Practical guide
Revoking access when a staff member leaves the practice
When a staff member leaves the management practice, their access to condominium data must not stay active a single day too long. A non-revoked account is residual access to the owners' archive, which the manager processes as data controller under the GDPR. Closing access, often called offboarding, is not just a matter of digital courtesy: it is a concrete security measure that closes doors otherwise forgotten. This guide proposes an orderly procedure to revoke credentials, devices and integrations at the end of a working relationship, so that nothing stays open through oversight, regardless of how the relationship ended.
Why prompt revocation is a security matter
An account still active after the end of the relationship is a risk regardless of the person's intentions. Even a staff member who leaves on excellent terms retains knowledge of credentials that, if not closed, remain usable. And if the relationship ended in conflict, a forgotten access can turn into a serious problem, from the theft of data to its alteration.
Prompt revocation answers the GDPR minimisation principle: owners' personal data must be accessible only to those who genuinely need it for their tasks. When the tasks cease, so does the need for access. Closing accounts at once is not distrust of the person, but consistency with the manager's responsibility towards owners.
What to revoke: not just the software
Access to the condominium software is the first element to close, but rarely the only one. A staff member may have credentials for the practice's email, banking or tax portals, communication services, document archives and any integrations linked to the software. Every uncatalogued access is a door left ajar.
That is why it helps to keep an up-to-date map of the access assigned to each staff member, so that at departure you know exactly what to close. Devices should also be considered: office computers, phones or authentication tokens must be returned or made unusable, and active sessions on those devices must be terminated.
Shared passwords and common credentials
If the practice has used shared passwords, for example for a service several people accessed with the same credentials, revoking the staff member's personal account is not enough. Those shared passwords they had access to must be changed, because the person retains knowledge of them even after leaving. Changing them is the only way to truly close that access.
This is one reason why personal accounts are preferable to shared ones: with an individual account it is enough to revoke it to close the person's access, without having to change credentials used by others too. Where shared passwords are unavoidable, a password manager makes the rapid turnover at the end of a relationship easier.
Verify and document the closure
Revoking access is not enough unless you verify that the closure is effective. It is worth checking that the staff member can no longer access the main services and that any active sessions are terminated. The software's tracking helps confirm there are no logins after the departure date.
Documenting the revocation is good practice from an accountability standpoint. Noting when and by whom a staff member's access was closed provides an orderly record of the measures adopted, useful both internally and in case of audits. Closing access thus becomes a structured step in the lifecycle of the relationship, not an improvised gesture.
A checklist for a staff member's departure
A software like AmministraPro, thanks to role-based access and operation tracking, makes it simple to revoke an account and verify that there is no residual access. Anyone who wants to understand how access and security are handled as the practice's organisation changes can review the capabilities on the features page and compare the plans on the pricing page.
Frequently asked questions
How much time do I have to revoke a departing staff member's access?
As soon as possible, ideally at the very end of the relationship. An account still active after departure is residual access to the condominium archive, regardless of the person's intentions. Prompt revocation answers the GDPR minimisation principle, under which data must be accessible only to those who genuinely need it: when the tasks cease, so does the need for access.
Is revoking the software account enough?
Usually not. A staff member may also have credentials for the practice's email, banking or tax portals, document archives and integrations linked to the software. Every uncatalogued access remains a door ajar. It helps to keep an up-to-date map of the access assigned to each person, so that at departure you know exactly what to close.
Should I change shared passwords when a staff member leaves?
Yes, if the practice has used them. Revoking the personal account does not close a shared password the person knows: only by changing it do you truly close that access. This is one reason why personal accounts are preferable to shared ones, because they allow closing a person's access without touching credentials used by others.
How do I verify that the revocation was effective?
By checking that the staff member can no longer access the main services and that any active sessions are terminated. The software's tracking helps confirm there are no logins after the departure date. Documenting when and by whom access was closed also provides an orderly record of the measures adopted.
Does revoking access apply even if the staff member leaves on good terms?
Yes. Revocation is not a judgement on the person, but a due security measure. Even a staff member who leaves on excellent terms retains knowledge of credentials that, if not closed, remain usable. Closing access at the end of every relationship, without exceptions, is consistent with the manager's responsibility towards owners' data.
Try AmministraPro
Accounting, thousandths-based cost splitting, meetings, communications and artificial intelligence in a single Italian software, compliant with UNI 10801 and GDPR.
