A former employee can still access a shared mailbox. A volunteer who helped with one event can still see supporter records. An administrator may have more access than their day-to-day role needs, simply because it was quicker to grant it at the time. These are common findings when organisations learn how to audit user access properly – and they are usually fixable without causing a fuss.

For small businesses, charities and community groups, access reviews can feel like a big-business exercise. They are not. They are a sensible housekeeping task that helps protect confidential information, reduces the risk of accidental changes and gives your team clearer control over the systems they rely on.

Why user access deserves a regular check

User access is the combination of accounts, permissions and tools a person can use. That may include Microsoft 365, email, shared files, finance software, your website, cloud storage, contact databases, Wi-Fi, devices and line-of-business systems.

Over time, access builds up. Someone changes job, covers a colleague’s absence or takes on a temporary project. They are given a new permission, but the old one is not removed. This is sometimes called permission creep, and it is one of the most common causes of unnecessary security exposure.

The risk is not only malicious activity. A well-meaning colleague with too much access can accidentally delete a shared folder, send information to the wrong place or alter a setting that affects everyone. For charities, this can involve sensitive beneficiary or donor information. For SMEs, it can mean customer data, payroll details or commercially confidential documents.

A clear audit also makes life easier when someone leaves, when you need to demonstrate good security practice, or when preparing for Cyber Essentials. Rather than scrambling to work out who has access to what, you already have a current record and a process that people understand.

How to audit user access step by step

The aim is not to remove access at random. It is to make sure each person has the access they need to do their job, and no more. This principle is often called least privilege, but in practical terms it means keeping things proportionate.

Start with the systems that matter most

Make a list of the systems that hold important information or affect your day-to-day operations. Begin with your identity platform and email system, as these often provide the key to everything else. Then include shared drives, cloud applications, finance and HR platforms, CRM systems, website administration, remote access tools and any specialist software your organisation uses.

Do not overlook less obvious accounts. A shared social media login, online booking platform, domain registrar, photocopier address book or broadband router can all cause problems if access is unmanaged. If the list feels daunting, start with the services that contain personal, financial or confidential information and work outwards.

Build a simple list of people and accounts

Next, compare your staff, trustees, volunteers and regular contractors against the accounts that exist. Your list should show the person’s name, their role, the system, their account type and their level of access.

This exercise often reveals duplicate accounts, generic logins and accounts belonging to people who left some time ago. Generic accounts need particular attention. They make it difficult to tell who made a change or accessed information. There can be a legitimate operational reason for a shared account, particularly for a small team, but it should be the exception and controlled carefully.

Ask managers or service owners to confirm who is still active. An IT provider can identify technical accounts, but only the people running the organisation can confirm whether an individual still needs a particular tool or folder.

Check access against the role, not the person

For each active user, ask a straightforward question: what do they need to do their job effectively?

A finance lead may need access to accounting software and payroll records. A fundraising volunteer may need a limited view of a contact system but no access to financial details. An external web designer may need website access for a defined period, but not unrestricted access to your whole Microsoft 365 environment.

This is where judgement matters. Giving everybody the lowest possible level of access can create delays and frustrate staff. Giving everybody administrator rights because it is convenient creates a much larger risk. The sensible middle ground is role-based access: permissions are assigned according to the responsibilities of a role, then reviewed when that role changes.

Pay close attention to administrator accounts. Global administrators, finance approvers, password reset permissions and access to security settings carry more risk than everyday user accounts. Keep the number of people with these permissions small, record who they are and make sure they use multi-factor authentication.

Look for the gaps that cause trouble

Once you have a list, look specifically for warning signs. These include inactive accounts, former staff, excessive administrator rights, external users with no end date, accounts without multi-factor authentication and shared mailboxes or folders with unclear ownership.

Also check whether access was granted directly to individuals when a group would be easier to manage. For example, a “Finance Team” group is simpler to review than manually adding five people to each finance folder. Groups are not always necessary for a very small organisation, but they become valuable as teams grow or responsibilities change.

Review access from outside your organisation too. Guests in Microsoft 365, third-party support companies and contractors may all have valid access. The key is to know why it exists, who approved it and when it should be reviewed or removed.

Remove, reduce and record

Where access is no longer needed, remove it promptly. Where it is broader than necessary, reduce it to the appropriate level. Before making significant changes, speak to the affected user or manager, especially where access supports a time-sensitive process such as payroll, grant reporting or event bookings.

Record what you changed and why. A simple spreadsheet is often enough for smaller organisations, provided it is stored securely and kept up to date. Include the date of review, the person who approved the decision and the next review date. This creates an audit trail and stops the same questions being asked from scratch next time.

For higher-risk changes, such as removing administrator rights or disabling a long-standing account, have a basic rollback plan. You may need to restore access quickly if a critical task has been missed. Careful planning avoids security improvements becoming an unexpected disruption.

Make access reviews part of normal housekeeping

A one-off clean-up is useful, but access changes whenever people join, leave, change roles or begin working with a new supplier. The best protection is a simple joiner, mover and leaver process.

When someone joins, agree what systems they need and who approves access. When their role changes, review what should be added and what should be removed. When they leave, disable access promptly, collect organisation-owned devices and arrange mailbox or file handover where needed. This is particularly important for volunteers and temporary workers, where start and end dates can be less formal.

How often you carry out a full review depends on your organisation. A small team with a handful of systems may be well served by a six-monthly review, plus checks whenever staff change. An organisation handling highly sensitive information, or one with many volunteers and contractors, may need quarterly checks. The right frequency is the one your team can maintain consistently.

Keep the conversation human

Access audits can make people worry that they are being monitored or that IT is making their work harder. Frame the review clearly: it is about protecting the organisation, its people and the information entrusted to it. Invite staff to flag access they rely on before it is changed.

This also uncovers useful operational knowledge. A colleague may explain that a shared folder is used by a project team, or that an old account still receives important supplier messages. Those details help you make safer decisions than a purely technical review ever could.

If your organisation is unsure where to begin, an experienced IT partner can help map your systems, identify higher-risk permissions and put a manageable process in place. At Bees Knees IT, we believe security should take the sting out of problems, not add another technical burden to your day.

A good access audit leaves your team with fewer unknowns, clearer responsibilities and a calmer response when staff or systems change. Put a date in the diary, start with your most important accounts and give yourself permission to improve the process as you go.