Sponsor management system access should be limited to authorised eligible users with individual credentials and defined responsibilities. Shared accounts make it harder to identify who acted and can undermine the organisation’s control of sponsorship records.
Create a reliable account inventory Start by listing every SMS User, their role, business relationship, contact details and reason for access. Confirm the list with the authorising officer and the people responsible for HR. An account that nobody recognises should prompt an investigation, not an assumption that it is harmless because the business has not noticed a problem.
For each active user, identify the tasks they are expected to perform and the records supporting those tasks. Keep this inventory under controlled access because it contains personal and operational information. Review it when staff join, change responsibilities or leave. A current list makes it easier to plan cover and to distinguish a legitimate account from an outdated arrangement.
Keep credentials and approvals separate Use individual credentials and keep passwords and one-time codes private. A manager approving a sponsorship action does not need to log in as the employee who submits it. Design a separate approval record that identifies the proposed action, the facts checked and the decision maker. This provides accountability without turning an account into a shared office resource.
Check where staff store supporting information. Avoid uncontrolled copies of passports and worker records in messaging threads merely to authorise a routine task. Link the approval to an appropriately restricted case record instead. If urgent work cannot wait for the usual user, use an eligible authorised cover arrangement rather than requesting their password while they are away.
Prepare for mandatory multi-factor authentication Home Office guidance introduces mandatory MFA in phases from 3 September 2026, with all sponsors expected to be covered by November. It specifies contact and identity information needed for authentication and says organisations will receive instructions when their accounts are enabled. [1] Check those instructions against the organisation's actual user records instead of assuming a generic authentication method will work.
Ask each user to verify their own recorded details through the proper process. Consider practical access issues such as an old telephone number, a departed colleague's email address or a device that will shortly be replaced. Record the resolution without collecting authentication codes centrally. The aim is dependable individual access, including during ordinary changes of equipment or contact details.
Act on inactive accounts and the Level 2 transition The guidance treats an account unused for at least twelve months as inactive and describes a contact-and-action process before deactivation. It also ends new Level 2 appointments from 9 September 2026 and requires eligible conversion or deactivation of existing accounts by 8 March 2027. [1] These are separate issues and should appear as separate tasks in the access review.
A rarely used account may belong to a legitimate backup user, but the organisation still needs to keep that arrangement functional. A Level 2 User may be active yet require a different future plan. Check eligibility before any conversion and verify that the person understands the responsibilities associated with the resulting access. Use Key personnel for a sponsor licence to review the wider personnel arrangement alongside the system list.
Reconcile system activity with the underlying evidence After a material action, retain an appropriate record of what was submitted and reconcile it with the approved instructions. Check dates, names and reference details while the context is still fresh. If a discrepancy appears, establish what happened and follow the correct correction process rather than silently changing the internal record to match an inaccurate submission.
Use periodic sample reviews to test whether the process works. Select a completed task and trace it from the manager's information through approval to the system action. A missing step identifies a process weakness that can be addressed. Keep this review proportionate: the purpose is to find actionable problems, not to create a second archive of every document the organisation already stores.
Prepare an access incident response Decide who staff should contact if they suspect a compromised account, receive unexpected authentication messages or discover that a former employee still has access. Preserve relevant details such as the time and nature of the concern. Follow official account recovery or support instructions, and assess whether any sponsorship records or reports may have been affected.
Do not send passwords or one-time codes in an enquiry to an adviser. An initial request through Sponsor management process support can describe the user roles, the access problem and any urgent sponsorship task without disclosing credentials. Where the problem is technical, the official support route and the organisation's own IT team may need to work alongside whoever assesses the immigration consequences.
Make access control part of routine management Assign an owner for the access inventory and a date for its next review. Include contact-detail checks, planned leavers, cover arrangements and unresolved actions from earlier reviews. Give the authorising officer a concise record of significant findings so decisions about staffing and support are connected to the system's actual condition.
Test the process after a real personnel change. Confirm that the replacement can carry out the necessary work under their own access and that the departing user's position has been handled appropriately. A written procedure earns its value when it helps staff complete this transition without losing deadlines, sharing accounts or becoming dependent on somebody who no longer works for the business.
Illustrative example
A business removes a departing user through the proper process and confirms that another eligible user can handle upcoming tasks without sharing passwords.
Preparation checklist
- Use named authorised accounts
- Define approval roles
- Protect credentials
- Review access on personnel changes
Frequently asked questions
Should our team share one SMS account?
Individual accounts and credentials support accountability and secure access. Arrange eligible user cover and separate approvals rather than making a password available to the wider team.
What should we check for MFA readiness?
Check the current Home Office instructions and ensure each user's required personal and contact details are accurate. Users should retain control of their own authentication methods and codes.
Does an unused backup account need attention?
Yes. The guidance includes an inactivity process for accounts unused for at least twelve months. Follow any notification and verify that the organisation's cover arrangements remain usable.
Can an existing Level 2 User automatically become Level 1?
No. Check eligibility and responsibilities before conversion. The current guidance requires eligible conversion or deactivation by 8 March 2027, with new Level 2 appointments ending from 9 September 2026.
Official sources
Sources checked: 8 September 2026. Check the linked guidance for subsequent changes.
General information only. The appropriate action depends on your circumstances and the applicable jurisdiction.
Report a correction