Access controls should limit client information to people who need it for their role. Start by identifying sensitive records and the consequences of inappropriate access. Use individual accounts and review both ordinary user permissions and privileged administrator access.
Include shared mailboxes, exported files, mobile devices and supplier support. A secure main application can be undermined by an unrestricted download folder. Establish a joiner, role-change and leaver process that covers every relevant system, not just the organisation's primary email account.
Build permissions around real responsibilities
List the activities each role performs and the records needed for them. Finance may require invoices and payment status without access to every case attachment; an external assistant may need a limited task queue without the full client archive. Use this map to define access groups. Avoid granting the broadest role simply because it prevents support requests during onboarding, as those permissions often remain long after the initial task ends.
Separate ordinary work accounts from privileged administration. Identify who can create users, export whole datasets, change sharing settings or remove audit records. Individual accounts make actions easier to investigate and permissions easier to withdraw. Shared credentials obscure responsibility and complicate departure, especially when the same password has also been copied into scripts or supplier support notes.
Review routes outside the main application
Check shared mailboxes, network folders, exported reports, mobile synchronisation and external collaboration links. A carefully restricted case system can be undermined by a nightly export to a folder everyone can open. Record which records may be downloaded and whether devices are managed appropriately. The NCSC's small organisation guidance provides a starting point for protecting accounts and devices. [1]
Inspect application integrations and service accounts as well as human users. A connection created by a former employee may continue to read client records after their login is disabled. Identify its purpose, permissions and owner. Where an integration requires broad access, decide whether that access is justified and how it will be monitored, rather than assuming it is harmless because no person signs in interactively.
Make joining, changing roles and leaving complete processes
Use a request and approval record for new permissions. Ask the manager to confirm the actual task and appropriate duration, particularly for temporary work. Test a new user's access with harmless records before giving them live assignments. Check that they can perform necessary tasks without viewing unrelated clients; a control that blocks legitimate work may encourage staff to create informal workarounds.
Treat role changes as a removal and reassessment exercise, not just an addition of new access. On departure, include accounts, active sessions, devices, external links and recovery methods. Transfer necessary business records through an authorised process. Do not keep the person's credentials in circulation so colleagues can continue using their mailbox or cloud account without a clear ownership and access decision.
Review exceptions and investigate unusual activity
Set a review frequency proportionate to the sensitivity and pace of change. A reviewer should see what the permissions allow, not only unfamiliar technical group names. Ask whether each exception still has a business reason and expiry date. Keep evidence of removals and unresolved items, then confirm that changes took effect in connected systems rather than assuming a completed ticket proves the result.
Define who reviews unusual bulk exports, new administrator accounts or unexpected external sharing. Avoid collecting logs indefinitely without a purpose or response process. Link potential incidents to Handling a suspected personal data breach so staff know when an access concern requires immediate escalation. Use Data protection when using cloud software when the relevant permissions depend on cloud service features or customer-controlled settings.
For Data processing agreement review, provide the role map, administrator list and examples of difficult access decisions. Ask the technical owner to explain available restrictions and audit evidence. A useful review identifies the policy, contract and configuration changes needed together. Build an emergency access route with limited authority and later review, so urgent client work does not require permanently opening every record to every employee.
Review shared links as a separate access route
A carefully managed staff account does not prevent disclosure through an unrestricted document link. Sample recent shared folders and inspect who can open them, whether onward sharing is possible and whether access survives the original project. Include external guests whose organisation or role may have changed since the invitation.
Give document owners a simple method for replacing overly broad links and informing legitimate recipients. Avoid removing access without planning how an active client will receive necessary information. Record the reason for any exception and a review date tied to the work. This focuses the review on real exposure rather than a count of enabled accounts in the main application.
Illustrative scenario
A staff member moves from case handling to finance but retains access to all client files. A role review removes unnecessary permissions while preserving the records needed for billing. The company also checks shared links created under the old role so that access is not retained through another route.
Preparation checklist
- List systems, shared folders and external access routes.
- Assign permissions according to actual duties.
- Review administrator accounts and public sharing links.
- Record access changes and investigate unusual activity.
Frequently asked questions
Is disabling a leaver's email account enough?
No. Review other applications, sessions, devices, integrations, shared links and recovery methods. Access can survive through routes that do not depend on the primary mailbox.
Should all managers have administrator access?
Administrative rights should follow a justified technical responsibility, not seniority alone. Use limited roles where possible and review privileged permissions separately from ordinary client work.
How do we review temporary access?
Record the purpose, approving person and expiry. Check that it is removed or reassessed when the task ends, including any exports or external sharing created during the work.
Do logs prevent unauthorised access?
Logs support detection and investigation but do not replace appropriate permissions and authentication. Decide who reviews relevant events and how suspected misuse is escalated.
Official sources
Sources checked: 8 September 2026. Check the linked guidance for subsequent changes.
General information only. The appropriate action depends on your circumstances and the applicable jurisdiction.
Report a correction