Stop account sharing
Replace shared and default logins with individual accounts, so activity is traceable to a person and access ends when they do.
Why this matters
A shared login records that something happened, but not who did it. If unreleased content is downloaded or shared before it should be, a file is deleted, or a setting is changed, the log points at an account rather than a person — and if six people use that account, you cannot tell which one. An investigation has to move fast — the sooner you know what happened, the sooner it can be contained and reported. Individual accounts turn that into checking a record; shared ones turn it into interviewing everybody, which is exactly the delay you cannot afford.
Shared credentials also outlive the people who used them. A password known to a freelancer who finished last spring is still a working key, because nobody changes it when one person moves on. Individual accounts close that door the day someone leaves.
Stop account sharing — checklist
- List the logins currently shared: delivery portals, review platforms, storage, the edit suite machines, the studio's own systems, social and billing accounts.
- For each one, check whether the service supports individual users. Most do, often at no extra cost — the shared login is a habit rather than a limit.
- Create a named account for every person who needs access, and give each the level of access their role actually requires.
- Retire the old shared password once everyone has moved across, rather than leaving it working alongside the new accounts.
- Where a shared or service account genuinely cannot be split, put its password in a password manager, record who holds it, and change it whenever someone with access leaves.
- Stop using default logins that shipped with equipment or software. Rename them where you can and change the password where you cannot.
- Make removing accounts part of the leaving process, alongside returning kit and keys, so it happens the day someone finishes.
- Review the account list quarterly. Anyone who no longer needs access should not still have it.
If this one helped, try another.
Consider these suggestions for what to do next. They either address the same gaps, or are logical next steps.