Team Systems
How to Set Up Team Access Management Without an IT Team
11 min read · Published 3 August 2026 · Last reviewed 11 August 2026 · Written by Kayley Hart
The short answer
Team access management is the practice of controlling who can log into each business system, at what permission level, and ensuring that access is removed promptly when someone leaves. Build a single access register listing every system, who has access, at what level, who granted it and when it was last reviewed. Review it on a fixed schedule rather than only when someone leaves, use role-based access where your tools support it, and always revoke access on someone's last working day, not whenever you next remember to.
Guide action map
Illustrative frameworkHow to Set Up Team Access Management Without an IT Team
Reviewed by a qualified professional
James Whitfield — FCCA, Chartered Certified Accountant — 18 years advising UK SMEs on employment costs, payroll and business finance. Reviewed 5 August 2026.
Author: Kayley Hart
Editorial policy & fact-checking apply.
What you will take away
- • A written access register is the foundation; without one, nobody can say with confidence who can get into what.
- • Access should be granted by role and reviewed on a schedule, not handed out ad hoc and forgotten.
- • Never share a single login between multiple people — use individual accounts with appropriate permission levels.
- • Revoking access on a leaver's last day is a security basic, not an optional nicety.
- • Financial and banking access needs tighter controls than general software access.
- • The NCSC's small business guidance is a genuinely useful, free starting point for basic security practice.
Why access drifts out of control in small teams
Access management in a small business rarely fails through a single dramatic mistake — it fails through accumulation. A freelancer is given access to the shared drive for a three-month project and stays on it two years after the project ends. A former employee's login to the accounting software is never revoked because nobody was assigned the job of checking. A shared password gets passed around so often that nobody can say for certain who currently has it.
None of this happens through carelessness in the way people usually mean it — it happens because there's no single written record of who has access to what, so there's nothing to check against and nothing that prompts a review. The single most useful thing a small business without a dedicated IT person can do is build that record and keep it current, before worrying about anything more sophisticated.
Building the access register
An access register does not need specialist software. A structured spreadsheet or a simple table, reviewed regularly, is entirely adequate for a team of two to ten. What matters is that it's complete, current and actually consulted rather than created once and forgotten.
- System or tool name (banking, accounting software, shared drive, email, CRM, social media accounts)
- Who currently has access, listed by individual account, not by shared login
- Access level (full admin, standard user, view-only, approver)
- Who granted the access and when
- Last review date and next review date
- What should happen to this access if the person leaves (immediate revocation, handover to a named colleague, or deletion)
Never enter actual passwords into an access register. It's a record of who has access, not a place to store credentials — use a dedicated password manager for those.
Individual accounts, never shared logins
Shared logins are one of the most common access shortcuts in small businesses, and one of the most costly. When several people share one login to a piece of software, there's no way to know who did what, no way to revoke one person's access without changing the password for everyone else, and no way to apply a lower permission level to someone who only needs partial access.
Almost every business tool worth using now supports individual user accounts with different permission tiers, often at little or no extra cost for a small team. Setting individual accounts up properly at the start, even for a team of two, saves a genuinely painful cleanup later, particularly once someone leaves and you realise the shared password needs to change everywhere at once.
Where a tool genuinely doesn't support multiple accounts, treat that as a security gap worth naming explicitly in your access register, along with a compensating control — such as changing the password immediately whenever anyone with access to it leaves.
Setting access levels by role, not by trust
A common and understandable instinct in a small, trusted team is to give everyone broad access because it's simpler and everyone gets on well. The problem this creates is not about trust in people's intentions — it's that broad, unnecessary access increases the damage from an honest mistake, a compromised password, or a phishing attempt that tricks someone into clicking something they shouldn't.
The better default is to give each role the access it genuinely needs to do the job, and nothing more — sometimes called the principle of least privilege. A part-time bookkeeper needs access to the accounting software and possibly view-only banking access; they do not need admin rights on your website, your email system or your social media accounts. Setting access by role, rather than by how much you like or trust someone, keeps the blast radius of any single mistake or breach much smaller.
This is also where role-based banking access is worth setting up properly rather than sharing your own login — most UK business bank accounts now let you add team members with defined permissions (view-only, ability to make payments up to a limit, or full admin) rather than forcing an all-or-nothing choice.
Reviewing access on a schedule, not just at crisis points
Most small businesses only think about access when someone leaves, which means access silently accumulates and drifts throughout everyone's employment without ever being checked. A fixed review — quarterly for a fast-growing team, twice a year for a stable one — catches the freelancer whose project ended months ago but who still has drive access, and the employee whose role changed but whose permissions never did.
