Staff turnover in nurseries is high. That is simply how the sector works. People move setting, go on maternity leave, change room or step up into a new role. Every one of those moves should also change what they can get into: systems, data and the building itself. Often, it doesn't.
This guide covers joiners, role changes and leavers, with leavers as the main risk. It also covers the shared passwords and door codes that quietly outlive everyone who has ever known them.
Why leavers are the dangerous moment
When someone joins, everyone pays attention. Accounts get set up, logins get handed out, the welcome is warm. When someone leaves, attention drops just as the handover gets rushed.
The result is that former staff can walk away with a live email account, the Wi-Fi password and the front door code. Most leavers are completely harmless. But security has to plan for the rare one: the person who leaves on bad terms, the person whose personal email is later hacked and used to get back into yours, or simply the person who keeps access they should not have.
The leaver checklist
Work through this on or before their last day.
Their accounts
- Disable their Microsoft 365 account on their last working day. Disable it, do not delete it, so their files and emails stay available for handover.
- Reset their password.
- Sign them out of all sessions, so any phone or computer still signed in loses access.
- Remove them from shared mailboxes and groups.
If you give your IT provider notice, this takes minutes. Our Microsoft 365 support team does it routinely for our customers.
Their devices
- Collect any nursery phone, iPad or laptop.
- If the device is managed, wipe the work account remotely. A managed device lets you remove nursery data without touching personal data.
- Remove the device from your management system so it stops receiving apps and credentials.
Shared credentials
- Remove them from any shared password vaults.
- Change any shared password they knew that is not in a vault. There is more on this below.
Physical access
- Collect keys and fobs.
- Change door codes the same day.
- If you use proper access control, revoke their individual credential instead. Our access control guide explains how.
The paper trail
- Record what was done and when.
That record supports your GDPR accountability, and it answers the question an inspector or insurer may one day ask: how do you make sure former staff no longer have access?
The shared-password trap
Every nursery has passwords that everyone knows and nobody owns. The Wi-Fi. The parent communications app. The CCTV system. The alarm code. A shared admin login or two.
There is no single account to disable, so former staff simply keep knowing them. Changing them means reconfiguring devices and telling everyone the new one, so it usually doesn't happen. Over the years these credentials build up like barnacles on a ship's hull.
The fix is to stop sharing passwords directly. Use a password manager such as Keeper, which we use ourselves, with a shared vault. Staff can use the credentials without ever seeing them, and when someone leaves you remove their vault access and nothing else has to change. Keeper can also be set up so staff sign in with their Microsoft 365 account, so one login unlocks everything they need.
Some credentials have to be typed into devices, the Wi-Fi password on room iPads being the usual example. Managed devices can receive new credentials automatically, so changing a password does not mean visiting every iPad. Our iPad management guide covers this.
When someone changes role
Role changes are the most overlooked of the three. People pick up new access as they move around, and nobody takes the old access away, so it accumulates.
Treat a role change as a leaver and a joiner at the same time:
- Add what the new role needs.
- Remove what the old role no longer justifies.
The room leader who becomes deputy manager needs new access. The deputy manager who steps back to part-time room work probably does not need the finance folder any more.
When someone joins
Getting the start right makes every later change easier.
- Give each person a named account. Never a shared one.
- Apply least privilege: only the access their role needs. If an account is ever compromised, that limits the damage.
- Add them to the right shared vaults, rather than telling them passwords.
- Set them up with two-factor authentication from day one. See our guide to two-factor authentication on Microsoft 365.
- Record everything you gave them, so you know exactly what to take away when they move on.
Making it stick: the HR and IT handover
Leaver admin usually fails in the gap between two people. HR or the manager knows someone is leaving. IT, whether that is an in-house person or a provider like us, is who can actually disable the accounts. If the message never crosses that gap, nothing happens.
The routine that works is simple: whoever processes the leaver on the HR side sends a completed leaver form to whoever handles IT. Every time, no exceptions.
If you are an Octopus 365 customer, ask us for our New Starter, Leaver and Role Change templates. The New Starter form records the accounts, access and devices a new joiner is given. The Leaver form is the last-day tick-box checklist and doubles as the HR to IT handover. The Role Change form prompts both what to add and what to remove. Brand them, adapt them and use them on paper or digitally, whichever suits your setting. It is part of how our managed IT support works day to day.
The one thing to take away
Granting access is easy and always gets done. Removing it is what protects your nursery, and it is the part that gets forgotten. Build your leaver process around one form that always reaches whoever can disable accounts, move shared passwords into a vault so leaving removes access automatically, and change the door codes on the day someone leaves.