Roles, multi-factor logins and a leaver routine that survives a busy week
Buy now
From$649USD one-off
One payment. Work starts once we have confirmed your requirements.
The four questions this page answers
1
What you buy
A one-off remote engagement that puts structure around who can do what: permission groups instead of everyone being an administrator, multi-factor authentication on the systems that matter, and a written joiner and leaver routine.
2
What you get
5 deliverables, listed in full below
Permission roles defined and applied across the agreed systems
Multi-factor authentication live for all users on every system that supports it
A shared password manager in use, with recovery codes held by the business
Carried out remotely by our team. Nothing is posted and no one visits.
REMOTE SERVICE
4
How long it takes
7–10 business days, depending on how quickly staff complete their enrolment
Measured from the point everything under “what we need from you” is with us, not from the moment you pay.
A permissions matrix showing who can do what, and who has two-factor enabled. Illustrative interface concept — not a screenshot of a client deployment.
What is this, in plain English?
A one-off remote engagement that puts structure around who can do what: permission groups instead of everyone being an administrator, multi-factor authentication on the systems that matter, and a written joiner and leaver routine.
Where the Account & Access Review reports, this implements. Roles are agreed with you and applied, multi-factor authentication is rolled out with recovery codes stored somewhere the business controls, a shared password manager replaces the spreadsheet, and offboarding becomes a checklist rather than a test of somebody’s memory.
The problem it solves
Everyone in the business is an administrator, passwords are shared in a group chat, and switching off a leaver’s access depends on whoever remembers first.
If that does not describe you, this is probably the wrong product. Tell us and we will point you at a better fit rather than sell you the nearest one.
What you get
The concrete things that exist at the end and that you own.
5 deliverables
Permission roles defined and applied across the agreed systems
Multi-factor authentication live for all users on every system that supports it
A shared password manager in use, with recovery codes held by the business
A written joiner, mover and leaver checklist ready to be followed
A handover session and a short administrator guide for the process owner
What's included
The work covered by the figure in the buy box, at no extra cost.
Up to eight systems
Role definition and application
Multi-factor rollout and user enrolment support
Password manager setup with per-team vaults
Replacement of shared logins with named accounts where possible
Everything listed here is delivered as part of this product. Nothing on this list is aspirational.
Permission roles defined with you and applied across up to eight systems
Multi-factor authentication enabled for every user on the systems that support it
Recovery codes generated and stored in a location the business, not an individual, controls
A shared password manager set up, with separate vaults per team
Shared and generic logins replaced with named accounts wherever the system allows it
A written joiner, mover and leaver checklist naming each system and each step
A 45-minute handover session for whoever will run the process afterwards
How it works
The delivery sequence from order to handover.
1
Agree the roles
We define a small number of roles that match how people actually work, rather than one permission set per person.
2
Apply them
Roles are applied system by system, starting with the lowest-risk one so any surprises appear early.
3
Roll out multi-factor
Enrolment is run with your staff, recovery codes are captured centrally, and anyone who cannot enrol is dealt with individually.
4
Set up the password manager
Vaults are created per team, existing shared passwords are moved in and then rotated.
5
Write the process
The joiner and leaver checklist is written, walked through in a handover session and handed to a named owner.
Delivery & fulfilment
Stream Edge Solutions ships nothing. Every package on this site is carried out and handed over remotely — this is exactly what happens after you order.
REMOTE SERVICEHow this is delivered
1We confirm requirementsWe read what you sent with the order, come back in writing with anything missing, and agree the scope before any chargeable work starts.
2We build and configure remotelySetup, configuration and testing are done by our team over a remote connection — on your systems or on ours, whichever the package specifies.
3We hand it overYou receive the working setup, the credentials, the documentation and a walkthrough. Everything built for you is yours at handover.
Carried out remotely by our team. Nothing is posted and no one visits. Typical turnaround: 7–10 business days, depending on how quickly staff complete their enrolment.
Delivery method
Remote Setup
Expected delivery time
7–10 business days, depending on how quickly staff complete their enrolment
Measured from the point everything under “what we need from you” is with us — not from the moment you pay.
Full detail of how work is handed over, what happens if requirements are outstanding and how order records are kept is in the Delivery & Fulfilment Policy.
What we need from you
Nothing starts until these are in place, and the turnaround above is measured from that point — not from the moment you pay.
Administrator access to each system in scope
A decision from the business on which roles exist and who belongs to each
Staff availability for multi-factor enrolment, which they must complete themselves
A nominated owner of the joiner and leaver process after handover
Acceptance that enabling multi-factor will briefly interrupt everyone’s logins
Who this is for
Businesses where staff share one login for a critical system
Companies that have never enabled multi-factor authentication anywhere
Owners who want access removed reliably when someone leaves
Teams that have completed an access review and now need the changes made
Just as plainly as the list above: the things this package is not.
Password manager subscriptions and any per-user licence fees, which you pay the provider directly
Systems that offer no multi-factor or role support, which are recorded as an accepted risk rather than forced
Single sign-on or identity provider build, which is quoted separately
HR policy, employment contracts and disciplinary process, which are not ours to write
Ongoing account administration after handover; the process is yours to run, or covered by a support plan
Any promise that access can never be misused; controls reduce the chance, they do not remove it
Anything outside the scope above is quoted separately, in writing, before it is carried out. Nothing is added to your bill without your agreement.
FAQs
Our staff will resist multi-factor authentication. What then?
We roll it out system by system rather than all at once, start with the systems where the risk is highest, and run the enrolment live with people so nobody is left stuck. Where a person genuinely cannot use an app, most systems allow a hardware key or a code list instead. Resistance usually fades once people have done it twice.
What about a system that has no multi-factor option?
We cannot add what the vendor has not built. Those systems go on a written list of accepted risks, with a note of what compensates for it, such as a strong unique password held in the manager and a tighter permission set. It is also worth asking that vendor when they intend to support it.
Do you keep copies of our passwords afterwards?
No. Anything we hold during the work sits in your password manager, not ours, and our own access is removed at handover with the removal confirmed to you in writing. Recovery codes are stored in a business-controlled location that you nominate, so no individual, including us, is a single point of failure.
What if we have more than eight systems?
The scope is fixed at eight so the price means something. Additional systems are available as an add-on, priced per system, and we confirm the final list before the work starts. If the count is much higher, the Account & Access Review first is usually the cheaper way to decide what is worth including.
Refund & cancellation
What happens if you change your mind, and what happens to money already paid.
Cooling-off before work starts
You have 7 days after ordering to cancel while work has not yet begun. Up to 25% may be retained to cover scoping and scheduling already carried out.
Work already done
Once delivery has started, refunds are assessed against the work completed and the deliverables already handed over — the list under “what you get” above is what that assessment is made against. Approved refunds are processed within 14 days.
If we cannot deliver what is described here
You are refunded. The scope on this page is the scope we are held to, which is exactly why the exclusions above are stated before you buy rather than after.