Close the old door
Remove access when people and vendors change
Use one joiner, role-change, departure, and vendor-exit routine so accounts, keys, devices, forwarding rules, and shared access do not survive by accident.
What this guide should leave behind
A dated access review shows who still needs each critical permission, what was removed, what remains shared, and who owns the next check.
Work the routine in this order
- 01
List the systems, shared folders, devices, remote tools, payment platforms, social accounts, API keys, forwarding rules, and physical access that change with a person's role.
- 02
Create a standard start, change, and departure checklist with an accountable business owner and a same-day path for urgent removal.
- 03
Use individual accounts and role-based access where available. Rotate shared secrets when membership changes and remove sessions, devices, recovery methods, tokens, and integrations.
- 04
Review administrators and vendor access on a calendar. Confirm that the business can export needed records and continue operating when the relationship ends.
Foundations worth seeing
- Former workers and vendors no longer have active accounts, sessions, or recovery paths.
- Administrative access is smaller than ordinary day-to-day access.
- Shared credentials and keys are rotated after relevant changes.
- The business owns required records, domains, billing, and recovery channels.
Terms behind this routine
Know when general guidance stops
Use qualified employment, contract, legal, privacy, security, or forensic review when access removal is disputed, evidence must be preserved, misconduct is suspected, or regulated records are involved.