Shared Accounts and Shared Machines
Why shared credentials exist, what they do to every record downstream, and the cheapest route to individual accountability without making the work harder.
A shared credential destroys attribution in every system it touches. A till operated under a supervisor code, a terminal on a shop floor with a generic login, a tablet the whole team uses — each produces timestamped rows with a name against them, and the name is a role rather than a person.
The identity gap described in “Shared Accounts and Shared Machines” matters when teams assess consult this product explanation for chronemics definition. The platform may make an activity or timestamp visible, yet a responsible review still distinguishes the device or account from the person, checks another source and records what the evidence does not establish.
The rows still look authoritative in a report. That is the problem: the weakness is invisible at the point the data is used, and visible only to whoever administers the system.
A broader reference for the question in “Shared Accounts and Shared Machines” is the FBI scams and safety resources. Read it alongside the local facts so that an external framework informs the assessment without replacing case-specific judgement.
Why they exist
Always for a good operational reason. Individual logins were too slow on a till at lunchtime. The machine is in a cold store and nobody can type a password with gloves. The account was created for a project in 2019 and four people inherited it.
None of these is laziness, which matters, because the fix has to address the reason rather than issue an instruction.
What they do downstream
Every analysis built on the data inherits the ambiguity. A report showing transactions by operator, time by user, or cases by assignee is a report about codes.
That is fine for operational purposes and fatal for anything about an individual. An investigation that reaches a conclusion from a shared code has reached it about a group.
Finding them
- Export the list of active accounts in each system.
- Flag any whose name is a role, a location or a generic word.
- Flag any used from more than one place at once.
- Flag any with more sessions per day than a person could work.
- Ask the system owner which ones are shared, and believe the answer.
- Record the list, because it is the caveat list for every later report.
Step three is the cleanest automated test. A credential used in two buildings eleven minutes apart is shared, whatever the register says.
Fixing it where the reason was speed
Individual credentials fail where they are slower than the work allows. The answers are mostly hardware: a card tap instead of a password, a second terminal, a device per person rather than per station.
Those cost money and they are the only things that actually work. An instruction to stop sharing, issued without changing the speed, produces compliance for a fortnight.
Fixing it where the reason was inheritance
Accounts shared because nobody closed them are the easy case: identify, reassign, close, and add account closure to the leaver checklist so it does not recur.
That one is pure housekeeping and it typically removes half the list without anybody having to change how they work.
Where it cannot be fixed
Some situations genuinely resist individual attribution — a control room, a shared vehicle, a machine in a hazardous area.
The honest response is to record that the credential is shared, attach the caveat to every report drawn from it, and look for attribution elsewhere: a rota, a handover sheet, a second system that is individual.
Keep a list of shared credentials and publish it with the reports they feed. A report that quietly attributes a shared code to one person is producing an error that nobody downstream can see.
The handover sheet
Where a station is shared, the paper or digital handover is often the only record of who was on it — and it is usually kept for a week and thrown away.
Retaining handovers for the same period as the system logs they explain costs nothing and converts an uninterpretable log into an attributable one. It is the cheapest fix in this section and the one nobody thinks of, because the handover is not regarded as a record at all.
The credential nobody closed
Accounts belonging to people who have left are the simplest version of this problem and the most common. They remain active, they are used because they are convenient, and every record they produce is attributed to somebody who is no longer there.
Reconciling active accounts against current staff quarterly finds them in one query, and closing them removes an entire class of uninterpretable record.
What this means for a case
A finding that rests on a shared credential is a finding about the role, and the step to an individual needs separate support — a rota showing who was on that station, a colleague, a second record that is individual.
Organisations discover this at the worst moment, when somebody points out that four people use the code. Knowing it in advance means the investigation starts in the right place, which is the rota rather than the log.