Changing jobs
A transfer on Monday
Sam Reyes has been a nurse on Harbor Clinic's pediatrics unit for four years. On Monday 9 November 2026, Sam transfers to oncology at the same site. HR records the change on 26 October with an effective date of 9 November: Sam's department becomes Oncology, and Sam's manager becomes the oncology nurse manager. Sam's employee number, E07731, and job title stay the same.
Someone whose job changes inside the organization is a mover. A transfer between units is the obvious case. Promotions, new managers, and temporary duties count too, because each of them changes the reasons behind some of a person's access.
Four years on one unit leave a trail. Sam's access today comes from three different places:
- Rules that apply to every registered nurse in pediatrics. These give Sam
EHR_PED_RW, to read and update pediatric patient records, the pediatrics rota in scheduling, and Ward nurse for the pediatric ward in pharmacy. - Requests that a manager approved. In 2023, Sam was granted "Receive controlled medication" in the pharmacy system. In 2024, when Sam started planning the unit's shifts, Sam was granted "Unit scheduler" for the pediatrics rota.
- A grant made by hand. When Sam joined the unit's incident review group in 2024, a nurse manager asked Jordan Ellis, an IT administrator, to give Sam access to the pediatric incident reviews folder. Jordan added Sam to the folder directly in the file system.
What happens to each of these on Monday depends on where it came from.
Adding is easy, removing is not
Picture the move with nothing connecting the transfer to Sam's access. Sam arrives on the oncology unit at 07:00 and cannot open the patient list. The charge nurse calls the help desk, and within the hour Jordan has added oncology access by hand. Sam gets to work, and as far as anyone can see, the problem is solved.
Nobody calls about the pediatric access. Sam may not even know it is still there. The pediatric manager assumes IT handles it, IT has no record that Sam moved, and the help desk only hears about the access people ask for. Missing access stops someone working and produces a phone call within the hour. Extra access produces silence.
Repeat that over a few moves and a few projects, and a long-serving employee holds a little of everything: the privilege creep described in Why access needs governance. Each grant was reasonable when it was made, and it simply outlived its reason. Sam is unlikely to misuse pediatric records. But if Sam's account were ever taken over, every leftover permission would come with it, and an auditor asking why an oncology nurse can update pediatric records would get no answer.
The hand-added oncology access causes trouble of its own. It duplicates what an oncology rule would grant, but nothing ties it to that rule, so when Sam eventually leaves oncology, the rule's access goes and the manual grant stays.
Recalculating access
Harbor's identity system can handle the move better because it records where each piece of Sam's access came from. On 9 November it applies HR's new department and manager, then treats each kind of access according to its origin.
Rule-based access recalculates itself. The pediatrics rule no longer matches Sam, so it stops granting EHR_PED_RW and the pediatrics rota. The oncology rule now matches, so it grants EHR_ONC_RW and the oncology rota. Nobody has to remember either change, which is the main reason rules make moves safer than grants made by hand. Access rules and birthright access looks at these rules in detail.
Requested access needs a fresh reason. Each request was approved for a reason that belonged to Sam's old job, by a manager who no longer manages Sam. So the identity system sends Sam's requested access to the oncology nurse manager, who has the first week of the transfer to decide what still applies. Unit scheduler was for the pediatrics rota, which Sam no longer plans, so it is removed. Oncology nurses also receive controlled medication, so the manager confirms that one, and the record now shows the new reason and the new approver. Some organizations simply remove all requested access on a move and let the person ask again. That is stricter and noisier, but either way, nothing carries over on an old reason.
