A Practical Access-Control Checklist for Business Systems

Practical access habits across websites, ERP, CRM, cloud platforms, repositories, automation tools and company accounts.

A Practical Access-Control Checklist for Business Systems

Scroll to read

Engineering Delivery · 1 July 2026 · 8 min read

By Peerprise Editorial Team

Access management is an operational discipline, not only a security task. When account ownership is unclear, routine work stops, former suppliers retain access and recovery depends on one person’s phone or inbox.

This checklist covers the controls most growing businesses should establish across websites, CRM, ERP, cloud platforms, repositories and automation tools: company-owned accounts, named users, least privilege, multifactor authentication, recovery, periodic reviews and prompt offboarding.

Why access control matters operationally

Access problems create more than security exposure. They also create operational delay.

Common examples:

  • A release cannot ship because only one person has repository or cloud access
  • A CRM update waits because ownership of the admin seat is unclear
  • A former contractor still appears in the ERP, hosting or automation admin list
  • A password reset stalls because the recovery inbox is unmanaged
  • An AI or analytics tool retains customer data under a personal login

Good access management protects the business and keeps delivery moving when people change.

Password managers and credential vaults

Shared spreadsheets and chat messages are poor places for credentials.

Use a company-owned password manager or credential vault for business accounts and:

  • Store unique passwords for every important service
  • Share vault items with named people rather than forwarding secrets in email
  • Separate human credentials from service-account secrets where possible
  • Remove access when responsibilities change
  • Keep ownership of the organisation vault with the business, not one employee personally

Multifactor authentication

Enable multifactor authentication on:

  • Website and CMS admin accounts
  • Hosting, domains and DNS
  • ERP and CRM platforms
  • Cloud consoles and infrastructure accounts
  • Code repositories and CI/CD systems
  • Email accounts used for recovery
  • Automation, AI and analytics tools with business or customer data

Prefer authenticator apps or hardware keys over SMS where possible. SMS is better than nothing, but app-based codes and security keys are stronger.

Named users and shared credentials

Shared logins are convenient and fragile.

Problems with shared accounts:

  • You cannot tell who changed what
  • Offboarding becomes guesswork
  • Multifactor setup gets tied to one device
  • People hesitate to rotate passwords because "everyone uses this"

Prefer individual user accounts with roles. If a platform truly allows only one login, keep it in the company password manager, minimise who can view it, and record every person who needs it. Rotate the password when anyone with access leaves.

Least-privilege access

Give people the minimum access required for their work.

Examples:

  • Editors who can update content without installing plugins or changing billing
  • CRM users who can manage their pipeline without exporting the full customer database
  • Analysts who can view dashboards without publishing or admin rights
  • Engineers with repository access limited to the systems they own
  • Billing owners separate from day-to-day operators

Review roles when a system changes purpose. Access granted for a launch or migration often remains long after the original team has moved on.

Contractor and supplier access

Contractors, agencies and temporary specialists need clear access boundaries.

Good practice:

  • Create named accounts when the platform allows it
  • Define which systems they need and which they do not
  • Set an expected end date or review date
  • Keep ownership of domains, hosting, cloud, ERP, CRM and company pages with the business
  • Avoid transferring primary ownership of critical accounts to an external personal profile

Before work starts, confirm who owns the asset and how access will be removed at the end. Peerprise handles client access carefully as part of Website Care and Integrations and Business Automation.

Recovery ownership

Every critical account needs a recovery path the business can use.

Check:

  • Recovery emails point to monitored company inboxes
  • Recovery phone numbers are current
  • Backup codes exist and are stored securely
  • Domain registrar, hosting, cloud and ERP recovery details are up to date
  • Service accounts and API keys have documented owners and rotation rules

Access reviews

Put access reviews on a calendar.

A simple quarterly review can cover:

  • Website admins and editors
  • Hosting, DNS and cloud accounts
  • ERP, CRM and finance platforms
  • Code repositories and deployment tools
  • Automation, AI and analytics systems
  • Email lists used for notifications
  • Connected apps, integrations and service accounts
  • Password manager memberships

Remove unused accounts instead of leaving them "just in case." Unused access is forgotten access.

Offboarding checklist

When someone leaves the business or a contractor engagement ends:

  1. Revoke website, CMS and application access
  2. Remove hosting, DNS, cloud and repository access
  3. Remove ERP, CRM, automation and analytics roles
  4. Rotate any shared passwords or keys they could view
  5. Remove them from the password manager
  6. Check recovery emails and notification lists
  7. Review connected apps authorised under their account
  8. Confirm who now owns each responsibility

Complete this promptly. Waiting until "later this month" is how inactive access survives.

A practical baseline for most businesses

If you only implement a few habits, implement these:

  • Company-owned password manager or credential vault
  • Unique passwords and named users where possible
  • Multifactor authentication on critical accounts
  • Least-privilege roles
  • Documented recovery ownership
  • Quarterly access review
  • Clear offboarding steps
  • Documented service accounts and integrations

These basics prevent many common failures without slowing the team down.

Bring access into normal operations

Access management should sit with day-to-day operations, not as a one-off cleanup every few years. Whenever tools are connected or workflows change, update who can see and change what.

This checklist is operational guidance, not a formal compliance certification, penetration test or legal review.

If your current setup depends on shared passwords, personal recoveries or informal handovers, start with an inventory of accounts and owners. That inventory often reveals more risk than any single weak password.

Peerprise can help review access as part of a Systems and Automation Review or ongoing Integrations and Business Automation support.

Key takeaways

  • Use a company-owned password manager and unique credentials for critical accounts.

  • Enable multifactor authentication with a business-controlled recovery path.

  • Prefer named roles and least privilege over shared logins.

  • Review access quarterly and offboard promptly when people leave.

Peerprise Editorial Team

Software Engineering and Business Systems

Practical insights from the Peerprise team on custom software, ERP, CRM, AI automation, integrations, modernization and engineering delivery.

02Next step

Need advice for your own system?