Getting started with access control
We end up explaining this on discovery calls often enough that it deserved writing down. A short on-ramp to access control for teams who have not touched it before.
Security is a maintenance habit rather than a purchase, which is why it drifts. It rarely shows up as a line item, which is exactly why it slips.
Why this earns attention
Give the least access that lets someone do their job. The reasoning matters more than the rule, because the rule has exceptions. Most teams find the first pass takes an afternoon and the maintenance takes minutes a month.
Your first week
- Find out what is already in place
- Review who has access when people change roles
- Change one thing and measure it
Shared logins destroy accountability. In practice this is a scheduling problem more than a technical one. It is the sort of thing that looks like polish right up until it costs you an enquiry.
What this looks like day to day
The realistic threat for most small businesses is automated and opportunistic, not targeted. Three things worth confirming about access control before you move on:
- Someone can say what the current setup is without going to look
- Review who has access when people change roles — and you know whether that is true here
- There is a way to tell whether the last change to this helped
None of this needs a rewrite. Most of it is a morning's work once someone decides to do it.