Easy emergency account recovery

Most organizations have at least a handful of user accounts for critical outside services.

Web hosting, payment processors, and more. Usually much more.

What happens when the person who manages one of those services leaves your organization?

How are you going to login to manage that service without the password that person was using?

But you've already decided to be smart and not store those passwords in a shared spreadsheet or document.

Your staff are each using a proper password vault for that, of course.

So there's a problem: your passwords are secure, but it's not easy to share them.

Here's the easiest solution I've found:

  1. Make sure any outside service account uses an organization email -- not a staff member’s (or vendor’s) personal email address.

  2. Record, in a shared spreadsheet or other document, which email address is used for each service account.

That's it.

If things really get bad, and the person who manages the account is inaccessible for whatever reason, at least you'll have a way to recover your access.

You'll know which email address to use, if you can reset the password by email.

And you'll have a way to access that email inbox, because it's an organization email address and not a personal one.

Sure, it's not perfect.

You might wish for a way to have secure password storage that can be easily shared across your organization.

But it's very likely that such a setup is more expensive or more complicated than your small organization wants to handle.

Still, just by documenting the email address for each service account, you get shareable documentation that can be pretty easily kept up to date, and you get a recovery method that works.

Not a bad compromise, I'd say.

All the best,
A.

Next
Next

Documenting passwords?