There are three ways to close somebody down, and they are not degrees of the same thing. Archiving stops somebody signing in. Anonymising removes who they were and keeps what happened. Purging removes both.
Almost always you want archiving. The other two answer a request to erase somebody, and they are not reversible.
Archiving
Section titled “Archiving”Archiving closes every route in and deletes nothing. It is covered in Restoring access and archiving leavers, and it is the gate to anonymising: Anonymise user is on the actions menu of an archived person and simply is not there on an active one. Purging is not gated that way — Purge user sits on both menus, so somebody can be purged without being archived first.
Anonymising somebody
Section titled “Anonymising somebody”- Archive the person first, if they are not archived already.
- Open the Archived tab, find them, and open the actions menu at the end of their row, the three dots. On an archived person that menu offers Activate, Anonymise user and Purge user.
- Choose Anonymise user.
- Read the summary before anything else. It asks “Are you sure you want to anonymise name?” and then counts exactly what goes, line by line: course engagements, form instances, goals, workflow instances, attestations, AI conversations, practice sessions, logged CPD entries and uploaded files — with a total at the top, and a separate line for certificates retained as proof, which are the ones that survive.
- If anybody might need the data, choose Export their data first. The screen is blunt about why: nothing can be recovered afterwards.
- Type the person’s email address into Type the user’s email to confirm. It is marked required, the field shows their address as its placeholder, and the Anonymise user button stays greyed out until you have typed it. There is no way to hurry past this step.
- Choose Anonymise user.
Anonymising replaces who somebody was and leaves what they did. Their completions, attempts and records stay, attached to a person who can no longer be identified.
Competency sign-offs after a course are kept the same way as retained certificates: a pseudonymised proof of the course, the date the learner was observed and that a qualified signatory signed them off. The evidence files, drawn signatures, notes and device details on their sign-off forms are removed.
You cannot anonymise yourself, and you cannot anonymise somebody in another account.
Purging somebody
Section titled “Purging somebody”- Open the actions menu at the end of their row.
- Choose Purge user.
- Confirm, typing their email address if they have any history.
- If they own reports, dashboards or schedules, choose whether those are transferred or deleted. Transferred ones come to you unless you name somebody else.
That fourth step is the one to slow down on. A schedule that keeps sending has to belong to somebody, so purging its owner makes you its owner by default.
Purging can be done from any status, including Pending, for someone who signed themselves up but never finished. It is not offered while a purge is already scheduled.
A purge usually waits 72 hours
Section titled “A purge usually waits 72 hours”Somebody with no history behind them is purged immediately, and the confirmation says so. Everybody else is queued, and the purge runs 72 hours later.
While it waits, the person’s row offers Cancel purge instead, and Pending purges at the top of the user list shows everybody currently queued.
That window is deliberate. It is the only chance to undo a purge, and it closes on its own.
A legal hold stops both
Section titled “A legal hold stops both”Where a legal hold covers somebody, anonymise and purge are both refused and the menu says why. Placing a hold on somebody whose purge is already queued cancels the queue rather than pausing it, so releasing the hold later does not resume it.
For what each action removes and what survives it, see How purging, anonymising and legal holds work.

