Back to Property Management Software
property management softwareaccess recertificationstaff role changeleast privilegeaccount review

Property Management Staff Role Change and Access Recertification Checklist

Review staff, temporary, service, and privileged access after role changes and on a defined cadence with tested removal and exception evidence.

JHA Solutions Editorial Team Published August 21, 2026 3 min read Access Recertification Templates

Short answer: access recertification should confirm each identity, employment or service status, current role, property scope, business need, permissions, privileged access, sessions, connected applications, shared credentials, approver, last use, exceptions, and removal evidence. A manager checking a box without testing access is not a complete review.

NIST SP 800-53 includes account-management and least-privilege controls across the account lifecycle. CISA recommends role-based access, periodic account review, removal of unnecessary accounts, and permissions limited to what work requires. This independent checklist adapts those principles to property operations; it is educational and not a security certification, employment instruction, privacy opinion, or substitute for qualified technical and legal review.

Trigger reviews when work changes

Start a review for hire, transfer, promotion, leave, contractor change, property reassignment, privileged duty, termination, merger, software migration, and material incident. Periodic reviews remain useful, but they should not delay urgent access removal after a known change.

Inventory every identity type

Include named staff, temporary users, contractors, vendors, owners, service accounts, API clients, shared mailboxes, emergency accounts, mobile sessions, and integration identities. Identify the human and business owner behind each non-person account.

Compare access with current duties

Review property and entity scope together with leasing, accounting, payments, owner reports, maintenance, resident data, documents, analytics, settings, user administration, exports, and deletion. Use the role permissions matrix as the approved baseline.

Review privileged and financial access first

Prioritize administrator rights, bank and payment controls, accounting changes, refunds, owner payouts, deposit records, exports, API keys, webhooks, user creation, audit logs, and security settings. Confirm separation of duties and escalation paths where consequence warrants them.

Download the access review checklist

Download the editable staff role-change and access recertification checklist (CSV). It covers identities, current duties, property scope, roles, permissions, privileged access, sessions, integrations, approval, denied tests, removal, and exceptions.

Find access outside the main application

Review email groups, drives, password vaults, messaging, calendars, banking, payment processors, lockboxes, smart access, devices, remote support, reports, exports, developer tools, and vendor portals. A disabled property-software account does not revoke these connected paths.

Test allowed and denied behavior

Use safe representative tests to prove required work remains possible and prohibited work is denied. Verify cross-property isolation and audit evidence. Record tester, time, exact role, result, and correction. The security and access-control checklist supplies the wider control context.

Remove sessions and persistent access

Disabling a user may leave mobile sessions, remembered devices, delegated mail, OAuth grants, API tokens, shared links, local exports, keys, codes, and browser profiles active. Revoke or rotate each path according to approved procedure and preserve evidence.

Time-limit approved exceptions

Record business reason, requested permissions, risk, compensating control, approver, start, expiry, monitoring, and removal owner. Do not let temporary elevation become a permanent role. Route unexplained access through the incident recovery workflow.

Measure review quality

Track stale accounts, excessive roles, orphaned service identities, failed denied tests, overdue removals, repeated exceptions, review completion, and access-related incidents. A 100% completion rate is weak evidence when the review never detects anything.

Compare findings by system, property, role, and reviewer so recurring design problems become visible. If every transfer requires manual cleanup across several tools, improve role design, identity inventory, and offboarding automation rather than relying on memory during the next change.

Frequently asked questions

How often should access be recertified?

Choose a cadence based on risk, policy, agreements, and applicable requirements. Review high-consequence access more often and trigger immediate review when duties or status change.

Can a direct manager approve all access?

The manager can confirm business need, but security, financial, data, or system owners may need to approve higher-consequence permissions and exceptions.

Official references

How this guide is produced

JHA Solutions checks material claims against cited primary or official sources where available, separates examples from requirements, and records meaningful updates.

Read the editorial standards

Related property management guides

Run property operations from one place

Use JHA Solutions to organize properties, tenants, maintenance, documents, financials, GPS routes, calendars, and owner reporting.

Start free