Volume 20, Chapter 4
Passwords and Access Management
Definition
A business's main social media account had been set up years earlier using a former employee's personal phone number for verification, with no record of this anywhere. When that number was no longer reachable, regaining control of the account took weeks of support tickets and identity verification, for an asset the business had used every single day.
is the discipline of controlling who can log into, change, or control every digital asset the business depends on, the practical, day-to-day version of Volume 04, Chapter 8's principle of least privilege and Chapter 1's "Password Vault", fully built out.
Why should it matter whose phone number an account happens to be tied to, if that person was completely trustworthy? Because trustworthiness was never the risk, availability was. The account wasn't lost to bad intentions, it was lost because one specific person became unreachable, and nothing about the business's own access depended on anyone's character.
Recall Volume 11, Chapter 5's rule: never register a business asset to a personal account. This chapter is how that rule is actually kept, day to day, a central, secured record of every login, who holds it, and how it's recovered if that person is ever unavailable.
What Belongs in Access Management
Unique password per account
If one reused password is stolen anywhere, it unlocks everywhere it's reused.
A password manager, not memory or sticky notes
Makes unique, strong passwords practical to actually use.
Business assets registered to business accounts
Never a personal email/phone, see Volume 11, Chapter 5.
Access reviewed on every departure
Per the Access Register's departure checklist.
Access matched to duty, not rank
Volume 04, Chapter 8's least-privilege rule applied to logins specifically.
Use the Access Register as the single central record. It already exists for exactly this purpose.
If the business would lose access to something the day one specific person left, that is not real access management. It is a single point of failure.
Example Story: The Account Registered to a Phone Number That Left
Here's the full version of the stranded-social-media-account story from the start of this chapter.
A business's main social media account had been set up years earlier using a former employee's personal phone number for verification, with no record of this anywhere. When that number was no longer reachable, regaining control of the account took weeks of support tickets and identity verification, for an asset the business had used every single day.
No password had been stolen. No mistake had been made in the moment. One quiet, forgotten detail years earlier was enough. Moving every account onto business-owned contact details, logged centrally in an Access Register, meant no single person's departure could ever again strand a business asset.
Across Industries
The exact accounts at risk of this quiet failure differ by trade, but the pattern is always the same.
| Business | An Access Management Gap Worth Checking |
|---|---|
| Golden Crust Bakery | Delivery app account tied to the owner's personal phone |
| Rapid Auto Works | Diagnostic software licensed under a former technician's name |
| Precision Print & Press | Cloud storage for client files registered to one designer's personal account |
Common Mistakes
This is the exact failure in the example story. It creates a single point of failure tied to one person's continued availability.
One breach anywhere becomes a breach everywhere the same password was used.
Leaves former staff with working logins to business systems indefinitely.
Quiz Yourself
Practice Exercise
Using the Access Register, list every digital asset the business depends on. Flag any registered to a personal account or phone number, and move it to a business-owned equivalent.
Quick Summary
Quick Summary
- Access management is least privilege (only the access each role needs), applied to logins: unique passwords, a password manager, and business-owned registration for every account.
- Never register a business asset to a personal account. Doing so creates a single point of failure.
- Review and revoke access on every departure, using the Access Register.