Somewhere in your stack, right now, a login belongs to someone who doesn't work with you anymore. The contractor from last spring who still has the shared drive. The employee who left in March whose email forwards somewhere nobody remembers configuring. The freelancer who set up your analytics and is still listed as an administrator. None of this was negligence — every one of those accounts was created for a good reason on a busy day. But accounts are created at the speed of onboarding and removed at the speed of never, and the gap between those two speeds is where small companies quietly accumulate their largest unexamined risk.

Big companies run quarterly access reviews because auditors make them. Nobody makes you — which is exactly why the audit is worth an afternoon: you are almost certainly carrying access debt right now, and unlike most debt, this kind costs nothing to retire once you can see it.

Build the grid from the money, not from memory

Don't start by listing people — memory is the thing that failed. Start from your subscription list, because every tool you pay for has a user list that remembers better than you do. For each tool, open its members or users page and write down every account you find. The output is a grid: tools down one side, every name you encounter across the top — including, and especially, the names that make you say “wait, why is she still in here?” That sentence is the audit working. Expect three finds on the first pass: orphans (people who left), over-grants (current people with admin rights they never needed), and mystery accounts (logins nobody can explain — often an agency, a trial, or a former tool wearing an integration's name).

Kill in the right order

Orphans first, and among orphans, admins first — a departed user with administrator rights on your email, your payment tools, or your customer data is the single worst line on the grid. Before deleting anyone, check what they own: files, scheduled reports, integrations, and automations often ride on a personal account, and deleting the account can silently kill the automation (this is the classic access-audit injury — transfer ownership first, then remove). Over-grants get downgraded, not deleted: most people need member, few need admin, and every admin seat is one phishing email away from being your problem. Mystery accounts get one short investigation and then removal — if nothing breaks in a week, the mystery is solved.

The shared-password problem

Every small company has a few logins that are really a sticky note: the social media accounts, the domain registrar, the one tool that charges per seat so everyone shares. Sharing may be a defensible cost decision, but an unmanaged shared password is an account you can never take back — when someone leaves, they leave with it, and rotating it is the step everyone skips. The fix costs an hour: put shared credentials in a password manager with shared vaults, so access rides on the person's vault membership instead of on what their memory took with them. Then rotating one password on departure is a checkbox, not an archaeology project.

Make offboarding close what onboarding opened

The audit fixes the past; the checklist prevents the sequel. The mechanism is symmetry: the same list that grants access on day one revokes it on the last day. Keep one page per person — the tools they were added to, kept current when anything is granted — and offboarding becomes reading the page backward: transfer ownership, revoke seats, rotate the shared credentials they touched, redirect their email. Your systematization plan already argues functions should run on checklists instead of memory; access is simply the function where forgetting has the sharpest teeth. And the departed person deserves the symmetry too — clean, same-day revocation is professional; discovering in November that they could still read the numbers is a mess for both of you.

Put a date on the repeat

Access debt regrows at the speed of hiring, tool adoption, and one-off favors. Twice a year is enough for a small company: the same grid, refreshed, on a calendar entry — conveniently the same rhythm as the renewal calendar, and the two reviews feed each other, since a tool with no active users is a cancellation candidate and a cancelled tool is one less user list to audit. Fifteen minutes per tool, twice a year, keeps the afternoon-sized cleanup from ever being needed again.

The bottom line

Your tools remember everyone you have ever worked with; your memory doesn't, and the gap is standing access for people who have no business holding it. One afternoon builds the grid from your subscription list, kills the orphans in the right order, downgrades the accidental admins, and moves the sticky-note passwords into managed vaults. One page per person makes every future departure a checklist instead of a leak. None of it needs a security team — it needs the same discipline as the rest of your back office: see it, close it, calendar it.

— Tom

Access that closes itself

The ByDesign suite ties accounts to people from day one — onboarding grants from a checklist, offboarding reads it backward, and the audit grid stays current instead of becoming an afternoon.

See the suite →

About the author

Tom Christian is the founder of TranscendByDesign, an AI-native operations suite built for SMBs and lean teams.

He built four production AI SaaS products from zero as a solo founder. Twenty years of practitioner work in CX, L&D, and operations at Guardian Life, Horizon Blue Cross Blue Shield, ConnectiveRx, LiveProcess, and TMP Direct before that. He writes about AI-native architecture, the SMB software stack, build vs buy decisions, and the operating discipline of solo founders shipping at scale.