FREE TEMPLATE
Access Control Policy
Onboarding, role changes and departures. The one that answers what the last five leavers can still reach — with the departure checklist written out.
[COMPANY NAME]
Effective date: [DATE] · Owner: [NAME, TITLE] · Review: annually, or after any material change
Purpose
Most small businesses can tell you who works there. Far fewer can tell you what those people can reach, or what the last five leavers can still reach. This policy sets out how access is granted, changed, reviewed and removed.
Scope
Applies to every system holding company data or supporting company operations, and to every employee, contractor, temporary worker and vendor who is granted access to one.
Principles
Least privilege. People get the access their role requires, and nothing else. “It’s easier to give everyone access” is how a single phished mailbox becomes a company-wide incident.
Role-based. Access is assigned by role, not negotiated per person. A new bookkeeper gets the bookkeeper’s access.
Documented. Every grant, change and removal has a written request and a record of who approved it. If you cannot produce that record, you do not have access control — you have a habit.
Reviewed. Access is verified on a schedule, not assumed to be correct because it was correct when it was granted.
System inventory
[POLICY OWNER] maintains a list of every system holding company data, with a named business owner for each and a note of what kind of data it holds.
You cannot control access to systems you have not written down. Include the ones nobody thinks of: the domain registrar, the DNS provider, the payroll portal, the bank, the insurance portal, the state filing account, social media, the website admin, the copier, the alarm and camera systems.
Onboarding
Before a new person’s first day, their manager submits an access request naming the role, the start date, and any access beyond the standard role profile with a reason.
[POLICY OWNER OR IT PROVIDER] creates accounts with the standard profile, enables MFA, issues credentials through the password manager, and records what was granted.
The new person reads and signs the Acceptable Use Policy before receiving access.
Role changes
A role change is an access change in both directions. The manager submits a request specifying what is being added and what is being removed.
Accumulated access from prior roles is the most common finding in any access review. Someone who has moved through three departments should not still be able to reach all three.
Departures
Departures are the single highest-risk access event, and the one small businesses most often handle informally. They are handled formally here.
On or before the final day:
- Disable — do not delete — the user’s accounts, so their mail and files remain recoverable
- Reset the password and revoke active sessions and tokens, so an open laptop or phone stops working
- Remove MFA devices registered to the person
- Forward or delegate the mailbox to a named person for [NUMBER] days
- Transfer ownership of files, folders and documents the person owned
- Remove the person from shared vaults, and change any shared credential they knew
- Remove building access, alarm codes and keys
- Collect all company equipment, and record what came back
- Remove the person from vendor portals, the bank, and any account where they were a named contact
- Remove them from the website, the phone system and public listings
Within [NUMBER] days: confirm every item above was completed, and record the confirmation.
For an involuntary departure, access is removed before or during the conversation, not after it.
Access reviews
At least quarterly, [POLICY OWNER] reviews every system on the inventory and confirms that each account still belongs to a current person in a current role, that administrative rights are still justified, and that no account belongs to someone who has left.
The review is recorded — date, systems reviewed, what changed. This record is what an insurer or auditor will ask for, and it is the single cheapest piece of evidence you can produce.
Third parties and vendors
Vendors get their own named accounts, never a shared login and never a staff member’s credentials. Access is scoped to what the engagement requires and has an end date matching the contract.
When an engagement ends, vendor access is removed on the same schedule as an employee departure.
Exceptions
Exceptions must be requested in writing from [POLICY OWNER] and documented with a business reason, a compensating control and an expiration date.
Enforcement
Managers who do not submit departure notices, and administrators who grant access without a documented request, are in violation of this policy. Violations may result in disciplinary action up to and including termination.
Review
Reviewed at least annually by [POLICY OWNER], and after any incident involving unauthorized access.
Acknowledgment
I have read and understood the [COMPANY NAME] Access Control Policy, and I agree to follow it.
Name: ______________________________
Signature: __________________________
Date: ______________________________
Template provided free by Cybertitans LLC, Woodbury, Minnesota. It is a starting point, not legal advice, and it has not been reviewed against your contracts, your industry’s regulations or your state’s employment law. Have counsel review it before you adopt it. Downloading or using this template does not create a client relationship with Cybertitans, and Cybertitans makes no representation that adopting it satisfies any insurer, regulator, auditor or customer requirement.
EDITABLE VERSION
Want the Word version you can edit?
The policy above is free to read, copy and adapt — that is the point of publishing it. The Word file is the same text with every fill-in field marked, our formatting, and the signature block ready for your team to sign. Tell us where to send it.
Free. About 20 seconds.
Where should we send it?
THE REST OF THE SET
Nine more, and someone to run them.
This is one of ten free templates written for businesses with no IT department. The others are on the resource library, and the editable Word versions are a name and an email away.
A policy nobody operates is a document. If you would rather someone owned this — and the offboarding, the backups and the MFA behind it — that is what TiTAN is.
