Insights · Schools

Teachers change. Access shouldn't linger: the back-to-school account checklist

Every school year starts with staff arriving and departing — and most schools only manage half of that. The accounts nobody closed are the quietest risk to student data.

By Andrew · NextGen Strategy PartnersJuly 20, 20265 min read

Every August, schools run a well-practiced routine for arriving staff: badges, keys, classroom assignments, first-day paperwork. The departing side of the ledger gets far less ceremony — and in most schools we assess, that's exactly where we find the problem: active accounts belonging to people who left in June. Or the June before that.

A lingering account isn't a hypothetical risk. It's a working set of credentials to your email, your files, and often your student information system — held by someone who no longer works for you, protected only by a password they chose years ago and may have reused everywhere. Under FERPA, you're responsible for who can access student records. "We forgot to turn it off" is not a control.

The offboarding half: close what June left open

Before the new year starts, reconcile the people against the accounts. For every staff member, aide, therapist, substitute, contractor, and volunteer who departed:

The audit question that finds problems fastest: "Who has access to student records — and would the head of school recognize every name on that list?"

The onboarding half: day-one access, least privilege

New staff deserve the mirror image: accounts ready before their first morning, with access matched to their role rather than copied from "whatever the last person had." A classroom aide doesn't need the business office share; a new therapist needs the IEP platform but not payroll. Set it correctly on day one and you never have to claw it back.

Do it annually, on the calendar

The schools that stay clean don't rely on anyone remembering. They run this reconciliation every August as routinely as fire drills — a one-hour exercise that closes a year of accumulated drift before students walk in. It also produces exactly the documentation boards, districts, and cyber-insurance questionnaires increasingly ask to see.

The practical takeaway

Before the first institute day, pull the full list of active accounts and match every name to a current staff member. Anything you can't match gets disabled the same day. If you'd like a second set of eyes, our free school IT assessment includes this access review — and the findings are yours either way.

Back-to-school is a season of fresh starts. Give your systems one too: every account current, every permission deliberate, and nothing from last year still holding a key.

Andrew, founder of NextGen Strategy Partners

Andrew — Founder, NextGen Strategy Partners

Veteran-owned managed IT for the nonprofits, schools, behavioral health providers, and medical & dental practices of McHenry & Lake Counties. Request a free security assessment →

Find out where you stand — before someone else does.

Our free IT security assessment gives your leadership a plain-English report on your risks, your compliance gaps, and exactly what it would cost to fix them. No obligation, no jargon.

Request the free assessment