Every new hire in a South African business typically needs access to email, shared drives, accounting software and sometimes client databases within their first day. What happens far less consistently is the process for reviewing that access over time, or removing it entirely when someone changes roles or leaves the company. Poorly managed access is one of the quieter risks facing businesses of every size, from a five-person estate agency in Stellenbosch to a mid-sized manufacturer in Gqeberha.
Getting access management right does not require expensive software for most small and medium businesses. It requires a clear process, applied consistently, and a habit of checking that reality matches what the business intends.
The Principle of Least Privilege
The principle of least privilege means giving employees access only to the systems and data they actually need for their current role, rather than granting broad access by default because it is easier at setup. A junior bookkeeper does not need administrative rights across the entire accounting system, and a sales consultant rarely needs access to payroll records.
- Start new employees with minimal access and add specific permissions as genuinely needed
- Avoid using shared logins for multiple staff members, since this makes it impossible to trace who did what
- Separate day-to-day user accounts from administrator accounts, even for the business owner, using the admin account only when actually performing administrative tasks
Role-Based Access That Grows and Shrinks With the Business
Access needs change as employees move between roles, take on new responsibilities, or move to part-time hours. A common mistake is adding new permissions as someone's role expands, but never removing the old ones from their previous role, leaving employees with a growing pile of access rights that no longer match their actual job.
Grouping permissions by role rather than assigning them individually to each person makes this far easier to manage. When someone moves from the sales team to operations, for instance, switching their role group automatically adjusts their access, rather than requiring someone to remember every individual permission that needs changing.
Offboarding: The Step Businesses Skip
Removing access when an employee leaves is arguably the most important, and most frequently delayed, step in the entire process. A departing employee, whether leaving on good terms or not, should lose access to company systems on their last working day, not whenever someone in HR or IT gets around to it.
- Create a standard offboarding checklist covering every system the employee had access to, from email and shared drives to WhatsApp Business accounts and physical building access
- Disable rather than delete accounts initially, in case files or emails need to be reviewed afterward
- Change any shared passwords the departing employee knew, particularly for social media accounts, banking portals or supplier logins
Regular Access Reviews
Even with a good process, access lists drift over time. A quarterly review, where someone actually checks the full list of who has access to what against who should have access to what, catches accounts that were missed during offboarding, contractors whose access was never time-limited, and permissions that quietly accumulated over the years.
For businesses without a dedicated IT staff member, this review can be as simple as exporting the user list from each major system, such as email, accounting software and any shared drives, and comparing it against a current staff list once every three months.
Frequently Asked Questions
What is the principle of least privilege?
It means giving each employee only the access they genuinely need for their current role, rather than broad access by default. This limits the damage possible if an account is compromised or misused.
Should we delete or just disable an ex-employee's account?
Disable it first rather than deleting it immediately. This preserves any emails or files that may need to be reviewed or reassigned, while still preventing the departed employee from logging in.
How often should we review employee access to company systems?
A quarterly review is a reasonable minimum for most small and medium South African businesses, comparing current access lists against an up-to-date staff list to catch anything that was missed or has become outdated.
Why is shared login use a problem?
Shared logins make it impossible to trace which individual performed a particular action, and mean that removing one person's access requires changing the password for everyone using that account, which is often forgotten.
Does access management matter for very small businesses too?
Yes, arguably more so, since small businesses often have fewer safeguards elsewhere and a single compromised or misused account can have an outsized impact on the whole operation.
Conclusion
Managing employee access is one of those tasks that feels unnecessary until the day it clearly was not, whether that is a disgruntled former employee still able to log in, or a compromised account with far more reach than it should have had. South African businesses that apply least privilege, structure access by role, offboard promptly, and review regularly build a much smaller attack surface without needing a large IT budget to do it. The process matters more than the tools.
Want to write a guest post for E-LibraryGlobe?
We welcome well-researched, original guest contributions from writers and businesses across South Africa and beyond. Reach out with your topic idea and we will get back to you.
Explore more practical, problem-solving guides on the E-LibraryGlobe homepage, or browse every article we have published for South Africa.