Operations ·
Write down who approves access before the next hire starts
When every access request ends on the founder's desk, onboarding waits and departures go unchecked. Name the approver, the administrator and the review step.
By Norwind
Separate the three requests that arrive
A new hire needs accounts created. A person changing role needs some access added and some removed. A person leaving needs access closed. These are three different requests with three different risks, and they are often handled as one informal favour. Write them down separately. Each one should say what is granted, who may ask for it and what evidence is left behind.
Name an approver who is not the founder
A founder approving every request becomes the queue. The work waits for a calendar gap, and the request is granted from memory rather than from a rule. Name the person who approves access for each system and the person who carries the change out. Where the two must be the same person, say so and record the decision. A founder can still hold the exception, provided the routine case no longer needs them.
Check departures on a fixed date
Closing access is the step most often missed, because nobody is waiting on it. Put a review on a fixed interval and compare the current people against current access. Confirm that shared accounts, external tools and anything connected through an integration were included. For a company with no organized technical function, this review is usually the first thing a technical lead should own.
A practical check
- Write down the joiner, mover and leaver requests as three procedures.
- Name the approver and the administrator for each system.
- Set a fixed date to compare current people against current access.