Keep Control of Your IT Access

Prevent vendor lock-in and make renewals and support easier. Book a Fit Check to verify your license ownership, admin access, and recovery controls, then get a clear list of any gaps.

What Should Happen When Someone Changes Roles (Mover Checklist)

Last updated

May 14, 2026

Reviewed by

Reviewed by: IT Service Delivery Lead

Speakable Summary

A mover checklist is a repeatable process forchanging access when someone changes roles. It prevents permission sprawl andbroken workflows by removing old access, adding new access, and verifyingresults.

Opening

Role changes create more access problems thannew hires. That is because access only gets added, not removed.

Then people keep old permissions, shared mailboxaccess stacks up, and nobody remembers what is intentional. When somethingbreaks, the office manager becomes the middleman again.

A mover checklist prevents this by making rolechanges a clean, documented access change with verification.

Direct Answer

When someone changes roles, IT should remove oldaccess, add new access, and verify the person can work in the new role withoutretaining unnecessary permissions. A mover checklist makes changes predictableand reduces security risk without slowing the business.

LINK: Approvals for Changes
LINK: Documentation Expectations
LINK: Contact / Fit Check

What a “mover” event includes

A mover is any change that affects access.

Examples

●    Promotion or department change

●    New responsibilities that requirenew apps

●    Removal of responsibilities thatshould remove access

●    Temporary coverage of another role

●    Location change that affectsprinters, Wi-Fi, or systems

Mover checklist

1) Create the ticket and set the effective date

●    Submit the request through thesupport front door

●    Include the effective date andtime

●    Identify the manager who approvesthe access change

●    State if the change is temporaryor permanent

2) Define the new role in plain English

●    Job title and team

●    Core workflows the person mustperform

●    Systems they must access daily

●    Systems they should no longeraccess

This prevents IT from guessing. Access is abusiness decision.

3) Access to add and access to remove

●    List access to add by system andgroup

●    List access to remove by systemand group

●    Remove old group memberships thatno longer apply

●    Avoid stacking access “just incase”

If access is not needed for the new role, removeit.

4) Email, shared mailboxes, and delegations

●    Add or remove shared mailboxaccess

●    Review Send As and Send on Behalfpermissions

●    Remove old delegations that shouldnot carry forward

●    Confirm distribution group andalias changes

Shared access is one of the most common sourcesof confusion.

LINK: Shared Mailboxes and Permissions
LINK: Do You Manage Shared Mailboxes and Permissions

5) Files, SharePoint, and shared drives

●    Remove access to old departmentfolders

●    Grant access to new departmentfolders

●    Confirm SharePoint sites and Teamspermissions

●    Confirm ownership transfer iffiles were role-owned

Confirm the person can open and edit what theyneed on day one.

6) App access and licenses

●    Add access to role apps and SaaStools

●    Remove access from apps no longerrequired

●    Confirm license changes if needed

●    Confirm admin roles are notgranted unless required

License and access should match role. Nothistory.

7) Devices, printers, and location changes

●    Confirm device profile andmanagement settings if applicable

●    Update default printers and mappedresources if needed

●    Confirm Wi-Fi access and networkresources

●    Confirm any location-based systemsstill work

8) MFA, security groups, and privileged access

●    Confirm MFA is still enforced

●    Review security group membershipchanges

●    Remove local admin rights unlessrequired

●    If elevated access is required,document why and approval

Admin access should be rare and documented.

LINK: MFA Explained for SMBs
LINK: Conditional Access Explained

9) Vendor portals and password vault access

●    Remove access to vendor portals nolonger needed

●    Add access to vendor portalsrequired for the new role

●    Update password vault sharedfolders and groups

●    Confirm recovery and ownershiprules are unchanged

This prevents vendor billing and portal accesssurprises.

LINK: Credential Ownership

10) Verification and closeout

A mover change is not complete until verified.

Verification checklist

●    Can sign in and complete coreworkflows

●    Can access required files, Teams,and apps

●    Shared mailbox permissions workcorrectly

●    Old access is removed andconfirmed

●    Any new permissions are documented

Closeout notes must include

●    What access was added

●    What access was removed

●    What was verified

●    Any follow-up tasks

Get My 15 Minute Fit Check

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.