Volume 24, Chapter 2
Passwords, Access, and Institutional Memory
Definition
MANIAC MINDZ's business bank account had only ever had the owner's name as an authorized signatory (the only person allowed to approve payments on it), a completely normal setup for a business its size, until an unplanned absence made it briefly impossible for anyone else to authorize even a small, urgent payment.
is the accumulated why behind the business's decisions, the Decision Log and tacit knowledge that must survive the owner's absence just as much as bank access does.
Why was a single-signatory account "completely normal" right up until it became a crisis? Because it works perfectly well every single day the owner is available, there's simply never a visible problem to notice. The risk only becomes real on the one day it's needed and isn't there, which is exactly why it goes unfixed for years.
Volume 20's Access Register already solves planned departures well. Succession planning asks the harder question: does a second person already have working access and enough documented context to step in without warning, not just after a planned handover period?
What Must Be Recoverable Without the Owner
Bank accounts
A second authorized signatory, not just the owner alone.
Domain, email, social media
Listed in the Access Register with a genuine second holder.
Supplier/customer relationships
Documented per Volume 04, Chapter 7, not held only in conversation memory.
The reasoning behind major past decisions
Captured in a Decision Log, not just the owner's memory.
A planned handover has weeks to transfer access and context. A succession emergency has zero. Everything critical needs a second working holder today, not a plan to add one "eventually."
Why a Second Signatory Matters More Here Than Anywhere Else
Volume 11's segregation of duties already argued against any one person holding unchecked power, succession planning adds the mirror-image argument: any one person holding sole access is also a risk, because the business stops functioning the moment that person is unavailable, for any reason.
Example Story: The Bank Account With One Name on It
Here's the full version of the one-signatory story from the start of this chapter.
MANIAC MINDZ's business bank account had only ever had the owner's name as an authorized signatory, a completely normal setup for a business its size, until an unplanned absence made it briefly impossible for anyone else to authorize even a small, urgent payment.
The setup had never once caused a problem, until the one day it did. Adding a second trusted signatory, with clear written limits on what they could approve alone, closed the exact gap the earlier hospital stay had exposed, without weakening any of the internal controls already in place.
Across Industries
The specific access gap changes by trade, but "only the owner knows this" is the same risk everywhere.
| Business | An Access Gap Worth Closing |
|---|---|
| Golden Crust Bakery | Wholesale account logins known only to the owner |
| Rapid Auto Works | Parts supplier trade accounts registered to one name only |
| Precision Print & Press | Client billing history accessible only from the owner's personal device |
Common Mistakes
The exact gap in the example story, completely normal until the moment it isn't.
The reasoning behind past decisions is just as vulnerable to disappearing as a password, see Volume 23.
A backup that only the owner knows how to find is not a real backup.
Quiz Yourself
Practice Exercise
Check every critical account in your Access Register. For each with only one working holder, add a genuine second person today.
Quick Summary
Quick Summary
- Succession planning needs a second person with already-working access and context, not just a documented plan to add one later.
- Institutional memory (the why behind decisions) is as vulnerable to disappearing as any password.
- A single authorized signatory on a critical account is a succession risk, regardless of trustworthiness.