What happens when
a worker leaves
The moment most communication records disappear is the day the worker who made them leaves. Here is what your service still has.
The scenario
A support worker messaged a young person six months ago. That worker has since left the organisation. Someone now needs to see the whole conversation: who sent what, when, with any photos or documents, and to hand it over as part of a review or an inspection.
On a personal phone, this is where the trail ends. The handset went with the worker. The messages were never the organisation's to begin with.
Here is what happens instead.
There is a second version of this question, and for most services it is the one that bites first: the same worker was in the staff team group for two years. That is answered further down, and the answer is a different shape.
Step by step
The day the worker left
Their access was cut. Not their history: their access. They can no longer open the conversation, and if a seat cannot be cleared, that is written into your audit trail as a finding. The conversation itself, and the record that this person was part of it, stay with your service.
Finding the conversation
You look up the young person, not the worker. The record is organised around the person being supported, so it does not matter how many workers have come and gone in between.
What you can see
For every message: when it was sent, who sent it, the role they hold in your service, which conversation it belonged to, the message itself, and any attachments by name.
The role matters more than it first appears. Six months on, "sent by a support worker" and "sent by a safeguarding lead" are different facts, and a name alone will not tell you which.
The audit trail goes one step further than the transcript does. Every recorded action carries the name and the role the person held at that moment, written into the entry at the time, so a change of role later does not rewrite what an entry says.
Handing it over
You export it. The PDF is laid out as a case note: it names whose record it is, states the period it covers, and lists each message in order with its timestamp, sender and attachments. There is a CSV as well when someone needs the data rather than the document.
And the export is itself recorded
Producing a record of a young person's communication is a significant act, so it is treated as one. The export is logged when it completes, and exports expire rather than sitting around indefinitely. If you are ever asked who took a copy of a young person's messages and when, that is answerable.
The same question, for the staff group
Most services start with the staff team chat rather than with a young person's record, because that is where the largest exposure already is. Handovers, coordination, the quick question mid-shift, and a fair amount about the people you support, all sitting on personal handsets. So the leaving question applies to it just as hard, and the answer is worth having separately.
The same worker was in your team group for two years. They wrote the handover on the night of an incident. They have now left, and the handset went with them.
Their messages stay with the service
Everything they wrote stays in the thread when somebody goes. The conversation reads the same way it did the day before, for everyone still in it, and that includes the handover they wrote. What changes is them: they come off the member list, and their access ends.
Access ends with the job
The moment one of your admins archives, pauses or blocks a member, they are out of the conversation on our own screens, and the seat they held in the chat itself is cut. Your service chooses the shape: access can end outright, or archiving can hold a read-only window first, running for a number of days your organisation sets, for the handover period that usually follows somebody leaving. The window closes on our side when it expires, rather than relying on anyone remembering.
If a seat cannot be cut, it is written into your organisation's audit trail as a finding, in plain words, so the gap is visible to the people whose job it is to close it.
You can produce the thread
A team group exports the same way a young person's record does. The PDF is laid out as a case note, naming the group, the period it covers, and each message in order with its timestamp, sender and attachments. There is a CSV as well when someone needs the data rather than the document. The export is recorded when it completes, it is available to the person who asked for it, and it expires rather than sitting around.
One limit, and it is deliberate. The export is produced by a member of staff who was in that conversation, not by an administrator reaching in from outside. Exporting adds no reach, so nobody sees a thread through an export that they could not already see in the product. Where somebody carrying the duty genuinely needs content they were not part of, that goes through the recorded, time-limited route rather than an unrecorded download.
And the trail still names them
A year later, the entries about a member of staff who has since left still carry the name and the role they held at the moment they acted. That is the part that answers a review, a complaint or an allegation, and it is why the record is worth keeping at all.
Who can look, and how you know
A record that anyone could read without leaving a trace would be surveillance. Access is limited to named roles, and where a safeguarding lead needs to see more, that is a deliberate, time-limited step with a beginning and an end, not a permanent standing permission.
Every one of those steps is recorded. So when someone asks who has looked at this young person's messages, there is a record that answers it.
Where it stops
This is a record of communication. It is not the young person's care record, and it does not replace the system you keep that in. Where something in a conversation becomes a safeguarding concern, it belongs in your recording system, and this is what you attach to it.
It also does not decide anything for you. Whether a record is sufficient, what to do about what it shows, and what to share with whom are judgements for your service. We hold the record; you hold the responsibility.
Your organisation is the data controller and we act as your processor, which is the way round it should be.
What you can show during an Ofsted inspection
Inspectors do not ask to see a messaging platform. They ask what contact a young person has had, how the service responded when something was raised, and how you know.
What you can put in front of them is a document, per young person, covering a period you choose: every message with its date, time, sender and role, attachments listed, in order. Produced in minutes rather than assembled from people's phones the night before.
The same document serves a Regulation 44 visit in England, a case review, a complaint, an allegation against a member of staff, or a request from a young person to see their own information.
And because the record builds itself while people work, it is written as things happen rather than assembled once the question is known.
Ask us to walk through this exact scenario with real screens rather than slides. Seeing an audit trail answer a real question is the fastest way to judge one.