Right access · right time · visible ownership

Free joiner–mover–leaver checklist builder.

Build an accountable checklist for a new starter, role change or departure. Cover accounts, applications, devices, information, physical access and the evidence needed to close the work properly.

Build the checklist

Three editable starting points

Start with the people event, then define what is in scope.

Use a role or case label rather than unnecessary personal details. The generated owners are responsibilities to confirm, not automatic assignments.

01

People change brief

Define the workflow

02Choose the access areasSelect every area the organisation needs to grant, change, recover or close.

Your draft stays in this browser unless you choose to copy or print it.

The control loop

A ticket is not finished when access is merely requested.

A reliable workflow starts from an authoritative request, applies the access needed for the role, records the action and asks the responsible business owner to verify the outcome.

Authorisetrusted source and role Changeleast necessary access Verifyevidence and owner
EVIDENCE LEDGERCASE / ROLE-CHANGE
09:00Authoritative request confirmedPeople owner
09:18Groups adjustedTechnical owner
10:05Previous access checkedBusiness approver
OWNERTIMEEVIDENCE

Do not use one generic checklist

Each people event closes a different gap.

J

Joiner

Start from an approved role profile, create an individual identity and prove that access works without unnecessary privilege.

M

Mover

Compare the old role with the new one. Removing inherited access is just as important as adding what the person now needs.

L

Leaver

Coordinate the exact removal time, preserve business information appropriately and verify accounts outside the central directory.

Official access-management guidance

Manage the whole identity lifecycle.

NCSC guidance connects onboarding and offboarding to a trusted identity source, role-based access, external users and timely revocation. The ICO access-control framework also asks organisations to document access changes and keep evidence of reviews and removals.

Access lifecycle questions

Close the gaps between people, IT and information owners.

Should we copy another employee's access for a new starter?

Not as the default. A role-based profile is easier to approve and review. Copying a person can reproduce temporary, historic or exceptional access that the new starter does not need.

Why does a mover need an offboarding step?

A role change can accumulate access if the process only grants new permissions. Record what belonged to the previous role and remove it promptly unless there is a documented continuing need.

Should a leaver's mailbox or files be deleted immediately?

Do not make that decision from a generic checklist. Agree ownership, retention, privacy, contractual and legal requirements first, then use an authorised preservation, transfer or deletion process.

Does ticking every box prove access was removed?

No. The boxes help coordinate work. Completion should be supported by system records, supplier confirmations, returned-asset records, exception tracking and an accountable review.

Need a repeatable process?

Turn the checklist into managed account operations.

ACA can help connect people-change approvals to identity, devices, cloud services and evidence, with a process that fits the way your organisation actually works.

Explore managed IT support