Skip to content

Close the old door

Remove access when people and vendors change

Use one joiner, role-change, departure, and vendor-exit routine so accounts, keys, devices, forwarding rules, and shared access do not survive by accident.

TARGET PRACTICE

What this guide should leave behind

A dated access review shows who still needs each critical permission, what was removed, what remains shared, and who owns the next check.

SEQUENCE / 04

Work the routine in this order

  1. 01

    List the systems, shared folders, devices, remote tools, payment platforms, social accounts, API keys, forwarding rules, and physical access that change with a person's role.

  2. 02

    Create a standard start, change, and departure checklist with an accountable business owner and a same-day path for urgent removal.

  3. 03

    Use individual accounts and role-based access where available. Rotate shared secrets when membership changes and remove sessions, devices, recovery methods, tokens, and integrations.

  4. 04

    Review administrators and vendor access on a calendar. Confirm that the business can export needed records and continue operating when the relationship ends.

CHECK THE FACTS

Foundations worth seeing

  • Former workers and vendors no longer have active accounts, sessions, or recovery paths.
  • Administrative access is smaller than ordinary day-to-day access.
  • Shared credentials and keys are rotated after relevant changes.
  • The business owns required records, domains, billing, and recovery channels.
FIELD DEFINITIONS

Terms behind this routine

ESCALATION BOUNDARY

Know when general guidance stops

Use qualified employment, contract, legal, privacy, security, or forensic review when access removal is disputed, evidence must be preserved, misconduct is suspected, or regulated records are involved.

Monthly field note

Get practical guidance in your inbox.

Monthly plain-language guidance for account ownership, recovery practice, device safety, and incident readiness.
Required