An access list records every account the business depends on, who controls it, and who else can reach it. Without one, departures leave access behind and nobody notices until something happens.

Why the list is the point

Security advice usually concerns how accounts are protected. The prior question is which accounts exist, and most small businesses cannot answer it.

Accounts accumulate over years, created by different people for different reasons. A developer set up the analytics. A former employee registered the social account. Somebody made a listing on a directory nobody remembers.

You cannot secure, transfer, or revoke access to something you have not written down, which makes the inventory the foundation rather than an administrative extra.

What belongs on it

For each: what it is, who owns the account, which email address it is registered to, who else can reach it, and whether two-factor is enabled.

That last column frequently reveals more than the rest, because it shows where the exposure actually is.

The three failures the list prevents

Access that outlives the person

Somebody leaves and retains access to a listing, a social account, or an analytics property because nobody remembered they had it.

This is rarely malicious and it is a real exposure, particularly where the account can be used to change how the business appears publicly.

Accounts registered to a personal address

An account registered to somebody's personal email is an account the business does not control. If they leave, or lose access to that address, recovery may be impossible.

This is extremely common with domains and social accounts, and it is the version of this problem that costs the most.

Third-party access nobody tracks

Developers, agencies, and contractors accumulate access during a project and keep it afterwards. Some of those relationships ended years ago.

The account that matters most

The domain, by a distance.

Whoever controls the domain registration controls where the site and the email point. That is more consequential than the site itself, because a site can be rebuilt and a domain in somebody else's account may not be recoverable on your terms.

It should be registered in the business name, with a business contact address that is not at the domain itself, with a registrar login the owner holds, and with the transfer lock enabled.

A business that cannot log into its own registrar has a problem worth fixing this week rather than eventually.

Doing the inventory

An afternoon, and there is a shortcut.

Rather than trying to remember, work from evidence. Search the business email for account confirmations and receipts, look at what the bank statement is paying for monthly, and check the password manager or browser for saved logins.

Those three sources find nearly everything, including the subscriptions nobody uses and the accounts nobody remembers creating.

Recurring charges for services nobody can identify are common, and the inventory usually pays for itself on that alone.

Scoping access properly

Once the list exists, the second question is whether each person needs the level they have.

Most platforms offer roles, and most small businesses use administrator for everybody because it is simpler. That means any compromised account is a full compromise, and any mistake is unlimited.

A content editor does not need billing access. A bookkeeper does not need the ability to delete the site. Setting roles takes minutes at the point somebody is added and is difficult to retrofit.

Departures

The moment the list earns its keep.

A written checklist, derived from the inventory, listing what to remove and in what order. Email and the password manager first, since those enable recovery of everything else.

Also worth including: anything with a personal address attached, any shared credential that now needs changing, and any device that holds saved logins.

Doing this from a list takes twenty minutes. Doing it from memory takes an afternoon and misses things.

Reviewing it

Annually, and whenever somebody joins or leaves.

The annual review checks that the list is still accurate, that third-party access still corresponds to live relationships, and that recovery details on the important accounts are current.

Recovery details are the item most likely to be stale. A phone number that changed or a backup address belonging to somebody who left will stop you recovering an account at the exact moment you need to, which is the same reason shared credentials cause trouble, as covered in passwords when more than one person needs access.


Frequently asked questions

Why does an access list matter?

You cannot secure, transfer, or revoke access to something you have not written down, and most small businesses cannot list the accounts they depend on.

What should the list record?

For each account: what it is, who owns it, which email it is registered to, who else can reach it, and whether two-factor is enabled.

Which account matters most?

The domain registrar. Whoever controls it controls where the site and email point, and a domain in somebody else's account may not be recoverable on your terms.

What is the fastest way to build the inventory?

Work from evidence rather than memory: search the business email for account confirmations, check what the bank statement pays monthly, and look at saved logins.

Why does everybody being an administrator matter?

Any compromised account becomes a full compromise and any mistake is unlimited. A content editor does not need billing access.

What goes stale on the list?

Recovery details. A changed phone number or a backup address belonging to somebody who left will stop you recovering an account exactly when you need to.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

Cannot say who can still edit your business listing?

We build the inventory from your email and bank records, which usually finds accounts nobody remembered and subscriptions nobody uses.

Start a Conversation