Access accumulates and is almost never removed. Former employees, previous suppliers, and one-off contractors typically retain the credentials they were given, because removing access requires someone to remember it after the relationship ended. The audit takes an afternoon and it is usually surprising.

Why the list is longer than you think

Access is granted in the moment, quickly, to solve something. A developer needs to fix a page. An employee needs to update the listing. A supplier needs to check something.

Each grant is reasonable. None of them is recorded, and removal depends on someone thinking of it weeks later when the relationship has ended and nothing is prompting them.

The result after a few years is a set of accounts with an unknown number of people holding credentials, some of whom the business no longer deals with and one or two of whom it may have parted with badly.

What to inventory

SystemWhat to check
Domain registrarAccount users, and the contact email on the domain
HostingControl panel users, FTP accounts, database users
Website platformAdministrator and editor accounts
EmailMailboxes, forwarding rules, and delegated access
Business listingOwners and managers
Analytics and search toolsUsers, and which account owns the property
AdvertisingUsers, and linked accounts
Social platformsPage roles, which persist independently of the personal accounts
Payment and invoicingUsers and any API access

Most systems have a users or permissions screen listing this directly. The exercise is opening each one and reading it, which is duller than it is difficult.

The findings that recur

That last one deserves particular attention, because it is invisible until the day you need to recover an account and discover the code goes to somebody else.

The principle worth applying

Give the least access that lets someone do the job, for the shortest time they need it.

Most systems have roles below administrator, and most people given administrator access do not need it. A contractor updating pages needs editor access. A bookkeeper needs the accounts, not the hosting. Someone posting to a listing needs manager rather than owner.

The practical benefit is not distrust. It is that a compromised account with limited permissions is a contained problem rather than a total one.

Named accounts rather than shared logins

Where a system supports multiple users, use them, which most business platforms do at no extra cost.

Three benefits: you can see who did what, removing one person is one action, and you are not changing a password everyone relies on every time someone leaves. Shared logins fail on all three, which is why the leaving employee scenario is so consistently mishandled.

It also means two-factor authentication can be applied per person rather than being an obstacle to sharing, which resolves the tension described in two-factor authentication on the accounts that matter.

When somebody leaves

A short list, run the same way every time.

The same list applies to a supplier relationship ending, which is the case people forget because it does not feel like an offboarding.

Making it stick

One page listing each system, who has access, and at what level. Reviewed twice a year and whenever someone joins or leaves.

That document is the whole of it. Without it, access is reconstructed from memory each time, which is how a former designer keeps administrator rights for four years. With it, the review is twenty minutes and the offboarding is a checklist rather than a recollection.


Frequently asked questions

Why does access accumulate?

Because it is granted quickly to solve something and removed only if someone remembers weeks later, after the relationship has ended and nothing is prompting them.

What should I inventory?

Domain registrar, hosting, website platform, email, business listing, analytics, advertising, social page roles, and payment systems. Each has a users screen listing this directly.

What is the most common finding?

A previous web designer still holding administrator access, and recovery addresses pointing at people who have left. The second only becomes visible on the day you need to recover an account.

How much access should someone have?

The least that lets them do the job, for the shortest time. A contractor updating pages needs editor rather than administrator, and a compromised limited account is a contained problem.

Why avoid shared logins?

You cannot see who did what, removing one person means changing a password everyone uses, and two-factor authentication becomes an obstacle rather than a protection.

What should happen when someone leaves?

Disable rather than delete, remove them from every system on your inventory, change shared passwords, check recovery addresses, reassign anything they owned, and check for mail forwarding rules.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

Cannot say who can log into your accounts?

We inventory every system, remove access that should have ended years ago, and leave you a document that makes the next departure a checklist.

Start a Conversation