HR News | Employer's Guardian

Leave-of-Absence Access: What Employers Need to Know

Written by Admin | Aug 18, 2026, 3:39:05 PM

Leave-of-absence access refers to how an employer manages an employee's system and facility permissions while that person is away on extended leave. It is a genuine gap in most access governance, because the employee has not left — so offboarding does not apply — but they are also not working, which means their credentials sit unused and unmonitored for weeks or months.

Dormant accounts with valid credentials are attractive targets precisely because nobody is watching them. If an account belonging to someone on a three-month leave is compromised, there is no user to notice anything unusual.

The competing considerations

Suspending access during leave reduces exposure. It also carries risks of its own, and they are not purely operational.

Employees on protected leave are entitled to be restored to their position, and to be free from retaliation for taking leave. Access changes that go beyond a security rationale — or that are applied inconsistently — can look like adverse treatment. An employee returning from medical leave to find their access reduced relative to what they held before has a plausible complaint, particularly if colleagues on other kinds of leave were treated differently.

There is also a practical dimension. Employees on leave frequently need continued access to benefits information, pay statements, and leave status. Cutting off all access can leave someone unable to check whether their benefits are continuing or their leave has been approved, which is both unhelpful and likely to generate its own dispute.

The workable middle position

The approach that satisfies both concerns is differentiated suspension: suspend operational access, retain self-service access.

That means network, email, and business system access is suspended for the duration of the leave, while the employee retains access to the self-service portal for pay statements, benefits information, and leave status. The security exposure of a dormant operational account is removed; the employee's legitimate needs are preserved.

Two conditions make this defensible. It must be applied uniformly to all extended leaves regardless of reason, and it must be documented as standard practice rather than decided case by case. Consistency is what distinguishes a security control from selective treatment.

Where the reason for leave should not matter

Employers occasionally handle access differently depending on why someone is out — treating a medical leave differently from a sabbatical, or an investigation-related suspension differently from parental leave. Some of those distinctions have legitimate bases, but they need to be articulated in advance and applied by category, not improvised.

The specific risk is that access decisions reveal information about the leave that should remain confidential. If the organization handles medical leaves visibly differently, colleagues can infer the reason for someone's absence from how their accounts were handled. Medical information is subject to confidentiality obligations, and inadvertent disclosure through operational practices is still disclosure.

Coverage arrangements

Work continues while someone is on leave, which means someone else needs access to what they were handling. This is where a second, quieter problem develops.

The common shortcut is granting a colleague access to the absent employee's account or mailbox. That destroys attribution — actions taken appear to come from the person on leave — and creates a credential-sharing practice that tends to persist after the leave ends.

The correct approach is granting the covering employee appropriate access under their own identity, with delegated mailbox access where needed rather than shared credentials, and a defined end date tied to the expected return. That delegation should then be reviewed and removed when the employee comes back — a step that is regularly skipped, leaving the covering employee with permissions they no longer need.

Return from leave

Restoration should return the employee to the access they held before, promptly, as part of the return process. Two failures are common.

The first is delay — an employee returning to find they cannot do their job for several days because access restoration was not prepared in advance. Beyond the operational cost, it undermines the employer's position on restoration obligations.

The second is incompleteness. Access suspended across multiple systems is often restored only partially, because there was no record of everything that was suspended. Documenting what was suspended at the start of the leave makes restoration verifiable rather than reconstructed.

Practical measures

  • Define a standard access practice for extended leave, applied uniformly regardless of reason
  • Suspend operational access while retaining self-service access for pay, benefits, and leave status
  • Record exactly what was suspended, so restoration can be verified
  • Grant coverage access under the covering employee's own identity, never through shared credentials
  • Attach an end date to delegated access and review it on return
  • Prepare restoration in advance of the return date
  • Include employees on leave in periodic access reviews rather than skipping them
  • Ensure access handling does not signal the reason for the absence

Employer's Guardian helps employers administer extended leaves consistently, including the documentation and process that keep handling defensible, through leave-of-absence management.

This article provides general educational information, not legal advice. Leave entitlements and restoration obligations vary by jurisdiction. Consult qualified counsel before establishing leave practices.