Shared Logins and the Accounts Nobody Owns

Every growing business ends up with the same quiet problem. There is a login that several people use. Nobody is quite sure who set it up, the password has not changed in years, and it is written down in a place that is convenient rather than sensible.

It got that way for practical reasons. A tool only allowed one seat, a contractor needed access for a week, somebody needed to cover while a colleague was away. Each decision was reasonable. The accumulation is the problem.

Why shared accounts cause more trouble than they solve

The obvious issue is that when somebody leaves, changing one password affects everyone, so it often does not happen.

The less obvious issues matter more. You cannot tell who did what, so mistakes cannot be traced and neither can anything deliberate. You cannot remove one person's access without disrupting the rest. And you usually cannot turn on stronger sign in protection, because the code goes to one person's phone.

A shared account is not just a security shortcut. It is a hole in your ability to manage anything about that system.

Find them first

Before fixing anything, build the list. Three sources will find most of them.

  • The card statement. Every subscription is a system, and single seat plans are where shared logins hide.
  • Ask each team. Not do you share logins, which invites a defensive answer, but which accounts do more than one of you use.
  • Look at what is written down. The spreadsheet, the note in the shared drive, the piece of paper in the drawer. Those are your inventory.

Expect to find at least one account nobody claims, and at least one that is still being paid for and no longer used.

You cannot manage access you have never listed. The list is ninety percent of the work.

Fix them in order of consequence

Not every shared account is equally dangerous. Sort them by what somebody could do with it.

Anything that can move money, change bank details, reach customer data, send from your company name, or administer another system goes first. Those get individual accounts, without exception, even if it costs more in licences.

The rest can be dealt with in order. Some will turn out to be unnecessary, which is the cheapest fix available.

When a shared account genuinely has to exist

Sometimes a system offers no alternative. In that case, the account should be treated as a managed asset rather than a convenience.

It needs a named owner, a record of who has access and why, a long unique password stored in a password manager rather than a document, a rotation whenever somebody with access leaves, and a review date. The password manager part matters because it means access can be revoked for one person without a new password for everyone.

Write down why the exception exists, and what would remove it. Often a plan change does.

Get a password manager, then use it properly

A business password manager solves several problems at once. It removes the need for people to remember or reuse passwords, it lets you share access without sharing the password itself, and it gives you a real list of what exists.

The part that gets skipped is the rollout. People keep their old habits unless the new tool is set up for them, populated with what they actually use, and explained in ten minutes with their own accounts in front of them.

Two rules make the rest work. Nothing that matters is stored anywhere else. And when somebody leaves, their access is removed centrally rather than found account by account.

Turn on the second step where it counts

Two step sign in is worth the minor annoyance on the accounts that matter. Email first, because it is the recovery route to everything else, then banking and finance systems, then anything holding customer data, then administrator accounts anywhere.

Where possible use an app rather than text messages, and make sure more than one person can complete the step for any business critical account. An account secured to a single person's phone is a different kind of single point of failure.

Make it part of joining and leaving

None of this stays fixed on its own. The list goes stale every time the business adopts a new tool or somebody moves roles.

Tie it to the processes you already have. New tool means a line on the joiner and leaver checklists. Somebody leaves means their password manager access is removed and any shared credential they knew gets rotated. Once a quarter, somebody checks the list against reality.

That is the whole maintenance cost, and it is the kind of ordinary process work we help businesses put in place. Not tooling for its own sake, just a list, an owner, and two checklists that stay current.

We work with businesses in Pompano Beach, across South Florida and remotely to get this list built and kept current. Book a consultation, or visit www.expertechsolution.com.

Related reading

Previous
Previous

How to Write a Scope of Work That Prevents Arguments

Next
Next

Backups You Have Actually Tested