Transfer business access without sharing personal passwords
- Reading time
- 2 minutes
- Last reviewed
A business account can quietly depend on one person's private email address or phone. The dependency may become visible only when a password reset is needed after they leave.
Prepare an access transition inventory with the responsible IT provider or administrator. Record the service, business purpose, authorised account owner and the approved way to change access. Do not put passwords, recovery codes or other secrets in the inventory.
Trace the route to the next legitimate user
For each essential system, ask who will need access after the current user leaves and what permission they actually need. A person answering customer queries may need a limited role rather than full administration rights.
Use the provider's supported process for account ownership, user roles and recovery arrangements. Have the authorised administrator carry out the change. Do not bypass a login, request a person's private password or assume possession of a work device grants access to every account on it.
Staff-record access needs particular care because technical access and permission to use personal information are separate questions. Ask privacy and legal advisers about unclear boundaries.
A fictional accounts service uses a departing employee's personal phone for recovery. The appropriate task is to arrange a supported business recovery route and test it, with the necessary authority. Writing the employee's password on the closure checklist would leave the original dependency unresolved.
Test continuity before removing old access
Agree the sequence with the administrator. The incoming authorised user should be able to reach the required records and perform an appropriate permitted task before the old arrangement is retired. Changes must also respect the business's security policies and any legal preservation requirements.
Handover acceptance can record the outcome without recording secrets. Note who tested the access, what business purpose was checked and any open problem requiring the provider's help.
Review recurring subscriptions and records retention with the relevant advisers. Cancelling a service may affect access to information still needed; continuing it indefinitely may create unnecessary cost. The office handover should identify the actual continuing tasks that justify access.
Keep a named owner for unresolved recovery or permission problems. A partly completed migration should not be marked finished merely because the normal login works on one existing device.
For UK Auction Group, the useful result is an authorised contact who can obtain asset records and confirm current instructions. There is no reason to share business credentials with the disposal enquiry. Supply the relevant information through an appropriate channel once legitimate access is established.
Explore employees and handover.
Sources
This guide is general information and education only. Legal, tax, employment and safety decisions may need a qualified adviser who knows your situation. Read the disclaimer.