Shared Admin Logins: Who Can Lock a Singapore SME Out of Its Own Business?
If a staff member resigned tomorrow, or your web vendor stopped replying to emails, could you still log in to your own domain registrar, Meta Business account, accounting software and payment gateway? For most Singapore SMEs the honest answer is no, and the reason is almost always the same: critical accounts were opened under whoever happened to be doing the work that day, using a shared password or a personal email address. The fix is not enterprise identity software. It is a written ownership register that names, for every business-critical account, which company-controlled email owns it, who holds the second factor, and who can restore access if that person is unreachable. That register takes one afternoon to build and prevents the single most expensive kind of SME outage: being locked out of a system you actually own.
What does account ownership actually mean?
Ownership is not the same as access. Five people may be able to post to your company Facebook page, but only one account can remove the others, change the recovery email, or delete the asset outright. That is ownership, and in most small firms it sits somewhere nobody chose on purpose.
The three ownership patterns worth separating:
- Owned by the company. The account root is a company domain mailbox such as [email protected], the billing card is a company card, and at least two people can recover it.
- Owned by an individual. The account sits on a personal Gmail or a staff member's work email that will be deactivated the moment they leave. Common for domains, ad accounts, courier portals and Google Business Profile.
- Owned by a vendor. Your web developer, agency or IT contractor registered the asset in their own name and gave you user-level access. You are a tenant in something you paid for.
The second and third patterns are not theoretical problems. A domain registered under a departed employee's personal email expires, the website and all company email go dark, and recovery requires proving ownership to a registrar that has no record of your company at all.
Which accounts break a Singapore SME first?
Not everything deserves the same attention. In practice, a short list causes nearly all of the damage, and it is worth ranking by how fast the business stops if access is lost.
Stops the business within hours: domain registrar and DNS, company email tenant (Google Workspace or Microsoft 365), corporate internet banking tokens, payment gateway, and your point-of-sale or order system. Stops the business within days: accounting software super-admin, payroll and CPF submission access, your InvoiceNow or e-invoicing access point login, marketplace seller centres, and any customer database or CRM. Costs money and reputation, but survivable: social and ad accounts, Google Business Profile, courier and logistics portals, design and file storage tools.
Two Singapore-specific items get missed constantly. First, CorpPass assignment: if only the owner holds the relevant e-service roles, nobody can file or respond while they are travelling or hospitalised. Second, the bank token. Many SMEs run on a single hardware or mobile token held by one director, which means payment runs stop entirely when that person is unavailable, and tends to be the moment someone starts emailing payment instructions that look urgent and legitimate.
Why do shared logins survive even when everyone agrees they are bad?
Because they are the cheapest thing that works. Paying for one seat and sharing it saves perhaps $240 a year per tool; across eight tools that feels like real money to a firm watching 2027 cost step-ups. Shared logins also remove friction: no permission requests, no waiting for the boss, work gets done.
The cost shows up elsewhere. Shared accounts destroy attribution, so when a wrong price goes out or a customer record is deleted, there is no record of who did it. They make offboarding almost impossible, because revoking one person means changing a password everyone needs. And they concentrate second-factor codes on one phone, usually the owner's, which is why so many small firms discover the problem during a holiday.
The honest comparison is not seat cost versus zero. It is seat cost versus the hours and lost revenue of one lockout. Recovering a hijacked Meta Business account or a lapsed domain routinely consumes a week of someone's attention.
What does a one-afternoon access audit look like?
Four steps, in this order:
- List the money trail. Pull twelve months of company card and bank statements and highlight every software, hosting and platform charge. This finds subscriptions nobody remembers, including ones still billing a departed employee's card.
- Record ownership, not just access. For each account, write down the owning email, who holds the second factor, the recovery email and phone, and the renewal date. A single spreadsheet is fine. Keep credentials out of it; this register points to a password manager, it does not replace one.
- Move the critical ten to company control. Change the owning email to a company domain mailbox, add a second administrator who is not the owner, and move second factors into a shared authenticator vault or at least onto two devices. Domain and DNS first, every time.
- Write the lockout plan. One page: if the owner is unreachable for 72 hours, who can approve payments, who can reset access, and where the register lives. Store a printed copy outside the systems it describes.
For a 10-person firm this is three to four hours of work, and it is the cheapest resilience spending available. It also makes your PDPA position defensible, because you cannot credibly say who can access personal data if you cannot say who owns the systems holding it.
How do you stop the register from going stale?
Attach it to events that already happen. Add one line to onboarding and offboarding: update the ownership register. Review it when any vendor relationship ends, when a tool is added, and once a quarter against the card statement. Put renewal dates for domains and certificates into a shared calendar with a named owner rather than relying on registrar emails that land in one inbox. Ninety minutes a quarter keeps it accurate; the audit only hurts the first time.
Frequently asked questions
Is a password manager enough on its own?
No. A password manager stores credentials well but does not tell you which account is the true owner of an asset, who holds recovery rights, or what to do when a second factor is on an unreachable phone. Use both: the manager holds secrets, the register holds ownership and recovery facts.
Our web vendor owns our domain and hosting. How do we take it back without a fight?
Ask in writing for a domain transfer authorisation code and registrar transfer, and offer to keep paying them for management afterwards. Most reasonable vendors comply, because control was convenience rather than strategy. Frame it as continuity planning, not distrust, and do it while the relationship is still good.
How many administrators should a 10-person company have?
Two for every critical system, never one and rarely more than three. One is a single point of failure; four or five dilutes accountability. The second administrator should be someone who can act when the owner cannot, which often means a director or office manager rather than the most technical person on staff.
Lockouts do not announce themselves. They arrive attached to a resignation, a lapsed card, or a vendor who stops replying, and they always arrive in a quarter you were already busy. Spend the afternoon now.
Ready to Transform Your Business?
Let Digital Perpetual help you automate, streamline, and grow.
Get Started with Digital Perpetual →