Support & operations · Practice guide

Review supplier access when the work ends

Illustrative situation

A supplier finishes its work, but its team members remain on several administrative accounts because access was granted through different systems. Access can remain in several places after a supplier finishes work. Review it against the actual service inventory, while confirming any support responsibilities that continue. The right outcome is deliberate access based on current work.

Healthcare website support desk with a system checklist, telephone and orange notebook.
Know who to call and what help your support arrangement includes.

What this means for your practice

Coordinate access review across the agreed service inventory using approved security procedures. Confirm ongoing support arrangements before removing access that remains necessary.

An example to discuss with your team

Compare a fictional offboarding list against the access inventory and identify an account omitted from the initial request.

Healthcare website maintenance with infrastructure, a status panel, tools and an operational checklist.
Monitor the useful journey, not just whether a server responds.
Healthcare backup and recovery illustrated by storage copies, an archive folder and a restoration route.
Test whether a backup can restore a usable service.

How to review the arrangement

Compare a fictional offboarding request with accounts, connections and administration records. What would the original list miss? Assign each removal or continuing permission to the authorised system owner. Record completion so the incoming team can distinguish an agreed retained account from one simply overlooked.

Review access against the service actually used

Start with the current list of website, hosting, domain, reporting and connected-service accounts. Identify where the outgoing supplier or its team members have access and which arrangements continue under an agreed support role. The authorised system owners should decide and carry out changes through the organisation's normal security process.

Include access used by connections or publishing tools, not only named people appearing on an obvious user list. Ask the responsible supplier to explain those dependencies so removing obsolete access does not accidentally break a service that still needs it. Record which items have been reviewed, which changes are complete and which permissions deliberately remain. During handover, compare that record with the incoming team's understanding of responsibility. A completed meeting or contract end date does not automatically update every account. The practical aim is a documented arrangement based on current work, with someone able to explain and review each remaining exception.

How to check the result

Track obsolete supplier access awaiting review or removal by authorised owners.

Turn reading into a next step

Your action checklist

Work through these checks with your team or supplier. Tick the ones you have resolved and leave unknowns open.

Checks to discuss

Record what you know, what is still missing and the answer you need from your team or supplier.

Use project decisions only, without personal, patient or confidential details. Entries stay in this page and are not submitted to Kay & Co. Copy or download before leaving; this page does not save your notes.

Further reading

These sources provide background for the topic. The practice examples and checklist are illustrative planning suggestions from Kay & Co.

Related guides

Need help with this?

Tell us what is getting in the way. Kay & Co. can help you understand the options and turn the next step into something that works for your practice.

Explore support & operations services or discuss your project.

Try the free Healthcare Digital Planner to find your starting priority.