Access inventory
Who has access to what, across cloud platforms, shared drives, finance systems, and administrative portals.
Access control is the discipline of making sure each person can reach exactly what their job requires, and nothing else. In most small businesses access accumulates: people change roles, contractors come and go, and permissions are added but never removed.
Who has access to what, across cloud platforms, shared drives, finance systems, and administrative portals.
Roles defined by what the job needs, so access is granted by role rather than by request.
A recurring review with a named owner, because access drifts the moment it stops being checked.
A written, testable sequence for removing access when somebody leaves, including shared credentials and third-party tools.
Identification of administrator and service accounts, and reduction of standing privilege where it is not needed.
Build the current access inventory, including the systems nobody lists on the org chart.
Define roles and the access each one carries.
Remove standing access that no role justifies, starting with former staff and contractors.
Set the review cadence and the offboarding runbook with a named owner.