Introduction
For years, the company has been using its domain, website, email, CRM, advertising dashboard, and phone system. Everything works fine until an employee quits, a contractor goes missing, or a phone with 2FA is lost. After that, it suddenly becomes clear that the business owner has no control over some of these critical services.
This kind of problem rarely seems urgent at first. As long as everything is working, access rights seem like a mere formality. But when a conflict arises, the site is migrated, an account is blocked, or the contractor is changed, it becomes a real risk of sales coming to a halt.
What Needs to Be Inventoried
- domain: who owns it, where it's registered, and which email address is associated with it;
- DNS: Where records are managed and who has access;
- Hosting or server: who is the administrator, and what login methods are available;
- Email: Who is the super admin? Where are the backup contacts? Is 2FA enabled?;
- CRM and Telephony: Who is the owner, and which integrations are enabled;
- Advertising and analytics: who holds the ownership rights;
- Recovery codes and 2FA: where they are stored and who can restore access;
- Former Employees and Contractors: What Rights Remain After They Leave.
Progress of the Work
First, compile a list of critical services. Don’t start by haphazardly changing all your passwords—you could accidentally disrupt a working integration or lose access permanently. It’s better to get a clear picture of your accounts first.
Next, roles are reviewed: where an owner is needed, where an administrator is required, and where temporary technical access is sufficient. It is best to replace employees’ permanent personal accounts with managed work accounts or properly configured roles.
Two-factor authentication (2FA) is verified separately. A common problem is that while access seems to be available, the recovery process is tied to the phone or email of someone who no longer works on the project. In such a situation, the password alone does not resolve the issue of access control.
What is considered a normal result?
After the audit, the owner should understand:
- where each critical service is located;
- who is the owner or primary administrator;
- Which access rights need to be removed;
- What types of permits should be issued on a temporary basis for work purposes?;
- where to enable or transfer 2FA;
- Which backup access points and codes should the owner keep on file?
Conclusion
Access credentials are just as much a part of the infrastructure as a server or a domain. If a business doesn’t control its key accounts, it depends not on the service, but on a random person. Taking inventory of access rights reduces the risk of sudden account suspension, domain loss, email outages, or conflicts with a former contractor.