Skip to content
CyberTECTDigital operations control
All resources

Who Owns Your Business Accounts and Passwords?

The business should control the legal account, billing, administrators, MFA, recovery methods, and emergency process for every critical system. A shared password spreadsheet is not enough.

The short answer

Your business controls an account when the organization—not an individual employee or outside provider—can prove the account relationship, authorize administrators, maintain protected recovery methods, remove access, obtain records, and continue operating if a key person is unavailable. Password possession is only one part of that control.

Key takeaways

  • Ownership includes contracts, billing, domain registration, administrative authority, recovery options, and the ability to replace a provider.
  • Each person should use an attributable account; shared credentials obscure responsibility and complicate offboarding.
  • Critical systems need at least one protected alternate path that does not depend on the same person, device, email account, or provider.
  • Administrative accounts should be separate from daily work and protected with strong MFA.
  • Review account ownership during onboarding, role changes, vendor changes, and offboarding—not only after access is lost.

The Canadian Centre for Cyber Security recommends managing the lifecycle of user accounts so they remain active only when needed, and applying access controls that reflect job responsibilities. Its guidance also distinguishes ordinary and administrative use.

For a small business, however, the first question is often more basic: who can prove and exercise organizational authority over the system? A provider may have administrator access. An employee may know the password. The bookkeeper may receive the bill. The owner may still be unable to recover the account, export the information, or remove access without someone else’s cooperation.

The objective is not for the owner to perform every technical task. It is to ensure that critical authority belongs to the organization, delegated access is explicit, and a safe alternate process exists.

The 11-part account ownership review

01 Identify the systems the business cannot operate without

Include domains and DNS, email and cloud tenants, websites and e-commerce, banking and payment platforms, accounting and payroll, practice or production systems, social media, backups, security tools, telecom, and key vendor portals.

02 Confirm the legal or organizational account holder

Record the customer name, contract or subscription, billing contact, invoices, renewal dates, reseller or partner relationship, and the process for proving authority. An employee’s personal account should not be the owner of a critical business asset.

03 Confirm domain, DNS, and email control

The domain often anchors email, password resets, website traffic, and brand identity. Record the registrar, registrant, DNS provider, renewal method, administrators, MFA, recovery contacts, and the organization’s ability to transfer the domain if required.

04 List administrative and privileged accounts

Record named administrators, role, purpose, owner, authentication method, last review, and whether the privilege is still needed. Separate administrative identities from ordinary email and browsing where the platform permits it.

05 Replace routine shared access with attributable identities

Use individual accounts and appropriate roles. Where a system forces a shared credential, control it through an approved password manager, restrict who can retrieve it, protect the vault, and document use and rotation.

06 Protect MFA and recovery methods

Record which method protects each critical account and who controls it. Avoid a design in which the password, second factor, recovery email, and recovery phone all depend on the same person or device. Preserve backup codes or emergency methods securely.

07 Document provider and vendor access

Record what the provider can reach, why it is needed, how access is authenticated, whether activity is attributable, and how it is removed. Provider administration should support the organization—not replace organizational authority.

08 Create a protected emergency-access path

Define when emergency access may be used, who authorizes it, where instructions and recovery material are held, how dual control or notification applies, and what must be reviewed afterwards.

09 Plan for role changes and departures

Offboarding should remove active sessions, delegated access, groups, forwarding, recovery methods, shared vault access, vendor portals, local credentials, and physical tokens. Transfer business records and ownership before the account is disabled.

10 Test the evidence, not only the list

Verify selected billing records, admin portals, domain records, recovery methods, password-manager access, and provider contacts. A register copied from memory should be marked unverified until evidence confirms it.

11 Assign a review cycle and trigger events

Review at a defined interval and after departures, acquisitions, provider changes, new systems, domain transfers, major incidents, MFA changes, and leadership changes.

What an account-control register should contain

Field Purpose
System and business purpose Why the account matters and which process depends on it.
Organizational owner The person accountable for the business relationship and access decision.
Provider and billing Vendor, reseller, subscription, renewal, invoice, and contract evidence.
Administrators Named privileged users, role, purpose, authentication, and review date.
Recovery Approved recovery email, phone, codes, device, alternate, and escalation path.
Data and export Information held, export method, retention, and continuity consideration.
Offboarding How access, sessions, delegated permissions, and provider authority are removed.
Evidence and review Where proof is held, verification date, open issue, owner, and due date.

Passwords are not the same as ownership

A password may open a system while leaving the organization unable to prove the contract, receive security notices, manage billing, change administrators, transfer the domain, retrieve historical records, or compel a vendor to act. Conversely, an owner may control the account without knowing every user password because administration and recovery are properly structured.

The goal is organizational authority with least-privilege delegation—not owner access to every employee’s daily credential.

A practical rural and small-business reality

Small organizations frequently depend on trusted individuals and long-standing providers. That trust is valuable, but it should be supported by clear authority, documented alternatives, and an orderly transition process. The control protects both the organization and the people carrying too much undocumented responsibility.

Frequently asked questions

Should the owner know every business password?

No. The owner or leadership should control organizational authority, administration, recovery, and oversight. Individual user passwords should remain private and attributable.

Is it acceptable for an IT provider to be a Microsoft 365 administrator?

It can be appropriate when authorized and governed. The organization should still control the tenant relationship, know the provider’s access, maintain protected organizational authority, and have a transition or emergency process.

Should two people be administrators of every system?

Not automatically. Use roles proportionate to the system. Critical systems need safe continuity, but excessive privilege also creates risk. An alternate may be an emergency-access process rather than another daily administrator.

Can account credentials be stored in a document?

A plain document is usually a weak control. Use an approved password manager or protected emergency-access method with strong authentication, restricted access, and a documented recovery process.

What is the first ownership issue to fix?

Start with the domain, primary email/cloud tenant, backup administration, banking/payment access, and the systems that hold essential customer or operational information.

Make trust visible as organizational control

A small business should be able to rely on trusted employees and providers without making its continuity dependent on undocumented personal access. The ownership record shows what authority exists, what has been delegated, and how the organization can act when normal access fails.

CyberTECT can establish the baseline through a Digital Operations Checkup or perform a deeper authority and emergency-access review through Break Glass Readiness.

Start with the level of review you need

Take the 90-second Digital Operations Control Check for an immediate directional result. For an evidence-based review of accounts, files, Microsoft 365 backups, vendors, AI use, and continuity, discuss the Digital Operations Checkup or the complete AI & Digital Operations Review. Scope and fees are confirmed before work begins.

General information only. This article does not provide legal, privacy, professional-conduct, or regulatory advice. Organizations should obtain appropriate advice for their sector, jurisdiction, information, and intended AI use.

Related CyberTECT services and checks

Authoritative sources and further guidance

Using this guidance

CyberTECT resources provide general operational guidance. They do not replace advice specific to your legal, regulatory, contractual or technical circumstances.

Discover more from Cybertect

Subscribe now to keep reading and get access to the full archive.

Continue reading