Access control: what to get right first
Most teams know this matters. Fewer have decided who owns it. If you only fix one thing about access control this quarter, make it the first item below.
The realistic threat for most small businesses is automated and opportunistic, not targeted. Assume whoever inherits this will have half your context and none of your patience.
Start here
Give the least access that lets someone do their job. It is worth being explicit about, because assumptions differ quietly. It is the sort of thing that looks like polish right up until it costs you an enquiry.
Then this
Review who has access when people change roles. There is a version of this that is over-engineered, and it is worth avoiding. It is the sort of thing that looks like polish right up until it costs you an enquiry.
Eventually
Shared logins destroy accountability. None of that requires a large budget, only a decision and someone to own it. The practical test is whether someone new to the project could tell, in a minute, that it had been handled.
The short version
Security is a maintenance habit rather than a purchase, which is why it drifts. Three things worth confirming about access control before you move on:
- Someone can say what the current setup is without going to look
- Shared logins destroy accountability — and you know whether that is true here
- There is a way to tell whether the last change to this helped
If you want a second opinion on how yours is set up, ask.