Review accounts and shared responsibilities

Find obsolete access and verify who can administer the site.

Access needed: Site administrator.

Review access periodically and after team changes.

  1. List current accounts and identify an owner for each, including service accounts.
  2. Compare user groups and collaboration memberships with each person's current responsibilities.
  3. Review accounts that can manage users, publish content, change modules, or administer permissions.
  4. Check who controls recovery email addresses and external sign-in providers.
  5. Remove obsolete access using the account-removal procedure; record exceptions and their review date.
  6. Test representative roles after the changes and assign an owner for the next review.

For collaboration groups, distinguish ordinary membership from group-management rights. Confirm that the site's rules actually restrict the group's content as intended; a group connection does not by itself guarantee privacy.

Keep an access record outside publicly visible content. Use individual accounts for routine work so changes can be attributed to a person.