Shared logins make it impossible to know who did what and force a password change every time somebody leaves. Named accounts where the platform supports them, and a shared password manager where it does not, resolve both problems for very little cost.

What sharing one login actually costs

Four separate problems, all of which arrive at once when somebody leaves.

That last one is the quiet cost. Shared logins actively prevent the single most effective security measure available.

Named accounts first

The right answer wherever the platform allows it, which is most of them.

Business listings, content systems, email, accounting software, and most business tools support multiple users with their own logins and permissions. That is included rather than an upgrade in most cases.

What it gives you: a record of who changed what, the ability to remove one person without disturbing anybody else, two-factor per person, and permissions scoped to what each person actually needs.

The setup cost is a few minutes per person at the point they join, which is the cheapest moment to do it.

Where sharing is unavoidable

Some accounts genuinely have one login: an older supplier portal, a utility account, a domain registrar on a basic plan, or a social account without team features.

For those, a shared password manager is the answer. The credential lives in a vault, people are granted access to specific entries, and access is revoked without changing the password.

That solves the departure problem, which is the most disruptive one, and it means the password itself can be long and random because nobody has to remember or type it.

What a password manager actually changes

Worth being concrete, because owners frequently see it as an extra thing to manage.

It removes the need for anybody to know a password, which means passwords can be unique per account and long enough to be genuinely strong. Reuse across accounts is the single most exploited weakness in small business security, and reuse happens because people have to remember.

It also means the list of what accounts exist is written down somewhere, which most small businesses have never done and which becomes valuable the moment somebody leaves or something goes wrong.

Business tiers with shared vaults are inexpensive per person, and for a team of three or four the cost is trivial against the alternative.

The rules worth setting

  1. Nobody shares a personal login, including with you.
  2. Two-factor on anything that supports it, particularly email, the domain, and banking.
  3. New person, new account, created rather than borrowed.
  4. Access matches the role, so most people are not administrators.
  5. Departures follow a list, written once and used every time.

The fourth is the one most often skipped. Making everybody an administrator is convenient and means any compromised account is a full compromise.

The email account underneath everything

The account that deserves the most protection and usually gets the least thought.

Whoever controls the email address attached to your other accounts can reset the passwords on all of them. That makes it the master key regardless of how well the individual services are secured.

It should have the strongest protection you can apply, and the recovery options on it should be checked, since an old phone number or a former employee's address in the recovery settings is a real exposure.

When somebody leaves

The moment all of this pays for itself, and the moment it is too late to arrange.

With named accounts, removal takes minutes and affects nobody else. With shared logins, every password they knew has to change, which means finding them all, changing them, and telling everybody the new ones during a period that is already awkward.

Keeping a written list of what each person has access to, updated when it changes, is what turns that from an afternoon of guesswork into a checklist.

The list matters as much as the passwords, because the accounts nobody remembers are the ones that stay accessible for years.

The realistic starting point

For a business currently sharing one password, the useful order is: write down every account that exists, turn on two-factor for email and the domain, create named accounts anywhere the platform allows it, and put the genuinely shared ones in a manager.

That is an afternoon and it removes most of the exposure. The list is the part that keeps paying, since a site whose login arrangements nobody can explain is the same maintenance problem as one whose construction nobody can explain, described in static pages versus a database.


Frequently asked questions

What is wrong with sharing one login?

No accountability for changes, a lockout for everybody when somebody leaves, uncontrolled spread of the password, and two-factor becomes impossible because the code goes to one phone.

What should I use instead?

Named accounts wherever the platform allows them, which is most business tools and usually included rather than an upgrade. Each person gets their own login, permissions, and two-factor.

What about accounts with only one login?

A shared password manager. The credential lives in a vault, access is granted per entry and revoked without changing the password, and it can be long and random since nobody types it.

Why does a password manager help beyond convenience?

It removes the need to remember, which is what causes reuse across accounts, and it produces a written list of what accounts exist, which most businesses have never made.

Which account matters most?

Email. Whoever controls the address attached to your other accounts can reset the passwords on all of them, which makes it the master key regardless of the others.

What should happen when somebody leaves?

With named accounts, removal takes minutes. Keeping a written list of what each person can access is what turns a departure from guesswork into a checklist.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

One password, several people, and nobody sure where it has been?

We inventory what accounts exist, get named logins where they are available, and put the rest somewhere access can be revoked.

Start a Conversation