Passwords are not an access-management system
A shared login makes it difficult to identify who changed something, remove one provider cleanly or protect the owner account with individual security controls. One-time passwords are security checks and should never be forwarded.
Use the role intended for the task
The business should remain owner or co-owner. A provider receives the appropriate manager or account role after the scope is agreed. Google Ads and website systems also have their own access models; one invitation does not unlock every platform.
Keep an access record
Record the account, role, date, authorised person and purpose. Review active access periodically and remove the provider when the service ends. Sensitive actions should still follow the agreed approval rules.
Last reviewed: 16 August 2026. Provider features and policies can change; confirm current account controls before acting.