Skip to content
Kayley HartThe Small Team Builder

Team Systems

How to Manage Starter and Leaver Controls Properly

10 min read · Published 3 August 2026 · Last reviewed 11 August 2026 · Written by Kayley Hart

The short answer

Starter and leaver controls are the written checklists that ensure every new employee is granted the right access and every departing employee has all access removed, consistently and completely. Use the same written checklist every time someone joins or leaves, covering accounts, cards, equipment, data access and building or physical access, with a named owner for each item and a confirmed completion date. Set up starter access in advance of day one rather than reactively, and treat leaver revocation as happening on the last working day, not sometime after.

Guide action map

Illustrative framework

How to Manage Starter and Leaver Controls Properly

How to Manage Starter and Leaver Controls ProperlyA practical four-part route through this topic. Use the guide’s detailed sections to turn each stage into a decision, a written rule and a repeatable routine.1Map workClarify the outcome2DocumentMake the rule visible3Share accessUse it in real work4MaintainCheck the evidence
A practical four-part route through this topic. Use the guide’s detailed sections to turn each stage into a decision, a written rule and a repeatable routine.

Reviewed by a qualified professional

James Whitfield — FCCA, Chartered Certified Accountant — 18 years advising UK SMEs on employment costs, payroll and business finance. Reviewed 5 August 2026.

Author: Kayley Hart

Editorial policy & fact-checking apply.

What you will take away

  • • A written, repeatable checklist prevents the most common failure: forgetting one account or one card out of many.
  • • Set up new-starter access in advance of their first day so it doesn't leak into an ad hoc process over their first weeks.
  • • Revoke leaver access on their actual last working day, financial access first.
  • • The same checklist should be used every time, regardless of how amicable or routine the departure feels.
  • • Data protection obligations apply to what you keep and delete about a leaver, not just their system access.
  • • Physical items — laptops, cards, keys — need the same discipline as digital access.

Why an inconsistent process is where mistakes hide

Starter and leaver mistakes rarely happen because someone deliberately skips a step — they happen because the process differs slightly every time, run from memory rather than from a written list. One leaver's departure gets handled thoroughly because it happened during a quiet week; the next gets rushed because three other things were happening at once, and an account or a card gets missed entirely.

The fix is a single written checklist, used identically every time regardless of how the departure or arrival feels emotionally, and regardless of how busy the week is. A written checklist doesn't get tired, doesn't forget the one shared login that was set up eighteen months ago for a project nobody remembers, and doesn't vary its rigour based on how the week is going.

Setting up a new starter's access before day one

New-starter access should be decided and set up before their first day, based on what their role genuinely requires, rather than granted reactively as they ask for things during their first few weeks. Reactive access-granting is where scope creep quietly starts — someone gets given broader access than they actually need because it was faster than working out the precise level required at the time.

Before day one, agree exactly which systems the role needs, at what permission level, and prepare the accounts so they're ready to use from the first morning rather than becoming a first-week task that competes with everything else a new starter needs to absorb. This also makes their first day noticeably smoother, which matters more to how quickly someone settles in than it might seem.

  • Confirm systems and permission levels needed for the role before the start date
  • Set up individual accounts, not shared logins, wherever the tool supports it
  • Prepare equipment (laptop, phone, access card) so it's ready on day one
  • Add the new access to your access register at the point it's created, with the date
  • Brief the new starter on where core documentation — SOPs, the knowledge base — actually lives, on their first day

The leaver checklist

A leaver checklist should run through every category of access and physical item the person held, not just the obvious ones like email and a laptop. Cross-check against your access register rather than relying on memory, since memory is precisely what fails when someone's been in the role for years and has accumulated access to things nobody actively thinks about any more.

  1. Confirm the last working day in writing, with enough notice to plan the offboarding properly rather than rushing it
  2. Revoke financial access first: banking, payment cards, accounting software
  3. Work through the full access register for that person, system by system
  4. Change any shared passwords the person knew, even if they had their own individual account elsewhere
  5. Recover physical items: laptop, phone, access cards, keys, any company equipment
  6. Redirect or archive their email, and reassign any client- or supplier-facing accounts
  7. Confirm final pay, holiday balance and, if applicable, any reference process, in line with Acas guidance
  8. Update the access register and starter/leaver log to record what was done and when

Financial access should be revoked on the actual last working day, not the week after — this is the single most important line item on the list.

