---
id: KB-AD-015
url: https://app.codecontract.io/help/administration/accounts-shared-between-several-people
idioma: en
categoria: administracion
audiencia: administrador
nivel: intermedio
actualizado: 2026-08-13
tambienEn: [es]
relacionados: [KB-AD-002, KB-AD-004]
citadoPor: [KB-ET-017]
---

# Accounts shared between several people

_The reception account, the warehouse one, the admin one: convenient until the day you need to know who did something._

**Responde a:** several people use the same account · shared warehouse account · i cannot tell who made a change · moving away from shared logins

Nearly every company has one: an account three or four people use because "it belongs to the desk". It works fine and causes no trouble until the day a very specific question needs answering — who did this, when, and with what permission — and there is no answer.

## What a shared account breaks

| What breaks | Practical consequence |
| --- | --- |
| The activity log | It says what was done, not who: it stops working as evidence |
| Offboarding someone | They leave and still know the password |
| Alerts and tasks | They go to nobody's inbox and get read by whoever remembers |
| The assistant's answers | It sees what the account sees, not what each person should |

> [!IMPORTANT]
> The second row accumulates the most real risk and is the most invisible. When someone leaves, their own access is withdrawn — but if they knew the shared password, that password stays valid and nobody changes it, because changing it means telling the other three. In practice, that access outlives the person by years.

## How to get out of it without falling out with the team

1. **Count what it is actually used for** — It is nearly always two or three specific tasks, not "everything".
2. **Give each person their own account** — With the permission those tasks need, which is usually less than the shared one has.
3. **Leave no open session on the common device** — The step that meets most resistance and changes the most.
4. **And retire it after a month unused** — Not before: if something depended on it, that month will show it.

> [!WARNING]
> The common-device case — the warehouse computer, the reception tablet — is what really has to be solved, because that is where shared accounts are born. The answer is not to ban it: it is that each person logs in as themselves and the device stores nobody's password. If that turns out to be too awkward for the pace of work, say so openly and find another route, because a rule that gets in the way gets bypassed.

## When a non-personal account is legitimate

**En corto**

- For an integration or an automatic process: there is no person behind it, and that is fine.
- With minimum permissions and a named owner, even if they never use it.
- And knowing what breaks if it is revoked, which is exactly what "remove and wait" cannot test.

> [!NOTE]
> Everything done from the shared account stays in the log: it is not lost when you stop using it. What cannot be done is reconstructing afterwards which of the four people did what — which is why the change is worth making before you need it, not after.

**Does each person take a seat?**

Yes, every user counts; in exchange the log says who did what again.

**What if the team resists?**

It is nearly always about the awkwardness of logging in, not the principle. Solve that first.

**Can I find out who used the shared account in the past?**

The log shows the account, not the person. That is exactly what is lost.

## Ejemplos

**A warehouse works from a common account on the goods-in tablet.**

- Gives the four people on shift their own accounts
- Leaves no saved password on the tablet and retires the shared one after a month

→ The log says who received each delivery again — exactly what was missing in the last claim.

**One account is used by three people.**

- Gives each of them an account

→ The log says who did what.

**Somebody leaves and the shared password has to change.**

- Removes only their account

→ Nobody else has to change anything.

**Nobody knows who made a change.**

- Checks the log by user

→ The action has an author.

**The shared account is used to save licences.**

- Weighs the real cost of not knowing who did what

→ The decision is taken with both sides in view.

**The password is shared over messaging.**

- Creates individual accounts instead of sharing

→ The credential stops circulating.
