Integrations & data · Practice guide

Review old and new access when staff change roles

Illustrative situation

An employee moves between teams but retains old access in several connected tools. Moving teams usually changes what access a person needs. Adding the new role without reviewing the old one can leave permissions accumulating unnoticed. Treat the move as one joined-up review.

Healthcare booking calendars on two connected screens with blue and orange appointment cards.
Make the handover between tools clear for the team using them.

What this means for your practice

Treat a role change as a review of existing access as well as a request for new access. Identify systems that need separate handling when automatic updates are unavailable.

An example to discuss with your team

Change a fictional staff role and inspect access across each connected tool.

Healthcare data integration connecting two applications through a field-mapping board.
Agree what each field means and which system owns it.
Healthcare data validation separating matched records from an exception tray.
Make rejected or uncertain records visible for review.

Questions to take to your supplier

Change a fictional staff role and inspect each connected tool. Which permissions are added, retained or removed? Ask who handles systems that cannot update automatically. The employee and manager should know what is ready and what still needs an authorised person to complete it.

Agree the working process

Treat a role move as a review of what the person already has as well as what they need next. List the connected applications and identify access to add, retain or remove, using the organisation's authorised process. Some permissions may remain appropriate for a handover period, but that should have a reason and review point. Ask the supplier how automatic updates and manual exceptions appear together so the owner can see when the change is genuinely complete. Use a fictional move between teams and inspect the destination tools, not only the central staff record.

Include a system that cannot update automatically and confirm a responsible person receives that task. Keep the agreed result understandable to the manager and employee. After completion, verify that old access is no longer present where removal was required. Repeated residual permissions may indicate that the application inventory is incomplete or the role mapping is unclear, rather than an isolated missed administration step.

How to check the result

Count residual permissions awaiting review.

Turn reading into a next step

Your action checklist

Work through these checks with your team or supplier. Tick the ones you have resolved and leave unknowns open.

Checks to discuss

Record what you know, what is still missing and the answer you need from your team or supplier.

Use project decisions only, without personal, patient or confidential details. Entries stay in this page and are not submitted to Kay & Co. Copy or download before leaving; this page does not save your notes.

Further reading

These sources provide background for the topic. The practice examples and checklist are illustrative planning suggestions from Kay & Co.

Related guides

Need help with this?

Tell us what is getting in the way. Kay & Co. can help you understand the options and turn the next step into something that works for your practice.

Explore integrations & data services or discuss your project.

Try the free Healthcare Digital Planner to find your starting priority.