Home/ Volume 20/ Chapter 4
Show menu button
1

Definition

A business's main social media account had been set up years earlier using a former employee's personal phone number for verification, with no record of this anywhere. When that number was no longer reachable, regaining control of the account took weeks of support tickets and identity verification, for an asset the business had used every single day.

Password and access management

is the discipline of controlling who can log into, change, or control every digital asset the business depends on, the practical, day-to-day version of Volume 04, Chapter 8's principle of least privilege and Chapter 1's "Password Vault", fully built out.

Why should it matter whose phone number an account happens to be tied to, if that person was completely trustworthy? Because trustworthiness was never the risk, availability was. The account wasn't lost to bad intentions, it was lost because one specific person became unreachable, and nothing about the business's own access depended on anyone's character.

In One Sentence

Recall Volume 11, Chapter 5's rule: never register a business asset to a personal account. This chapter is how that rule is actually kept, day to day, a central, secured record of every login, who holds it, and how it's recovered if that person is ever unavailable.

2

What Belongs in Access Management

Unique password per account

If one reused password is stolen anywhere, it unlocks everywhere it's reused.

A password manager, not memory or sticky notes

Makes unique, strong passwords practical to actually use.

Business assets registered to business accounts

Never a personal email/phone, see Volume 11, Chapter 5.

Access reviewed on every departure

Per the Access Register's departure checklist.

Access matched to duty, not rank

Volume 04, Chapter 8's least-privilege rule applied to logins specifically.

Use the Access Register as the single central record. It already exists for exactly this purpose.

Memory Trick

If the business would lose access to something the day one specific person left, that is not real access management. It is a single point of failure.

3

Example Story: The Account Registered to a Phone Number That Left

Here's the full version of the stranded-social-media-account story from the start of this chapter.

A business's main social media account had been set up years earlier using a former employee's personal phone number for verification, with no record of this anywhere. When that number was no longer reachable, regaining control of the account took weeks of support tickets and identity verification, for an asset the business had used every single day.

No password had been stolen. No mistake had been made in the moment. One quiet, forgotten detail years earlier was enough. Moving every account onto business-owned contact details, logged centrally in an Access Register, meant no single person's departure could ever again strand a business asset.

4

Across Industries

The exact accounts at risk of this quiet failure differ by trade, but the pattern is always the same.

BusinessAn Access Management Gap Worth Checking
Golden Crust BakeryDelivery app account tied to the owner's personal phone
Rapid Auto WorksDiagnostic software licensed under a former technician's name
Precision Print & PressCloud storage for client files registered to one designer's personal account
5

Common Mistakes

Common Mistake #1: Business Assets Registered to Personal Accounts

This is the exact failure in the example story. It creates a single point of failure tied to one person's continued availability.

Common Mistake #2: Reused Passwords Across Multiple Accounts

One breach anywhere becomes a breach everywhere the same password was used.

Common Mistake #3: No Access Review When Someone Leaves

Leaves former staff with working logins to business systems indefinitely.

6

Quiz Yourself

Quiz 1
Why is registering a business's social media account to an employee's personal phone number risky, even if that employee is completely trustworthy?
Because it creates a single point of failure: if that person becomes unreachable or leaves, the business can lose access to its own asset, regardless of how trustworthy they were.
Quiz 2
What should happen to a departing employee's access, and where is that tracked?
Every item they held should be reviewed, revoked, or transferred, tracked using the Access Register's "On Every Departure" checklist.
7

Practice Exercise

Using the Access Register, list every digital asset the business depends on. Flag any registered to a personal account or phone number, and move it to a business-owned equivalent.

8

Quick Summary

Quick Summary

  • Access management is least privilege (only the access each role needs), applied to logins: unique passwords, a password manager, and business-owned registration for every account.
  • Never register a business asset to a personal account. Doing so creates a single point of failure.
  • Review and revoke access on every departure, using the Access Register.