Skip to content
Foxx Cyberfoxxcyber/docs

Deleting a Client

Archive a former client to keep its records read-only, or have an admin delete an archived client permanently, with a backup first.

There are two ways to end an engagement in Bedrock GRC, and they are very different:

Archive clientDelete permanently
What happensThe client is closed: read-only for staff, gone for assessors, its portal links revoked.The client and everything it holds are erased.
Records and filesAll kept.All deleted, issued assessments included.
UndoRestore client brings it back.Cannot be undone.
WhoAnyone with edit access to the client.Admins only, and only on an archived client.

Archive first. Delete permanently only when a contract or an erasure request requires the client to be gone.

Archive a client

At the bottom of the client's Profile tab, under Archive this client, choose Archive client and confirm. The client:

  • leaves the portfolio, the client list, Monitoring and search;
  • stays readable to the staff who are on it, under Clients → Archived clients, marked Archived · read-only. Every change is refused, admins' included, except Restore client and an admin's permanent deletion;
  • disappears for assessors from partner firms;
  • has its client access links revoked, each recorded in the audit log. Clients archived before this rule existed had their live links revoked when it was installed.

Exports and, for people with edit access, the full backup can still be downloaded from an archived client. See Clients and the Portfolio.

Delete a client permanently

Only an admin can do this, and only once the client is archived.

  1. Open the archived client's Profile. At the bottom, the Delete permanently card lists what will be deleted.
  2. Download a full backup first if the client's records should be kept anywhere, such as for the client or for your own records. See Client Backup and Restore. Keep the backup encrypted: its files are not.
  3. Type the client's name exactly as shown to confirm.
  4. Choose Delete permanently and confirm once more.

You return to the archive list with a message saying the client was deleted.

What is deleted

Everything that belongs to the client, in one step that either completes or changes nothing:

  • the profile, contacts and the people assigned to it;
  • goals, risk appetite and risks;
  • adopted frameworks, answers, objective answers and snapshots;
  • issued assessments from partner firms, which otherwise can never be deleted;
  • the roadmap;
  • documents, evidence, engagement agreements, every version and every stored file;
  • vendors, assets, calendar events and the engagement log;
  • client access links and any open portal sessions;
  • imports still waiting for review.

Nothing that belongs to another client is touched.

What is kept

  • The audit log. The client's earlier entries stay, without the link to the client, and one more entry (client.purge) records who deleted client id and when. See Audit Log.
  • Backups you downloaded, wherever you put them.
  • Database backups taken by whoever runs the service, until they age out of their retention period. On the hosted service, ask support@foxxcyber.com about retention if an erasure request needs a date.

Bring a client back

  • An archived client comes back with Restore client on its profile, with its records as they were. Its client access links do not come back, because archiving revoked them; make new ones as needed.
  • A deleted client can only come back from a client backup, which an admin restores as a new client from Clients → New client.

Last updated October 9, 2026