Manual grants are what stay behind. Jordan shared the incident reviews folder directly in the file system, so the identity system holds no request, no reason, and no rule for it. It may not even know the grant exists until it next compares the folder's actual permissions with what it expects, a check called reconciliation that Keeping systems in sync explains. Until then, Sam can still read pediatric incident reviews, which name patients, from the oncology unit.
| Access | How Sam got it | After 9 November |
|---|---|---|
| Directory account, email, and files | Rule for every employee | Kept |
EHR_PED_RW: pediatric patient records | Rule for pediatrics nurses | Removed on 23 November, after the handover |
| Pediatrics rota and Ward nurse for pediatrics | Rule for pediatrics nurses | Removed |
EHR_ONC_RW: oncology patient records | Rule for oncology nurses | Added |
| Oncology rota and Ward nurse for oncology | Rule for oncology nurses | Added |
| Unit scheduler, pediatrics rota | Request approved in 2024 | Removed: no reason in the new job |
| Receive controlled medication | Request approved in 2023 | Kept, with the oncology manager's new approval |
| Pediatric incident reviews folder | Shared by hand in the file system | Left behind |
The last row is the failure, and it is the kind that survives most moves. The fix is not a better memory. Jordan should have made the change through the identity system, as a request with an owner and a reason, so that the transfer would have sent it to the new manager with everything else. When a grant genuinely has to be made by hand, it still belongs on record in the identity system, so that a move, a review, or a departure can find it.
An overlap with an end
Sam cannot hand over in an instant. Several children on the pediatric unit have care plans Sam wrote, and the pediatric team wants Sam available to answer questions and update notes for two weeks. Removing pediatric access first thing on Monday would make that impossible, or push Sam toward asking a colleague to open records under the colleague's sign-in, which would leave a misleading record of who did what.
The answer is an overlap with an end set at the start. On 26 October, when HR records the transfer, the pediatric nurse manager requests continued EHR_PED_RW for Sam, with the reason "handover of pediatric patients" and an end date of Monday 23 November. The identity system records this as a separate grant. When the pediatrics rule stops granting the access on 9 November, the handover grant keeps it. On 23 November the grant ends, and the access goes without anyone having to act.
Setting the end date at the start is the whole point. "Keep it for now, and we'll take it off when the handover is done" becomes permanent access, because two weeks later nobody is thinking about it. The pediatric manager has a new nurse to settle in, and Sam is learning a new unit. If the handover does run late, the manager asks for an extension, which is a new decision with a new date.
For those two weeks, Sam holds both pediatric and oncology access. That is expected, and anyone reviewing Sam's access during that time can see why: a handover grant with an owner, a reason, and an end date, rather than leftover access nobody can explain.
Quieter changes
A transfer is hard to miss. Other changes look small in HR but change access, or the people responsible for it, just as much.
A new manager is one. Sam's manager changed with the transfer, and that matters beyond the organization chart: approvals for Sam's requests now go to the oncology nurse manager, and so do reviews of Sam's access. If HR had updated the department but not the manager, the pediatric manager would go on approving requests for someone they no longer supervise, and would be asked in the next review to vouch for oncology access they know nothing about. A new manager with no transfer, after a reorganization for example, needs the same rerouting.
A promotion is another. When a pediatrics nurse becomes a charge nurse, the department stays the same and nothing looks like a move, but the new job may need Unit scheduler, and some of the old job's access may no longer fit. A promotion to nurse manager adds something different: that person now approves requests and reviews access for a team. That authority should follow from HR's record of who manages whom, not from an entitlement someone adds by hand.
Temporary cover works like the handover. When the oncology charge nurse takes three weeks of holiday in January, Sam covers the role and needs Unit scheduler for the oncology rota. The grant carries the reason and an end date matching the cover, so it does not quietly become part of Sam's permanent access.
A name change is the quietest of all. When Dana Okafor changes surname to Mensah, Dana's user name and email address change to [email protected]. The identity, the employee number, and every entitlement stay exactly as they were. The mistake to avoid is treating the change as a leaver and a joiner, disabling the old accounts and creating new ones, which breaks the link to Dana's history and can lose access Dana still needs. Applications that store the identity's unchanging identifier rather than the email address follow the change without trouble.
A move ends some reasons for access and creates others. When someone leaves, every reason ends at once. Continue to Leaving an organization to follow a locum physician's last day and what it takes to end access that is already open.