Review accounts and shared responsibilities
Find obsolete access and verify who can administer the site.
Access needed: Site administrator.
Review access periodically and after team changes.
- List current accounts and identify an owner for each, including service accounts.
- Compare user groups and collaboration memberships with each person's current responsibilities.
- Review accounts that can manage users, publish content, change modules, or administer permissions.
- Check who controls recovery email addresses and external sign-in providers.
- Remove obsolete access using the account-removal procedure; record exceptions and their review date.
- Test representative roles after the changes and assign an owner for the next review.
For collaboration groups, distinguish ordinary membership from group-management rights. Confirm that the site's rules actually restrict the group's content as intended; a group connection does not by itself guarantee privacy.
Keep an access record outside publicly visible content. Use individual accounts for routine work so changes can be attributed to a person.