What This Guide Covers
This guide gives you a straightforward process for one of the most effective security habits you can build. You will learn what an access review is and why it’s a critical, non-negotiable task for protecting your business. We will identify the specific security risks that build up over time when old user accounts and permissions are left active. You will get clear guidance on how to decide which of your company’s systems and accounts need to be reviewed first. This article provides a step-by-step plan you can follow to complete your first review without needing special tools or a big budget. You will also understand who in your organization needs to be involved to make sure the review is accurate and complete. Finally, we’ll cover how to turn this one-time task into a simple, repeatable annual habit.
What is an Annual Access Review (and Why Do You Need One)?
An annual access review is a methodical process of checking who has permission to use your company’s digital resources. Think of it like a master key inventory for your entire business. You are systematically checking who has a key to your email server, your financial software, your customer list, and your shared files.
The goal is simple: ensure that only the right people have the right access to do their jobs. Anyone who has left the company, changed roles, or is a long-forgotten contractor should have their “digital keys” taken back.
For a small business, this isn’t a complex corporate audit. It’s a practical necessity. Over time, every organization accumulates old accounts and outdated permissions. An employee leaves, but their account in your project management tool remains active. A contractor finishes a project, but their access to your shared cloud drive is never removed. Someone moves from sales to marketing, but they keep their administrative access to the sales Customer Relationship Management (CRM) software.
Each of these leftover accounts is a potential security risk. An access review is your chance to find and fix these problems before they can be exploited. It is a foundational security practice that directly reduces your risk of a data breach, fraud, or accidental data loss. You don’t need fancy software; you just need a plan and a few hours set aside each year.
Why Do Old Permissions Matter for Your Small Business?
It’s easy to dismiss old accounts as harmless digital clutter. In reality, they are unlocked doors waiting for someone to walk through them. The risks they pose to a small organization are real and can be significant.
First is the risk from former employees and contractors. When someone leaves your company, their relationship with you changes. Even if they leave on good terms, their continued access to your systems is a liability. Their old password could be weak or reused on other sites that get breached, giving an attacker an easy way into your network. A disgruntled former employee could intentionally access, delete, or steal sensitive data. Removing their access immediately upon departure is ideal, but an annual review serves as a critical safety net to catch any accounts that were missed.
Second is the problem of internal permission bloat, often called “privilege creep.” This happens when employees change roles within your company. They gain new permissions for their new job but rarely have their old, unneeded permissions removed. A person who moved from customer service to accounting might still have access to every customer support ticket. An employee promoted to manager still has access to the entry-level tools they no longer use. This violates a core security principle called the “Principle of Least Privilege,” which states that a user should only have the absolute minimum permissions required to perform their job. The more unnecessary access an employee has, the more damage can be done if their account is ever compromised by a hacker.
Third, these old accounts are a prime target for external attackers. Hackers actively search for dormant or forgotten accounts because they are less likely to be monitored. If an attacker gains control of a former employee’s email account, they can use it to send convincing phishing emails to your current staff or reset passwords for other, more critical systems. The account acts as a foothold inside your organization.
Finally, failing to manage access can create compliance and legal problems. If your business handles sensitive information—like customer financial data, patient health records, or personal information covered by privacy laws like the General Data Protection Regulation (GDPR) or the California Consumer Privacy Act (CCPA)—you have a responsibility to protect it. Demonstrating that you regularly review and limit access to that data is a key part of meeting those obligations. An access review creates a record that you are performing due diligence to safeguard sensitive information.
How Often Should Your Business Review Access?
The name “annual access review” suggests the right frequency, and for most small businesses, once a year is the perfect starting point. An annual schedule is frequent enough to catch problems before they become severe but not so frequent that it becomes an overwhelming burden.
An annual review provides a predictable rhythm. You can schedule it for the same time each year, such as during a slower business period or at the beginning of the fiscal year. This consistency helps turn the process from a reaction to a proactive habit.
However, an annual schedule is a baseline, not a rigid rule. You should consider more frequent reviews for specific situations:
- Highly Sensitive Systems: If you have systems that contain extremely sensitive data—your primary accounting software, the database with all your customer information, or servers with proprietary trade secrets—a quarterly or semi-annual review is a better practice. The higher the risk, the more often you should check the locks.
- High Employee Turnover: If your business experiences high turnover in certain roles (like seasonal staff, interns, or specific departments), you should review access for those roles more frequently. It may be practical to review the accounts for that group at the end of each season or semester, rather than waiting a full year.
