Access Request & Offboarding Checklist for Small Teams

In a 5-person company, "who has access to what" is tribal knowledge. At 15 people it's a security incident waiting for a Tuesday. The fix is two one-page documents — an access request template and an offboarding checklist — and one rule: if it isn't in the log, it doesn't exist. This page gives you both, plus the 20-minute quarterly review that keeps them true.

The access request template (6 fields, no exceptions)

Every grant request — Slack, AWS, Figma, the accounting system — gets the same six fields. Copy this into a form or a doc template:

  1. System: the exact name, not "the cloud thing."
  2. Person + role: who, and what they do for the company.
  3. Access level: viewer / editor / admin. Default to the lowest that works.
  4. Duration: permanent, or ends on a date (contractors always get dates).
  5. Approver: one named human. Forwarded DMs don't count.
  6. Reason in one sentence: if nobody can write it, access doesn't get granted.

Keep the filled requests in one doc, newest first. That doc IS your access inventory — auditors, insurers, and future-you all read the same page.

The grant checklist (per system, written once)

The offboarding checklist (run it the same day, every time)

  1. Revoke logins: SSO/identity provider first, then every system in the grant recipe list — the access inventory doc above tells you exactly where they had access, which is why you kept it.
  2. Rotate shared credentials: anything the person knew or could have known, including WiFi passwords and API tokens tied to their account.
  3. Forward or freeze their work: email auto-forward to their manager for 30 days, transfer file ownership, reassign scheduled reports and cron jobs (these are the ones that page you three weeks later).
  4. Remove external access: vendor portals, client admin panels, social accounts, the domain registrar. Contractors accumulate these silently.
  5. Recover hardware & note the date. The date matters: "revoked the same day" is the sentence you want to be able to write.

The 24-hour rule: offboarding access happens the same day the decision is made, not at the end of the week. Goodwill is not a security control.

The 20-minute quarterly access review

Once a quarter, open the access inventory doc and ask three questions of every line: does this person still work here? do they still need this level? would today's you grant this again? Delete anything that fails. The review takes 20 minutes precisely because the inventory exists — without it, "audit our access" is a two-week archaeology project.

Common failure modes

---

The Automation Starter Pack ($19) ships the access request form, the grant recipe sheet, and the offboarding checklist as fill-in templates, alongside the intake triage board, the Monday digest script, the incident first-response skeleton, the handover doc, and the pick-first automation filter — launch month: 30% off with code HIVE-LAUNCH30 at checkout.

← All ops notes