Shared logins are convenient right up until the moment they are not. One account used by four people creates problems that only become visible during an incident or a staff departure.
You lose accountability
Every content management system records who did what. With a shared account, the log says "admin" changed the pricing page at 3am and nothing else. When a page is deleted, an order is refunded incorrectly, or a setting is changed, there is no way to find out who did it or ask them why. This also matters for your own internal governance, not only for security.
Offboarding becomes messy
When someone leaves, you should be able to disable their access in one action. With a shared login you have to change the password and redistribute it to everybody else, which never happens promptly and often does not happen at all. The departed employee retains access until someone remembers.
Permissions cannot be right for everyone
A shared account has to be powerful enough for the most demanding user, which means the person who only edits blog posts also has the ability to delete the site, install plugins and change payment settings. Most damage we see is accidental, done by someone who had more power than their job required.
Two factor authentication breaks down
You cannot sensibly attach a second factor to an account four people log into from different devices. Either the codes go to one person who becomes a bottleneck, or the second factor gets disabled, which removes your best protection.
What to do instead
- One named account per person, using their work email address.
- Assign the lowest role that lets them do their job. Most people need Editor or Author, not Administrator.
- Keep one or two administrators, no more.
- Review the user list every few months and remove anyone who no longer needs access.
We can set up individual accounts and correct roles on your site. Reply to your email thread or contact [email protected].