does an invite link made before; only a new invitation does. See change roles and remove people.
  3. Take their address off the sign-in allowlist if it's listed, and remove them from your Google Workspace.
  4. Rotate the secrets they could read. They may have copies. In protected environments, History → Reads shows which values they read.
  5. If they could reach the Cloudflare account, or knew the passphrase of selfhost.json, remove their account membership, choose a new passphrase (self-host --change-passphrase), and rotate the secrets of every environment. A new passphrase doesn't lock them out of a copy of the file they already have, so the secrets have to change. Give the instance a new encryption key too (self-host --rotate-key), so a copy of the database taken later doesn't open with the key they know. self-host can't rotate BETTER_AUTH_SECRET yet.