Handling data protection obligations for leavers

When someone leaves, you're likely still holding personal data about them — employment records, performance notes, payroll history — and you have obligations under UK data protection law about how long that's retained and how it's stored. There isn't a single universal retention period; different types of employment record have different reasonable retention periods, often tied to tax, pension or potential-claim time limits, so it's worth checking current ICO guidance rather than guessing.

Separately, decide what happens to any data the leaver created or had access to during their employment — files, customer records, correspondence — and make sure ownership and access transfer cleanly to whoever's picking up their work, while personal data specifically about the individual (rather than about the business) is handled according to your retention policy, not left indefinitely in an old email account nobody's monitoring.

Handling awkward or sudden departures without skipping steps

The temptation to skip or rush the checklist is strongest precisely when a departure is difficult — a dismissal, a sudden resignation, a departure on bad terms. These are exactly the situations where a consistent, unemotional process matters most, both to protect the business and to ensure the departing person is treated fairly and consistently regardless of the circumstances.

If a departure involves any disciplinary or dismissal element, run the leaver checklist alongside, not instead of, following fair process under Acas guidance — the practical offboarding of accounts and equipment is a separate track from the employment-law process, and rushing the offboarding doesn't excuse skipping the employment-law steps, or vice versa.

For a genuinely sudden or hostile departure, prioritise revoking financial and sensitive-system access immediately, even before the rest of the checklist is complete, and involve a professional adviser early if there's any risk of dispute.

Consistency across every departure, however routine it feels

It's tempting to relax the checklist for a departure that feels entirely amicable — someone moving on to a new opportunity, leaving on good terms after years of good work. But the risk an unrevoked login or an unreturned laptop poses doesn't depend on how the relationship ended; a forgotten account is just as much a gap whether the person left happily or not.

Running the identical checklist every time, regardless of the emotional tone of the departure, is what actually prevents the pattern where the one departure everyone assumed was 'fine' turns out to be the one where an account gets missed, simply because nobody thought it needed the same rigour.

A simple starter/leaver log

Keep a running log — even a simple spreadsheet — recording every starter and leaver, the date, who ran the checklist, and confirmation that each step was completed. This turns starter and leaver controls from a one-off task into an auditable, repeatable process, and it's genuinely useful evidence to have if a question ever arises later about when access was granted or revoked.

Review the log occasionally against your access register to confirm the two are consistent — that everyone currently listed with access is actually a current employee or contractor, and that everyone who's left no longer appears with active access anywhere.

Do it now, with a tool

Team Access Register

Records systems, access levels, owners, review dates and leaver actions, including financial access.

Open the tool (5 minutes)

Founder Absence Planner

Plans cover for decisions, payments, customers and emergencies while you are away.

Open the tool (5 minutes)

Team Spending Controls Builder

Builds your spending policy first — roles, thresholds, approval routes, evidence rules and leaver controls — and only then discusses mechanisms.

Open the tool (6 minutes)

Frequently asked questions

What's the single most important item on a leaver checklist?

Revoking financial access — banking, payment cards and accounting software — on the actual last working day. This is the item most likely to cause real damage if missed and the one most worth prioritising if time is tight.

Should starter access be set up before or after someone's first day?

Before. Deciding the access a role needs and setting it up in advance avoids the drift that comes from granting things reactively during someone's first few weeks, and it makes their first day noticeably smoother.

How long can we keep an ex-employee's personal data?

There's no single universal period; different records have different reasonable retention periods, often linked to tax, pension or potential-claim time limits. Check current ICO guidance on employment records rather than assuming a default.

Does the leaver checklist change for a dismissal versus a resignation?

The offboarding checklist itself — accounts, equipment, access — should stay the same regardless of circumstances. What changes is that a dismissal also requires following fair process under Acas guidance, which runs alongside, not instead of, the practical offboarding steps.

What about a departing freelancer or contractor rather than an employee?

The same checklist logic applies — access risk doesn't depend on employment status. Freelancer offboarding is more often forgotten precisely because there's no formal HR process triggering it, so it deserves the same discipline, if not more.

How do we make sure nothing gets missed when someone leaves?

Cross-check the leaver checklist against your access register rather than relying on memory. The register should list every system the person had access to, so working through it item by item is far more reliable than trying to recall everything from memory.

Sources & Citation

Cite this guide

Hart, K. (2026) "How to Manage Starter and Leaver Controls Properly". The Small Team Builder. Available at: https://www.kayleyhart.co.uk/guides/how-to-manage-starter-and-leaver-controls-properly

Rates, thresholds and rules change. Confirm anything financial or legal on the source before you act on it.