Startup SOP Library
Founder operations · Free SOP

Access Management SOP.

A lean access-control process for granting, reviewing, changing, and removing access before shared passwords become a company incident.

Download DOCX

Editable DOCX · Copy in one click · No email gate

DOCX

Operating standard

Control without the corporate sludge.

Owner

The security or operations owner; until assigned, the technical founder.

Response

Standard requests within one working day. Critical revocation immediately. Privileged changes within four business hours.

Metric

100 percent of departures revoked on time and zero shared administrator credentials.

Why this exists

If nobody owns the process, the founder owns every emergency.

Purpose

Give each person the minimum access needed, maintain accountability, and remove access promptly when roles change or people leave.

When it applies

Use for every employee, contractor, founder, vendor, service account, and production system from the moment access is requested until it is revoked.

Required inputs

Do not start blind.

Approved user identity and role
Systems and permission level requested
Business justification
Manager and system-owner approval
Start and expected end dates
Exact steps

Trigger to outcome. No meeting required.

  1. 01

    Submit an access request naming the user, system, role, justification, and duration.

  2. 02

    Confirm the manager and system owner approve the minimum permission level.

  3. 03

    Create an individual account; never reuse another person's credentials.

  4. 04

    Require multi-factor authentication and store recovery methods securely.

  5. 05

    Record the grant in the access register and notify the user of acceptable use.

  6. 06

    Review privileged access monthly and all other access quarterly.

  7. 07

    Change access within one working day when responsibilities change.

  8. 08

    Disable access immediately for involuntary departures and by end of the final day for planned departures.

Decision and approval points

Authority must be explicit.

The person's manager confirms business need.
The system owner approves permission level.
Production, billing, payroll, banking, and administrator access requires a founder or security owner.
Escalation path

Know when to stop.

Report suspected credential compromise immediately to the security owner. Disable the affected account first when delay increases risk, then investigate and document.

Records to keep

If it is not recorded, it did not happen.

Access request and approvals
Access register
Privileged access review
Revocation confirmation
Security exceptions and expiry dates
Customize before use

Make the generic parts real.

✓List every critical system and its owner.
✓Define privileged roles and approval thresholds.
✓Choose the request and access-register location.
✓Set review frequency based on risk.
✓Link this SOP to onboarding and offboarding.
Common startup mistakes

How teams break the process.

01

Sharing one administrator login across the team

02

Granting broad access because it is faster

03

Removing email but forgetting cloud, code, billing, and vendor accounts

Write it before the expert leaves

Make the process executable.

Download it, assign the real owners, set the thresholds, and test it with someone who did not write it.

Download DOCX
Planning template only. Adapt it to your contracts, risk, and jurisdiction. Obtain qualified professional advice where required. Last reviewed 2026-10-04.