Making the team work · 4.4

Access and tools, and what a blocked person costs

Access and tools, and what a blocked person costs. What actually decides it, and what to do about it.

A person who cannot log in is a person being paid to wait, and access problems are the most common avoidable cost in the first month.

The day-one list

Written before the start date and tested by somebody actually logging in, not by somebody confirming that an invitation was sent.

Email. The chat channel. The task system. The files. Every business system the role touches. And whatever multi-factor arrangement each of them requires, which is where most of the delay comes from.

Named accounts, always

One account per person, never shared. Shared credentials remove any record of who did what, cannot be revoked for one person, and make multi-factor authentication impossible to administer.

The temptation is a licence cost, and the answer is that the licence is cheaper than the audit trail you gave up.

Scoped permissions

Access to what the role requires and nothing further. This is ordinary practice and it matters more here for a reason worth stating plainly: an arrangement where somebody outside your organisation has broad access is one where a mistake or an incident is harder to bound.

The entry on the bookkeeping role describes what this looks like for financial systems, where the stakes are highest.

Credentials, and where they must not be

Not in chat, not in email, not in a spreadsheet. A shared password manager with per-person access is inexpensive, it makes revocation a single action, and it is the one piece of tooling in this entry that has no reasonable substitute.

The surprise nobody plans for

Systems that block foreign addresses. Banking portals, some government services, and applications configured to allow one country only. This is discovered on the first morning and takes days to resolve through a support channel that has never been asked before.

Check it before the start date by having somebody at the provider try to reach each system.

Devices

Provider-managed machines rather than personal ones. It sounds obvious and personal devices appear in this industry more than clients assume, particularly in home-working arrangements.

Ask what the machine is, who administers it, whether disk encryption is on, and what happens to it when the person leaves.

Bandwidth

Tools differ enormously in what they demand. Remote desktop sessions, video calls with several participants and large file transfers all compete, and a connection adequate for one is not adequate for three at once.

If the role involves working inside a remote session all day, say so before the engagement rather than discovering it in week two.

Offboarding, written before you need it

A list of every system to revoke, and a named person responsible for running it on the day. Most organisations have an onboarding list and no offboarding list, which is how former staff retain access for months.

The provider will tell you the person's last day. Acting on it is yours.

What a blocked day costs

The salary, which is small, plus the momentum, which is not. A person blocked repeatedly in their first month concludes that the work is not taken seriously, and that conclusion is difficult to reverse.

Preparing access properly takes an afternoon somewhere in the fortnight before the start date. It is the cheapest thing in this part of the journal and the most frequently skipped.

Licence counting

Per-seat costs for the tools the role touches, multiplied by the team size, are a real line in the model from the entry on cost. They are small individually and not always small together.

Check also whether your licence terms permit access by a contractor or by an employee of another company, because some do not and it is better discovered now.

The access review

Every six months, list who has access to what and remove whatever is no longer needed. Roles change and permissions accumulate, and the accumulation is invisible until somebody looks.

Also in making the team work