Staff movement is a normal part of architecture and engineering practices.
Designers move between firms.
Project engineers change roles.
Contract staff join or leave project teams.
While these transitions are expected, they also introduce operational risk if system access is not managed carefully.
Architecture and engineering firms rely heavily on digital systems that contain design documentation, project drawings, specifications and internal collaboration records.
If access remains active after someone leaves the firm, exposure can persist long after the individual has moved on.
Most issues do not arise from malicious intent.
They arise from inconsistent offboarding processes.
Why Access Management Matters in Design Firms
Design teams often hold access to multiple systems simultaneously, including:
- CAD and BIM platforms
- shared project file repositories
- cloud collaboration platforms
- email and communication systems
- internal documentation and specifications
These systems contain intellectual property and project documentation that may be commercially sensitive.
If access is not removed promptly when staff leave, firms may face:
- ongoing access to project drawings and models
- exposure of confidential project documentation
- continued email communication through old accounts
- difficulty demonstrating control over intellectual property
These risks often remain invisible until an issue occurs.
Structured access management reduces that exposure.
The Objective: Remove Access Without Disrupting Projects
Effective offboarding should achieve three outcomes:
- remove system access promptly and consistently
- preserve necessary project documentation and communication records
- ensure project responsibilities are transferred smoothly
Design environments rely on continuity.
The offboarding process should therefore support project stability.
What a Structured Offboarding Process Typically Includes
1. Access Revocation
On or before the final working day:
- disable email and cloud accounts
- remove access to CAD and BIM platforms
- revoke permissions to project file repositories
- remove multi-factor authentication tokens
- terminate remote access permissions
Access removal should be coordinated centrally rather than managed across individual systems.
2. Device Recovery and Review
Where staff are issued workstations or laptops:
- recover firm devices
- remove stored credentials
- review locally stored project documentation
- securely reconfigure devices before reassignment
Design files are often stored locally during project work, making device review important.
3. Project Continuity
Design staff typically contribute to multiple projects.
Offboarding should ensure:
- project responsibilities are reassigned
- access permissions reflect updated team roles
- documentation ownership is transferred
- client communication continues without disruption
The objective is continuity across active projects.
4. Permission Review Beyond the Individual
Staff transitions provide an opportunity to review broader access permissions.
Firms may review:
- shared project folders
- collaboration platform permissions
- administrative system access
- consultant access to shared environments
These reviews help ensure access remains aligned with current project teams.
Common Gaps in Design Firms
Across many architecture and engineering firms, offboarding is often handled:
- informally between departments
- without a documented checklist
- with delayed IT involvement
- without confirmation that access has been removed
The assumption is often:
“If the person has left, the access must be gone.”
In reality, access can remain active quietly across multiple systems.
What Leadership Should Be Able to See
From a management perspective, leadership should have visibility into:
- whether staff departures trigger a structured offboarding process
- whether access to project repositories is removed promptly
- whether intellectual property remains protected
- whether devices and credentials are recovered
- whether permission changes are documented
Clear oversight ensures project data remains controlled as staff transitions occur.
Closing Perspective
Staff movement is inevitable in architecture and engineering firms.
Operational risk during those transitions does not have to be.
Structured offboarding processes ensure access permissions remain aligned with active project teams and that intellectual property remains protected.
Your focus should remain on delivering successful projects.
Operational discipline should quietly support that work.
If you’re unsure how this applies to your environment, we’re happy to walk you through it.
If useful, you can see how we approach IT support and cybersecurity specifically for architecture & engineering firms here: → IT & Cybersecurity Services for Architecture & Engineering Firms