A useful review question for each line in the register is simply: does this person still need this level of access to do their current job? If the honest answer is no, or you're not sure, that's a signal to reduce it rather than leave it as it is out of inertia.
Put the review date in a calendar with a named owner responsible for actually running it, the same way you would for a financial reconciliation. An access review that exists only as an intention rarely happens; one that's scheduled with an owner reliably does.
Leaver controls: the moment access must actually be revoked
Revoking access on someone's last working day, not sometime in the following weeks, is one of the simplest and most important security habits a small business can build. The risk window between someone's departure and access revocation is exactly when things go wrong — whether through a disgruntled departure, an honest oversight by the departing person, or simply an account that's no longer monitored by anyone becoming an easier target.
Build a leaver checklist that runs through every line of your access register for that person, not just the obvious accounts like email. It's easy to remember to remove someone from the email system and forget the shared drive, the CRM, the social media scheduling tool, or a login to a supplier's ordering portal that was set up once and never revisited.
Financial access deserves particular attention: remove banking access, card access and any accounting-software permissions the same day, and if the person had a payment card, cancel it immediately rather than waiting for it to be returned.
- Confirm the last working day in writing well ahead of time, so the revocation isn't a last-minute scramble
- Work through every line of the access register for that person on their final day
- Revoke financial access first — banking, cards, accounting software
- Change any shared passwords the person knew, even if they had an individual account elsewhere
- Redirect or archive their email and confirm any client-facing accounts are reassigned
- Recover physical items — laptop, phone, keys, access cards — as part of the same process
- Update the access register to reflect the revocation, with the date it happened
Starter controls: setting access up properly from day one
Access management is easier to keep clean if you get it right at the start rather than trying to tidy it up later. Before someone's first day, decide exactly what access their role genuinely requires and set it up in advance, rather than granting things reactively as they ask for them over their first few weeks — reactive access-granting is exactly how permission creep starts.
Add every new access grant to the register at the point it's created, with the date and who granted it, so the record stays live rather than becoming a project you have to reconstruct from memory every six months.
Getting the basics right without specialist tools
A small business without a dedicated IT person does not need enterprise security tooling to manage access reasonably well. A maintained spreadsheet, individual accounts wherever a tool supports them, a password manager for shared credentials that genuinely must be shared, and two-factor authentication turned on for anything financial or containing personal data will cover the large majority of realistic risk.
The NCSC's small business guidance is written specifically for organisations without dedicated security staff and is worth reading in full — it covers backups, malware protection, phishing awareness and password practice in plain language, without assuming any technical background.
Do it now, with a tool
Team Access Register
Records systems, access levels, owners, review dates and leaver actions, including financial access.
Open the tool (5 minutes)Founder Absence Planner
Plans cover for decisions, payments, customers and emergencies while you are away.
Open the tool (5 minutes)Team Spending Controls Builder
Builds your spending policy first — roles, thresholds, approval routes, evidence rules and leaver controls — and only then discusses mechanisms.
Open the tool (6 minutes)Frequently asked questions
Do we need dedicated software for access management at ten people or fewer?
No. A well-maintained spreadsheet, kept current and reviewed on a schedule, is entirely adequate at this size. The discipline of maintaining it matters far more than the sophistication of the tool it lives in.
How quickly should access be revoked when someone leaves?
On their last working day, not afterwards. Financial access — banking, cards, accounting software — should be revoked first, ideally before the rest of the working day ends.
Is it ever acceptable to share a single login between team members?
Try to avoid it wherever the tool supports individual accounts, which most modern business software does. Where it genuinely can't be avoided, treat it as a named gap in your access register and change the password immediately whenever anyone who knew it leaves.
How often should we review who has access to what?
Quarterly for a fast-growing team, at minimum twice a year for a stable one. The review should ask, for each person and system, whether their current role still genuinely requires that level of access.
What's the single highest-priority access to control?
Banking and financial-system access, followed by anything containing customer or staff personal data. Get those two right first if you're building an access register from nothing.
Should freelancers and contractors be in the same access register as employees?
Yes — access risk doesn't depend on employment status. Freelancer access is actually more likely to be forgotten once a project ends, so it deserves at least the same review discipline as employee access, arguably more.
Continue from here
Choose the related decision that comes next for your team.
- Continue with How to Manage Starter and Leaver Controls Properly
- Continue with How to Create a Small Business Operations Manual
- Continue with How to Create a Team Spending Policy
Sources & Citation
Cite this guide
Hart, K. (2026) "How to Set Up Team Access Management Without an IT Team". The Small Team Builder. Available at: https://www.kayleyhart.co.uk/guides/how-to-set-up-team-access-management-without-a-full-time-it-person
Rates, thresholds and rules change. Confirm anything financial or legal on the source before you act on it.
