Skip to content

Make access traceable and recoverable

Replace shared logins with owned access

Move away from the password everyone knows while keeping daily work usable and departures manageable.

TARGET OUTPUT

What this field note should leave behind

People use named accounts, strong authentication, appropriate roles, and a documented business-controlled recovery path.

SEQUENCE / 04

Work the problem in this order

  1. 01

    List every place where staff share one username, pass credentials in chat, or depend on one person's phone or personal email for recovery.

  2. 02

    Confirm the vendor supports named users, role-based access, multi-factor authentication, backup administrators, and business-controlled recovery.

  3. 03

    Move one critical system at a time. Create named accounts, apply the smallest workable role, verify the backup administrator, and test recovery before retiring the shared access.

  4. 04

    Add an access change step to onboarding, role changes, contractor closeout, and departures. Review privileged access on a recurring schedule.

CHECK BEFORE CLOSE

Evidence worth seeing

  • The business controls the primary domain, billing account, and recovery contacts.
  • Administrative access is not tied to one employee's personal email or phone.
  • Multi-factor authentication is enabled using methods appropriate to the system and team.
  • Departing people can be removed without changing access for everyone else.
ESCALATION BOUNDARY

Know when general guidance stops

Pause and use qualified security or vendor support if changing access could lock out the business, interrupt regulated work, or remove needed audit history.