Short answer: access recertification should confirm each identity, employment or service status, current role, property scope, business need, permissions, privileged access, sessions, connected applications, shared credentials, approver, last use, exceptions, and removal evidence. A manager checking a box without testing access is not a complete review.
NIST SP 800-53 includes account-management and least-privilege controls across the account lifecycle. CISA recommends role-based access, periodic account review, removal of unnecessary accounts, and permissions limited to what work requires. This independent checklist adapts those principles to property operations; it is educational and not a security certification, employment instruction, privacy opinion, or substitute for qualified technical and legal review.
Trigger reviews when work changes
Start a review for hire, transfer, promotion, leave, contractor change, property reassignment, privileged duty, termination, merger, software migration, and material incident. Periodic reviews remain useful, but they should not delay urgent access removal after a known change.
Inventory every identity type
Include named staff, temporary users, contractors, vendors, owners, service accounts, API clients, shared mailboxes, emergency accounts, mobile sessions, and integration identities. Identify the human and business owner behind each non-person account.
Compare access with current duties
Review property and entity scope together with leasing, accounting, payments, owner reports, maintenance, resident data, documents, analytics, settings, user administration, exports, and deletion. Use the role permissions matrix as the approved baseline.
Review privileged and financial access first
Prioritize administrator rights, bank and payment controls, accounting changes, refunds, owner payouts, deposit records, exports, API keys, webhooks, user creation, audit logs, and security settings. Confirm separation of duties and escalation paths where consequence warrants them.
Download the access review checklist
Download the editable staff role-change and access recertification checklist (CSV). It covers identities, current duties, property scope, roles, permissions, privileged access, sessions, integrations, approval, denied tests, removal, and exceptions.
Find access outside the main application
Review email groups, drives, password vaults, messaging, calendars, banking, payment processors, lockboxes, smart access, devices, remote support, reports, exports, developer tools, and vendor portals. A disabled property-software account does not revoke these connected paths.
Test allowed and denied behavior
Use safe representative tests to prove required work remains possible and prohibited work is denied. Verify cross-property isolation and audit evidence. Record tester, time, exact role, result, and correction. The security and access-control checklist supplies the wider control context.
Remove sessions and persistent access
Disabling a user may leave mobile sessions, remembered devices, delegated mail, OAuth grants, API tokens, shared links, local exports, keys, codes, and browser profiles active. Revoke or rotate each path according to approved procedure and preserve evidence.
Time-limit approved exceptions
Record business reason, requested permissions, risk, compensating control, approver, start, expiry, monitoring, and removal owner. Do not let temporary elevation become a permanent role. Route unexplained access through the incident recovery workflow.
Measure review quality
Track stale accounts, excessive roles, orphaned service identities, failed denied tests, overdue removals, repeated exceptions, review completion, and access-related incidents. A 100% completion rate is weak evidence when the review never detects anything.
Compare findings by system, property, role, and reviewer so recurring design problems become visible. If every transfer requires manual cleanup across several tools, improve role design, identity inventory, and offboarding automation rather than relying on memory during the next change.
Frequently asked questions
How often should access be recertified?
Choose a cadence based on risk, policy, agreements, and applicable requirements. Review high-consequence access more often and trigger immediate review when duties or status change.
Can a direct manager approve all access?
The manager can confirm business need, but security, financial, data, or system owners may need to approve higher-consequence permissions and exceptions.