Can you send me the code?
A bookkeeper needs to download statements from a client's online banking viewer, or log into a supplier's portal to get invoices. They enter the password from the spreadsheet, and a code goes to the partner's mobile. The partner is with another client. The bookkeeper waits, then messages, then moves on to something else and forgets to come back.
Multiply that across many clients and many services. The partner's phone has become a piece of firm infrastructure, and it goes on holiday with them.
How it ended up like this
When the firm was small, the partner set up everything. Each client's portal, each supplier login, each tax account was registered with their details. As staff joined, passwords were shared in a spreadsheet or a notebook, and codes were passed on by text. It worked, just, and nobody had time to redo it.
Many services now offer better options, such as adding staff users, delegated access for agents, or authenticator apps that more than one person can use. Changing each one takes effort, and the old way keeps limping on.
What the old way costs and risks
Work stalls waiting for codes. The partner is interrupted constantly. When staff leave, nobody is sure which passwords they knew. A spreadsheet of client passwords is exactly the kind of file that should not exist. And clients themselves may not know how many people at your firm can see their accounts.
| Setup | What goes wrong |
|---|---|
| Passwords in a spreadsheet | Copied, emailed, never changed after leavers |
| Codes to one phone | Work waits for one person |
| Shared single login per service | No record of who did what |
| Staff user or agent access | Needs setting up once per service |
How we sort out client access for a firm
- We list every client and service where staff need access, with how access works today, by going through your spreadsheet and talking to the team.
- For each service, we check whether it offers proper multi-user or agent access. Where it does, we help you switch to it, so each person has their own login.
- Remaining shared logins go into a business password manager with vaults per client team, so people only see the clients they work on.
- Where a service allows authenticator app codes, these are set up inside the password manager so an authorised team member can get the code without the partner's phone. Where it only allows text codes, we look at options such as a firm phone number the service will accept.
- Every use of a shared login is logged in the password manager, and access is removed in one step when someone changes role or leaves.
- A simple register shows, per client, what access the firm holds and who has it, which is useful when a client asks.
We work within each service's own terms. Some services only permit the account holder to log in, and for those the right answer is to ask the client for a proper delegated user or a document export, not to share their login.
Access that does not depend on one phone
Bookkeepers get into what they need, when they need it, without chasing a partner. Leavers lose access the day they go. Nobody keeps a password spreadsheet. The partner's phone goes back to being a phone. And you can tell a client exactly who at the firm can see their accounts.
Does this sound familiar?
- Staff regularly ask a partner to forward a login code.
- Client passwords are kept in a spreadsheet or notebook.
- You are not sure which logins a leaver knew.
- Several people share one login for the same service.
- Work stops when a particular person is on holiday.