Make access traceable and recoverable
Replace shared logins with owned access
Move away from the password everyone knows while keeping daily work usable and departures manageable.
What this field note should leave behind
People use named accounts, strong authentication, appropriate roles, and a documented business-controlled recovery path.
Work the problem in this order
- 01
List every place where staff share one username, pass credentials in chat, or depend on one person's phone or personal email for recovery.
- 02
Confirm the vendor supports named users, role-based access, multi-factor authentication, backup administrators, and business-controlled recovery.
- 03
Move one critical system at a time. Create named accounts, apply the smallest workable role, verify the backup administrator, and test recovery before retiring the shared access.
- 04
Add an access change step to onboarding, role changes, contractor closeout, and departures. Review privileged access on a recurring schedule.
Evidence worth seeing
- The business controls the primary domain, billing account, and recovery contacts.
- Administrative access is not tied to one employee's personal email or phone.
- Multi-factor authentication is enabled using methods appropriate to the system and team.
- Departing people can be removed without changing access for everyone else.
Know when general guidance stops
Pause and use qualified security or vendor support if changing access could lock out the business, interrupt regulated work, or remove needed audit history.