Access control

Shared logins: why shared Gmail is a liability for UK SMEs

Shared office@ passwords feel efficient until a leaver, a phishing click, or a buyer questionnaire.

If three people know the password to office@yourcompany.co.uk, you do not have an inbox. You have a shared key to customer data, supplier conversations, password resets, and often the recovery path for banking and cloud tools. It feels efficient. It is also one of the most common ways small UK firms lock themselves out, leak data, or fail a buyer questionnaire.

This guide is for owner-managers with roughly 5 to 50 staff. It explains why shared Gmail (and the Microsoft equivalent) is a liability, what to use instead, and a practical migration you can finish in a week without becoming the IT department.

What “shared login” actually means

A shared login is any account where more than one person uses the same username and password. Classic SME examples:

  • office@ or info@ Gmail / Google Workspace / Microsoft 365 mailboxes with one password on a sticky note
  • One person’s personal Gmail used as the company inbox
  • Shared Xero, FreeAgent, Shopify, Meta Business, or supplier-portal passwords in WhatsApp
  • A single admin account for the domain registrar or hosting panel “because only two of us need it”

Shared calendars and shared drives are fine. Shared passwords are not. The product usually already has a proper share or delegate feature. Using one password for many humans is the shortcut that ages badly.

Why shared Gmail keeps winning in small firms

It starts for boring reasons. Someone needs a mailbox before the company domain is ready. A temp covers reception. The bookkeeper needs invoices. Paying for another seat feels silly when “just send them the password” works today.

Then the inbox becomes the centre of the business: customer complaints, MFA codes, password-reset emails, HMRC notices, bank alerts, and the “forgot password” link for everything else. At that point the shared Gmail is not a convenience. It is the master key to the rest of the stack.

The real liabilities (not the scary brochure)

Skip the apocalypse language. These are the problems UK owner-managers actually hit:

  1. Leavers keep access. When someone leaves (or falls out with you), rotating one shared password is awkward. People keep old sessions on phones. You cannot prove who read what.
  2. No audit trail. If a customer email is deleted, a quote is altered, or a bank-detail change request is answered wrongly, you cannot say which person did it.
  3. Password resets cascade. Whoever controls the shared inbox can reset Microsoft 365, Xero, domains, social, and half your SaaS estate.
  4. MFA becomes theatre. Either MFA is off, or the OTP lands in a shared place and gets screenshotted into WhatsApp. That is not multi-factor authentication. That is a group chat.
  5. Cyber Essentials and insurance forms hate it. Access control questions expect unique accounts. Shared generic logins are a common weak answer on supplier questionnaires.
  6. GDPR and client trust. Personal data in a free-for-all inbox is harder to justify when something goes wrong. You do not need a lawsuit for this to waste a week.

None of this requires a nation-state attacker. A forgotten leaver, a phishing click, or a phone left unlocked is enough.

Shared Gmail vs proper company email

If you are still on consumer Gmail for company work, move to Google Workspace or Microsoft 365 Business with your own domain. That alone does not fix sharing, but it gives you admin controls, offboarding, and a company-owned identity.

Then stop sharing the password. Use:

  • Individual mailboxes for people (james@, rachel@)
  • Shared mailboxes or Google Groups / Microsoft shared mailboxes for info@ and support@ (people open them from their own login)
  • Delegation where one person needs to send as another without knowing their password
  • A password manager for any leftover true shared logins (registrar, niche supplier portals) with named owners and leaver rotation

The pattern: humans authenticate as themselves. Shared work gets shared through the product, not through a reused secret.

What to do instead this week

A one-week migration for a typical under-50 firm:

  1. Day 1 — List every shared password. Mailboxes, finance, social, domain, hosting, payment tools. Put the list in a temporary vault item, not in Slack.
  2. Day 2 — Fix email first. Create individual accounts. Convert office@ / info@ into a shared mailbox or group. Stop circulating the old password.
  3. Day 3 — Turn on MFA for every human account on Microsoft 365 / Google Workspace. Store backup codes in the company password manager.
  4. Day 4 — Rotate the dangerous shared SaaS logins (banking portals, Xero/FreeAgent admin, domain registrar, Meta Business). Unique passwords, vault items, named owners.
  5. Day 5 — Kill the anti-patterns. Delete the Excel password sheet. Remove the WhatsApp “passwords” chat. Tell staff the new rule in two lines.
  6. Day 6 — Offboarding dry run. Pick a hypothetical leaver. Can you disable their account in ten minutes and leave shared mailboxes intact?
  7. Day 7 — Write the house rule. “No shared passwords. Shared inboxes via shared mailbox/group. Secrets only in the company password manager.” Add it to onboarding.

How a password manager fits (without turning you into IT)

A team password manager does not replace proper email accounts. It replaces the spreadsheet and the WhatsApp thread for the few logins that genuinely cannot be individual yet.

For most UK SMEs under 50 seats, 1Password Business or Bitwarden Teams/Business is enough: company billing, vaults or collections by function, revoke a leaver the same day, MFA on the vault itself.

Roll out order that usually works: fix shared email identity first, then put remaining shared secrets in the vault, then uniquify personal work logins so reuse dies. See OwnerSec’s earlier pieces on password managers and stopping reuse if you need the longer rollout.

Special cases people argue about

“Our receptionist needs info@.” Use a shared mailbox. They open it while logged in as themselves.

“Our accountant needs invoices.” Guest access, a dedicated finance@ shared mailbox, or secure client portal. Not your personal Gmail password.

“Meta / Google Ads only allows one login.” Prefer Business Manager roles. If a true shared login remains, vault it, name two owners, and rotate on every leaver.

“We are only five people.” Especially then. Small teams feel shared passwords more when one person leaves or gets phished.

Cyber Essentials and buyer questionnaires

Shared generic accounts fight the access-control story in Cyber Essentials and many supplier forms. Unique accounts, MFA, and a clear leaver process are the answers those forms are fishing for. A password manager helps you operate that without heroics. None of this “gives you” a certificate by itself — see the Cyber Essentials beginner guide — but shared Gmail is a predictable weak spot when someone later asks how you control access.

Quick checklist you can copy

  • No consumer Gmail as the company system of record
  • Individual human accounts for every staff member
  • info@ / office@ as shared mailbox or group, not a shared password
  • MFA on the email suite for every person
  • Remaining shared SaaS secrets in a company password manager
  • Named owner + leaver rotation for every vault-shared login
  • Password spreadsheets and chat password dumps deleted
  • Two-line house rule in handbook and onboarding

FAQ

Is a shared mailbox the same as a shared password?
No. A shared mailbox lets authorised people open a common inbox while signed in as themselves. A shared password means many people know one secret.
Can we keep one emergency break-glass admin account?
Yes, if it is rarely used, stored in the vault, MFA-protected, and monitored. Do not use it as the daily inbox.
Will this stop phishing?
It limits blast radius and makes offboarding real. It does not stop someone clicking a bad link. Train people and keep MFA on.

Written for UK SME owners. More guides · How we make money