Work from a list of people rather than a list of systems. Naming everybody who has ever been given access finds the accounts a system-by-system review misses.

Two ways to do this, and one works

The obvious approach is to open each system and look at who has access.

That finds the accounts each system knows about, and misses shared logins, credentials in a password manager, and anything using a personal account nobody thinks of as access.

The better approach is to list every person who has ever been given anything, then ask what each still holds.

People are easier to remember completely than systems are, and the list is shorter.

Who to list

The fifth is the category nobody writes down. Somebody's nephew who set up the email in 2019, a friend who fixed the site once, or a former partner who still has the hosting login are all real and all invisible to a system-by-system review.

For each person, ask what they hold

Which is the practical work.

The website admin, the hosting account, the domain registrar, the email accounts, the local listing, social profiles, the accounting system, the payment processor, and any shared drive.

Go through that list per person rather than per system, and mark what each still has.

For anybody no longer involved, everything should be removed, and for anybody current, the question is whether they need all of it.

Somebody who needs to update the website does not need the payment processor.

That distinction takes a moment and reduces what a single compromised account can reach.

A worked example

A business listed eleven people rather than eight systems.

The list included two former employees, a web designer they had not used since 2021, an accountant who had been replaced, and the owner's brother-in-law who had set up the original email.

Between them those five still held the hosting login, admin access to the website, the listing, and a shared drive containing customer records.

None of it was malicious and all of it was simply never removed.

Removing everything took about an hour.

A system-by-system review the previous year had found two of the five.

Shared logins are the hard part

Which the exercise usually surfaces.

A single account whose password four people know cannot be revoked from one person; it can only be changed for everybody.

So the finding is not that somebody has access but that access cannot be removed individually at all.

Where you find one, change the password now and move to individual accounts where the system supports it.

Where it does not, note it, since that is a real limitation to weigh when the system is next reviewed.

A shared login is the single reason most stale access persists anywhere.

Where it exists, note who currently knows the password.

Check the recovery routes too

Which is the access nobody counts as access.

A password reset goes to an email address or a telephone number, and whoever controls those controls the account regardless of who holds the password.

Check the recovery email and recovery phone on every important account, since those were set during setup and frequently point at a person rather than the business.

A former employee's mobile number as the recovery on the payment processor is a serious finding that no permissions list will show.

That single check takes about ten minutes across the accounts that actually matter.

Do it as part of leaving, not annually

Which is the version that prevents the problem.

The annual review exists because nothing happens when somebody leaves.

Write a short list of what to remove, keep it with the supplier list, and work through it the week anybody stops being involved.

That includes suppliers finishing a project, not only staff, since a designer who finished in March is exactly as stale by December.

Doing it then takes ten minutes and doing it annually takes an hour and misses things.

Write down who should have what

Which is the durable output.

A short document listing each system and who legitimately needs it, kept with the domain list and the file set.

Next year's review then becomes a comparison rather than an investigation.

It is also what somebody else needs if you are unavailable, which is the same argument as everywhere else in this run.

Half an hour to write once, then twenty minutes a year to check against.

That is the cheapest security work available to a business of this size.

Turn on two-factor while you are in there

Which is the single most useful thing this review can produce.

You are already logging into every important account to check its access list, so adding the second step costs a couple of minutes per account and nothing afterwards.

Prioritise the ones that would be worst to lose: the email that receives every password reset, the domain registrar, the payment processor, and the hosting.

Note where you have enabled it, and make sure the recovery codes are stored somewhere more than one person can reach rather than on one person's phone.

Stale access is a housekeeping problem and an unprotected email account is a genuine risk, so if the hour only produces one outcome, make it this one.

The counter-case

Most stale access is harmless.

People who left on good terms do not log back in, and the realistic risk for a small business is far lower than a strict reading suggests.

Removing access can also break something, particularly where a supplier's account is what an automated process runs under.

And revoking abruptly without a word can damage a relationship you may want to use again next year.

A short message saying you are tidying up the records covers it entirely and costs nothing.

List the people rather than the systems, remove everything for anybody no longer involved, check the recovery routes, and write down who should have what.

The hour

  1. List every person, not system.
  2. Include suppliers and helpers.
  3. Ask what each still holds.
  4. Remove everything for the departed.
  5. Change shared passwords.
  6. Check recovery emails and numbers.
  7. Write down who should have what.

Step six finds what no permissions list ever will, since whoever controls the recovery address controls the account regardless of who holds the password.

A prior version of this is at access nobody has revoked.


Frequently asked questions

Why list people rather than systems?

Because a system-by-system review finds the accounts each system knows about and misses shared logins, password managers, and personal accounts nobody thinks of as access.

Who should be on the list?

Current staff, anybody who has left, current and former suppliers, family or friends who helped once, and yourself on old devices.

Which category gets missed?

Informal helpers. Somebody's nephew who set up the email, a friend who fixed the site once, or a former partner who still holds the hosting login.

What about shared logins?

They cannot be revoked individually, only changed for everybody. Change the password now and move to individual accounts where the system supports it.

What does a permissions list not show?

Recovery routes. Whoever controls the recovery email or telephone number controls the account regardless of who holds the password.

When should this happen?

The week anybody stops being involved, including suppliers finishing a project. Doing it then takes ten minutes; doing it annually takes an hour and misses things.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

Reviewing access this month?

List the people rather than the systems. The informal helpers never appear on a permissions page.

Start a Conversation