- After a Security Incident: If your company experiences any kind of security breach or even a close call, an immediate, full access review should be part of your response plan. You need to verify exactly who has access to what as you work to secure your systems.
For everything else, stick to the annual plan. The goal is to create a sustainable process. It is far better to complete a thorough review once a year than to plan for quarterly reviews and never get them done because you’re too busy. Start with an annual cadence and adjust only if you have a specific, high-risk reason to do more.
What Systems and Data Should You Review?
The first step in an access review is knowing what you need to review. For a small business, the list can feel long, but it’s manageable if you break it down into categories. Your goal is to identify every place where user accounts are created and permissions are assigned. Start by making a simple list.
Here are the common categories to think through:
1. Core Communication and Collaboration Platforms
This is the heart of your daily operations. Access here is powerful, as these accounts often control identity and can be used to reset passwords for other services.
2. Financial and Administrative Systems
Compromise of these systems can lead to direct financial loss. Access should be tightly controlled.
3. Customer and Operations Systems
These platforms contain your valuable customer data and intellectual property.
4. Website and Marketing Assets
These accounts represent your public-facing brand and digital presence.
To make this process more concrete, here is a simple framework for organizing your review.
| Concept | What It Means | Why It Matters | What To Do Next |
|---|---|---|---|
| Inventory Systems | Make a list of every piece of software or online service your business uses that requires a user login. | You can’t secure what you don’t know you have. This list is the foundation of your entire review. | Create a simple spreadsheet with columns for System Name, Purpose, and Who Manages It. |
| Identify Owners | For each system, name the person in your company who is responsible for it. For QuickBooks, it might be your bookkeeper. For the website, your marketing lead. | The system owner is the best person to know who should and should not have access. You can’t make these decisions alone. | Add an “Owner” column to your spreadsheet and fill it in for each system. |
| Prioritize by Risk | Rank your list of systems from most critical to least critical. Financial and core email systems are almost always at the top. | If you have limited time, you must focus on the systems that pose the greatest risk to your business if compromised. | Start your review with your top 3-5 most critical systems. Tackle the rest later if needed. |
| Extract User Lists | For each high-priority system, go into the administrative settings and find the list of users with access. | You need a complete list of every single account—active, suspended, or otherwise—to review. | Export the user list from each system. Most services offer a “Download as CSV” or similar option. |
A Simple Step-by-Step Guide to Your First Access Review
This process does not require specialized technical skills. It requires diligence and a methodical approach. Follow these steps for each critical system you identified.
Step 1: Get the List of Users
Log in to the system as an administrator. Navigate to the user management section (this might be called “Users,” “Team,” “Manage Access,” or “Permissions”). Find the option to view all users and export the list, preferably as a spreadsheet (CSV or Excel format).
The exported list should ideally include the user’s name, email address, their permission level (e.g., “Admin,” “Editor,” “User,” “Viewer”), and the date of their last login. The last login date is incredibly helpful for spotting dormant accounts.
Step 2: Review for Recognition
Open the spreadsheet. Read through the list of names and email addresses. For each user, ask a simple question: “Do I know who this person is, and should they have access to this system?”
Your first pass is to identify obvious removals. This includes:
Highlight anyone who should be removed immediately. If you don’t recognize a name, ask the system’s owner or a long-term employee for help identifying them.
Step 3: Review for “Least Privilege”
Now, go through the list again, this time focusing on the current employees. For each person, look at their permission level and ask: “Does this person need this level of access to do their current job?”
This is where you correct for privilege creep. The goal is to enforce the Principle of Least Privilege.
Be critical here. Downgrade permissions to the minimum required. It’s always possible to grant more access later if needed, but it’s much harder to undo the damage from an account with excessive permissions that gets compromised. We often grant all permissions “just in case”. This can create an overwhelming number of choices in the interface for a user that has specific duties. This also makes it easier for someone to accidentally break something.
Step 4: Take Action
You have your two lists: accounts to be removed entirely and accounts that need their permissions reduced. Now, log back into each system and make the changes.
Allocate enough time to complete the process in one go. The value of the review is in the action you take. Block the access now.
Step 5: Document Your Review
The final step is to create a simple record of what you did. This doesn’t need to be a formal report. A simple text file or a new sheet in your spreadsheet is fine. Record the date of the review, the system you reviewed, and a summary of the actions taken (e.g., “Removed 3 former employees, downgraded 2 admin accounts to user level”).
