How to review record access when staff leave
Remove unneeded access, transfer operational ownership and account for shared devices and integration credentials during a staff departure.
A staff departure affects more than one login. The person may own template updates, receive support mail, manage a shared tablet or know where PDF exports are stored. Review the whole operational role while removing access that is no longer needed.
List the access and responsibilities
Identify the person's account, role, location access and any shared-device responsibilities. Include exports or shared folders used in their work. Record who will own active templates and unresolved signing issues after the handover.
Keep the review factual. You do not need to copy participant records into a departure checklist to explain which responsibilities are transferring.
Change access through the proper controls
Use the organization's account and permission process to remove or reduce access at the appropriate time. If credentials were shared, replace that practice with named access where possible and coordinate any necessary credential change.
Integration keys deserve separate attention. A key named after a former employee may still serve an active booking system. Identify its purpose before revoking it, then follow credential rotation if ownership or exposure requires a replacement.
Verify the handover
Confirm the remaining owner can manage the intended forms, retrieve records and handle guest questions. Check shared devices so a departing employee's staff session is not left available at reception.
Document the completed access changes and any outstanding work. Revisit exported copies under the organization's handling process; removing an app login does not automatically remove files previously downloaded elsewhere.
Check the places a login review can miss
Use a short ownership table for the departure. Fill it with your actual systems rather than assuming that one account change covers everything.
| Access or responsibility | What to verify | Evidence to keep |
|---|---|---|
| Named app account | The person no longer has the access their role does not require | Account and role reviewed, change time and reviewer |
| Reception devices | Staff sessions are closed and the participant route still works | Devices checked and any follow-up owner |
| Export folder | Shared storage permissions match the remaining team | Folder owner and access review outcome |
| Integration credential | The booking or reporting workflow has an accountable owner | Integration name and rotation outcome, never the secret |
| Support and template work | Open requests and pending edits have been transferred | Next action and responsible role |
For a routine departure, test the replacement owner's access before the outgoing person's last shift ends. For example, have the incoming manager find a sample record and locate the active template without using someone else's session. If they cannot do the task, resolve their own permissions instead of retaining a shared login as a workaround.
Do not paste tokens, passwords or participant PDFs into the checklist. A record of what was changed is enough; the checklist should not create another place where access credentials need protection.
Before you call it ready
- Account and location access were reviewed.
- Template and support responsibilities have a new owner.
- Shared devices do not retain an inappropriate staff session.
- Active integration keys were identified before changes.
Common questions
Should we revoke every key associated with the employee immediately?
Assess the situation and the purpose of each key. For routine handovers, coordinate replacement so active integrations keep working. Suspected exposure can require immediate containment through your incident process.
Does removing a login delete exported PDFs?
No. Treat exported copies as separate stored information and follow your organization's access and retention process for their destinations.
Useful next steps
A clear process. A better start.
Build your form, try the guest experience, and give your team a workflow they can follow.