Staff changes are normal. The risk comes when technology access doesn’t change with them.
When someone joins, moves into a new role, or leaves, the business should have a clear process for email, files, groups, devices and admin permissions. Without one, access tends to drift — and “drift” usually means someone who shouldn’t still have access to something quietly does.
New starters need the right access, not all access
It’s tempting to copy another person’s permissions because it’s quick. But that can give a new staff member more access than they need, often to systems they’ll never touch.
A better approach is role-based. What does this person need to do their job? Which mailboxes, files, Teams and applications are required? Who’s authorised to approve those?
Role changes need a review
When someone moves role, old access should be reviewed. A person who moves from finance to operations probably no longer needs the finance mailbox. A staff member promoted to manager may need new approval responsibilities.
Access should follow the role, not the person’s history.
Departures need a calm checklist
When someone leaves, the business should know how to:
- block sign-in at the right time;
- preserve email and files where required;
- redirect or delegate the mailbox;
- remove group and application permissions;
- recover business-owned devices;
- check shared files and ownership;
- remove admin access where it exists.
A checklist protects the business and makes the handover cleaner for everyone involved — including the person leaving.
Admin access needs extra care
Admin access shouldn’t be handed out casually. It can affect security, billing, users, files, and business continuity all at once.
For higher-risk permissions, use approval steps. Make it clear who can request access, who can approve it, and when it should be reviewed.
A simple test
Create a staff access checklist with three sections: joining, changing role, and leaving. Keep it short enough that managers will actually use it.
A calm next step
Good access management isn’t about distrusting staff. It’s about making sure people have the right access at the right time — and that the business can prove it, when it matters.