This documentation is invaluable. It serves as proof of your due diligence for compliance purposes, and it makes next year’s review much faster because you can see what you did last time.
Who Should Be Involved in the Review Process?
In a very small business, the owner might be the only person involved. However, as soon as you have a few employees, an access review becomes a team effort. Trying to do it alone is a mistake, as you likely don’t have the full context for every person’s role and access needs.
There are three key roles in a successful access review:
1. The Owner/Coordinator: This is the person responsible for making sure the review actually happens. In most small organizations, this is the business owner, a general manager, or an office manager. They schedule the review, keep track of the systems list, and ensure the final actions are taken. They are the project manager for the review.
2. The System or Data Owner: This is the person who best understands a specific system and its users. The “owner” of your accounting software is likely your bookkeeper or CFO. The “owner” of your CRM is your head of sales. When reviewing a specific system, you must involve this person. They are the only one who can definitively say whether a particular salesperson still needs access or if an accountant’s permissions are appropriate.
3. The IT Resource: This is the person who physically makes the changes. It could be an internal employee with administrative skills, a trusted managed service provider (MSP), or a freelance IT contractor. They are the ones who will log in to Microsoft 365 or Google Workspace to disable accounts and change permissions.
The process works best when the Coordinator works with each System Owner to review their specific user lists. The System Owner provides the decisions (“remove this user, downgrade that one”), and the Coordinator then hands the finalized action list to the IT Resource to implement.
Making Access Reviews a Regular Habit
A one-time cleanup is good. A repeatable, annual process is great. The key to making access reviews a sustainable habit is to reduce the friction and make it as easy as possible to do it again next year.
First, schedule it now. While the memory of your first review is fresh, open your calendar and schedule your next one for a year from now. Create an all-day event titled “Annual Security and Access Review.” Invite the other key people who were involved. A scheduled event is much harder to ignore than a vague intention.
Second, use your documentation from this year. The systems list you created is your template for next year. The notes on who you removed and why provide valuable context. You are not starting from scratch next time; you are updating your previous work. Store this documentation in a safe, central location where you can easily find it in 12 months.
Third, integrate it with other business processes. The best way to keep your user lists clean is to handle access changes as they happen. Create simple checklists for employee onboarding and offboarding. The offboarding checklist should include a line item for every single system the employee had access to, ensuring their accounts are disabled on their last day. This “point-in-time” maintenance dramatically reduces the cleanup work you’ll have to do during your annual review.
In practice, the annual review then becomes a checkup to ensure your day-to-day processes are working and to catch anything that was missed. It’s your safety net, not your primary tool for removing access.
The Bottom Line
If you do nothing else, perform an annual access review on your three most critical systems. For nearly every small business, this means your core email platform (Microsoft 365 or Google Workspace), your primary file storage (OneDrive, Google Drive, Dropbox), and your main financial software (QuickBooks, Xero). These three areas contain your most sensitive communications, your operational data, and the keys to your financial kingdom.
Start there. Use the step-by-step guide in this article to review just those three systems. The process will likely take only a few hours and will immediately and significantly reduce your organization’s security risk. It is one of the highest-impact security activities you can perform for the time invested. Do not wait for a security incident to force your hand.
Frequently Asked Questions
What is “privilege creep” and why is it a problem?
Privilege creep is the gradual accumulation of unnecessary access rights by employees as they change roles over time. It’s a problem because it violates the “Principle of Least Privilege,” increasing the potential damage if that employee’s account is ever compromised by an attacker.
Do I need special software to do an access review?
No. For a small business, you do not need any special software. A spreadsheet to track your systems and the built-in user management tools within each of your applications are all that is required to conduct a thorough and effective review.
How long does an access review take for a small business?
For a business with under 50 employees, a focused review of the most critical systems can often be completed in two to four hours. The first time takes the longest because you have to create your systems list. Subsequent annual reviews are typically much faster.
What happens if we find unauthorized access?
If you find an active account that you believe is being used by an unauthorized person, you should immediately disable the account to block access. Then, investigate its recent activity to see what, if anything, was accessed or changed. This may require you to treat it as a security incident.
Who is responsible for access reviews in a small business?
The owner is legally on the hook, but if you don’t name one specific person to actually run the review, it doesn’t happen. If you use an IT provider, don’t assume it’s on their checklist unless it’s written into the contract.
Put the review on next quarter’s calendar now, before this falls off the list again.
