Reusable practice kit
Access change checklist
A repeatable joiner, role-change, departure, and vendor-exit record.
What the completed kit should do
Access follows current work and closes visibly when a person or relationship changes.
Capture these facts in your approved system
- Person or vendor role, business owner, effective date, and approved systems
- Accounts, groups, shared folders, devices, physical access, and remote tools
- Administrative rights, payment rights, forwarding, tokens, keys, and integrations
- Records transfer, device return, session removal, secret rotation, and recovery update
- Verifier, completion time, exception, evidence location, and next review
Use the structure in this order
- 01
Start from an approved role rather than copying another person's access.
- 02
Apply the smallest useful permissions and individual accounts.
- 03
Remove or change access at the effective time.
- 04
Verify cleanup and record unresolved exceptions.
Close the practice loop
A second reviewer can see that access matches the current relationship and that old paths are closed.
Protect the completed record
- Coordinate evidence preservation and disputed access with qualified reviewers.
- Removing an account may also remove needed records or audit history.
- Shared secrets must be rotated, not only removed from a user list.