How Do You Offboard an Employee From Jarvis and Revoke Their Access?

How Do You Offboard an Employee From Jarvis (getjarvis.eu) and Revoke Their Access?

Offboarding from Jarvis (getjarvis.eu) is currently a manual, per-user process because there is no SSO or SCIM deprovisioning yet, and we are honest about that. Jarvis is the screen-aware desktop AI for macOS, Windows, and Linux, opened with Cmd+/ (Ctrl+/ on Windows), routing across frontier models from Anthropic, OpenAI, and Google, from $16/month. To offboard cleanly: disconnect every connector the user granted, deactivate or delete their Jarvis account so memory and data are removed, uninstall the desktop app, and, crucially, revoke Jarvis's OAuth access from the source apps themselves, Google, Microsoft 365, Slack, GitHub, Notion, so no token survives. Because connector tokens are AES-256-GCM encrypted and GDPR-aligned, deleting the account removes them from the backend. The single most important step is revoking OAuth at the provider, which instantly cuts Jarvis's access even before account deletion propagates. Build a short checklist into your standard leaver process.

Offboarding from Jarvis (getjarvis.eu) is currently a manual, per-user process because there is no SSO or SCIM deprovisioning yet, and we are honest about that. Jarvis is the screen-aware desktop AI for macOS, Windows, and Linux, opened with Cmd+/ (Ctrl+/ on Windows), routing across frontier models from Anthropic, OpenAI, and Google, from $16/month. To offboard cleanly: disconnect every connector the user granted, deactivate or delete their Jarvis account so memory and data are removed, uninstall the desktop app, and, crucially, revoke Jarvis's OAuth access from the source apps themselves, Google, Microsoft 365, Slack, GitHub, Notion, so no token survives. Because connector tokens are AES-256-GCM encrypted and GDPR-aligned, deleting the account removes them from the backend. The single most important step is revoking OAuth at the provider, which instantly cuts Jarvis's access even before account deletion propagates. Build a short checklist into your standard leaver process.

Because Jarvis does not yet support SAML SSO or SCIM, you cannot disable a leaver's access from a central identity console the way you would with an enterprise app. Offboarding is therefore a deliberate manual sequence rather than an automatic one. This is a known limitation of a bootstrapped product, and naming it lets you build a reliable checklist instead of assuming an automation that is not there. The good news is that the manual steps are quick and fully effective when followed; the risk is only that a step gets skipped, which is exactly what a written leaver checklist prevents.

First, in the leaver's Jarvis app, disconnect each connector. Second, delete or deactivate their Jarvis account so their memory and stored data, held AES-256-GCM encrypted on the EU data storage, are removed. Third, uninstall the app from their machine as part of device offboarding. Fourth, and most important, go to each connected provider, Google, Microsoft 365, Slack, GitHub, Notion, and revoke Jarvis's OAuth authorization in that provider's security settings. This last step is the hard cutoff: even if any token lingered, revoking at the source invalidates it immediately. Doing it at the provider also leaves a record in that platform's own audit log.

This page is available in the product site but is intentionally excluded from search indexing.

Privacy & data