High-impact

Stop account sharing

Replace shared and default logins with individual accounts, so activity is traceable to a person and access ends when they do.

Why this matters

A shared login records that something happened, but not who did it. If unreleased content is downloaded or shared before it should be, a file is deleted, or a setting is changed, the log points at an account rather than a person — and if six people use that account, you cannot tell which one. An investigation has to move fast — the sooner you know what happened, the sooner it can be contained and reported. Individual accounts turn that into checking a record; shared ones turn it into interviewing everybody, which is exactly the delay you cannot afford.

Shared credentials also outlive the people who used them. A password known to a freelancer who finished last spring is still a working key, because nobody changes it when one person moves on. Individual accounts close that door the day someone leaves.

Stop account sharing — checklist

  • List the logins currently shared: delivery portals, review platforms, storage, the edit suite machines, the studio's own systems, social and billing accounts.
  • For each one, check whether the service supports individual users. Most do, often at no extra cost — the shared login is a habit rather than a limit.
  • Create a named account for every person who needs access, and give each the level of access their role actually requires.
  • Retire the old shared password once everyone has moved across, rather than leaving it working alongside the new accounts.
  • Where a shared or service account genuinely cannot be split, put its password in a password manager, record who holds it, and change it whenever someone with access leaves.
  • Stop using default logins that shipped with equipment or software. Rename them where you can and change the password where you cannot.
  • Make removing accounts part of the leaving process, alongside returning kit and keys, so it happens the day someone finishes.
  • Review the account list quarterly. Anyone who no longer needs access should not still have it.