Access Request & Offboarding Checklist for Small Teams
In a 5-person company, "who has access to what" is tribal knowledge. At 15 people it's a security incident waiting for a Tuesday. The fix is two one-page documents — an access request template and an offboarding checklist — and one rule: if it isn't in the log, it doesn't exist. This page gives you both, plus the 20-minute quarterly review that keeps them true.
The access request template (6 fields, no exceptions)
Every grant request — Slack, AWS, Figma, the accounting system — gets the same six fields. Copy this into a form or a doc template:
- System: the exact name, not "the cloud thing."
- Person + role: who, and what they do for the company.
- Access level: viewer / editor / admin. Default to the lowest that works.
- Duration: permanent, or ends on a date (contractors always get dates).
- Approver: one named human. Forwarded DMs don't count.
- Reason in one sentence: if nobody can write it, access doesn't get granted.
Keep the filled requests in one doc, newest first. That doc IS your access inventory — auditors, insurers, and future-you all read the same page.
The grant checklist (per system, written once)
- Every system you run gets a 3-5 line grant recipe: where the admin panel lives, the exact permission set for each level, and what the invite email should say.
- Mark which systems support SSO or deprovisioning APIs — those go first in the offboarding list below because they're the ones people forget.
- Shared credentials get an owner and a rotation date. A password in a group chat is not a credential policy, it's a countdown.
The offboarding checklist (run it the same day, every time)
- Revoke logins: SSO/identity provider first, then every system in the grant recipe list — the access inventory doc above tells you exactly where they had access, which is why you kept it.
- Rotate shared credentials: anything the person knew or could have known, including WiFi passwords and API tokens tied to their account.
- Forward or freeze their work: email auto-forward to their manager for 30 days, transfer file ownership, reassign scheduled reports and cron jobs (these are the ones that page you three weeks later).
- Remove external access: vendor portals, client admin panels, social accounts, the domain registrar. Contractors accumulate these silently.
- Recover hardware & note the date. The date matters: "revoked the same day" is the sentence you want to be able to write.
The 24-hour rule: offboarding access happens the same day the decision is made, not at the end of the week. Goodwill is not a security control.
The 20-minute quarterly access review
Once a quarter, open the access inventory doc and ask three questions of every line: does this person still work here? do they still need this level? would today's you grant this again? Delete anything that fails. The review takes 20 minutes precisely because the inventory exists — without it, "audit our access" is a two-week archaeology project.
Common failure modes
- Admin-for-everyone: the default grant level of busy teams. Cost shows up later as an unexplained change nobody can attribute.
- The growing spreadsheet nobody updates: if the inventory isn't the same doc the requests land in, it's already stale. One doc, one place, newest on top.
- Offboarding-by-memory: the departing person's manager remembers most systems and forgets the one that matters. The grant recipe list exists so the checklist does the remembering.
---
The Automation Starter Pack ($19) ships the access request form, the grant recipe sheet, and the offboarding checklist as fill-in templates, alongside the intake triage board, the Monday digest script, the incident first-response skeleton, the handover doc, and the pick-first automation filter — launch month: 30% off with code HIVE-LAUNCH30 at checkout.