The Password Everyone Knows
One login, shared by everyone, changed the last time somebody left badly. What shared access actually costs, and the small number of changes that fix it without buying anything.
What a shared login costs
You cannot tell who did anything. ⚠️ The largest cost and the least obvious. A booking deleted, a price changed, a record altered — the system knows it happened and not who.
Leavers keep access. Until somebody changes it, which happens when there is a reason, which is exactly when it is too late.
Nobody can be trusted with more. ⚠️ Because everyone has everything, you cannot give one person more authority — permissions only exist if accounts do.
Mistakes cannot be corrected at the source. Someone is doing something wrong. You cannot see who, so you tell everybody, which is worse for the people doing it right.
Why it persists
Individual accounts feel like admin. Setting up, removing, resetting.
People forget passwords. ⚠️ A real operational cost, especially with casual staff, and it lands at the busiest moment.
It works. Until it does not, and then it fails all at once.
Nobody owns it. ⚠️ The recurring theme — access has no owner, so it drifts.
The minimum worth doing
Not a project. Four things:
Individual accounts for anyone who changes records. ⚠️ Not for everyone — for the people whose actions you would want to trace.
Remove access on the last day. A line on the leaving checklist, and there should be a leaving checklist.
One person owns the list of who has access. Reviewed quarterly. It takes ten minutes and it will contain surprises.
Different levels where the system allows. ⚠️ Not everyone needs to be able to delete things — and most of the damage that gets done is done by people who did not intend to.
The leaver case
The one that causes real harm.
Access removed the same day. ⚠️ Not "when we get round to it" — a departing member of staff with live access to guest data is a genuine exposure, whatever the circumstances of their leaving.
And the shared password changes too, if there is one. Otherwise removing their account achieves nothing.
Guest data deserves the higher bar
⚠️ In this industry specifically. Your records contain information guests would be seriously unhappy to see travel.
Who can see the guest list is a real question, and "everyone with the shared login" is a poor answer to it — regardless of how much you trust the current team, because the current team is not permanent.
What you lose is the ability to answer a question
"Who changed that booking?"
"Who exported the guest list?"
"Who voided that ticket?"
⚠️ With one shared login, every answer is "someone." ⇒ The cost is not theft. It is that you cannot investigate anything, including the cases where nobody did anything wrong.
The second-order cost
⇒ When you cannot tell who, suspicion lands on whoever is least liked. A shared login does not protect the team; it exposes them.
The three excuses, and what each actually means
"It is faster" → the login flow is genuinely too slow. Fix that.
"They forget theirs" → nobody ever set them up properly. Do it once.
"We are too small for that" → small teams have the least slack when it goes wrong
⚠️ The third is backwards. A large venue absorbs one bad night; a small one does not.
Do it in the order that costs least
1. Separate accounts for anyone who can change money or guest data
2. Everyone else keeps working exactly as before
3. Add the rest at the next natural moment (new hire, new device)
⚠️ Do not attempt everyone at once. A migration that inconveniences the whole team on a Friday gets reversed by Saturday.
The leaver checklist nobody has
Their account disabled the same day
Shared passwords they knew changed within the week
Devices returned or wiped
Group chats removed
⚠️ Two is the one that gets skipped, and it is the only one that matters if there is still a shared login anywhere.
Make it a checklist, not a memory
⇒ ⚠️ Leaving is emotional and rushed. Anything not written down does not happen on that day — and it will not happen later either.
Guest data is a different category
Operational data inconvenient if lost
Guest data a problem for the guest, not just for you
⚠️ This is not only an internal matter. Rules on holding and handling personal data vary by jurisdiction and change over time. ⇒ Take advice from a qualified professional. This page covers only what a venue can decide internally.
There is one login for the booking system. Everyone uses it. It was last changed when somebody left on bad terms, two years ago.
Nobody thinks this is ideal. Nobody has had a reason urgent enough to change it.
Three to hold
People with access against people currently employed. ⚠️ Compare the two lists. There will be a gap.
Whether an action can be traced to a person. Pick a recent change and try. The answer is the whole assessment.
Days from leaving to access removal. Should be zero. Measure it on the last three leavers.
Where the record has to sit
Knowing who did something requires the system to know who was acting. A shared account cannot provide that no matter how carefully the rest is managed — the information was never captured.
tasteck records changes against the staff account that made them, so a change history answers who as well as what.
Nobody is careless. The shared login was the practical answer when there were three of you, and nothing since has forced the question.
Read next
Related articles
Who Types The Request In
A guest asks for somebody by name. Between that sentence and the figure on your monthly sheet, three or four people handle it. Every one of them is a place where it can quietly vanish.
What One More Regular Is Worth
Venues in this trade know what a quiet Tuesday costs them. Far fewer can say what one additional regular is worth over a year — which is the only number that tells you what you can sensibly pay to find one.
What a Listing Is Worth To One Room
A single-room salon and a twelve-room clinic get the same price from the same portal. Only one of them can work out whether that price is defensible, and it is the small one — because the arithmetic is smaller.
Map out your operations in 5 minutes
Eight questions cover reservations, customer management, shifts, and settlement. Results shown instantly with industry benchmark. Sales emails only if you request them.
Your answers are not stored. The assessment runs entirely in your browser.
Try tasteck free for 30 days
No credit card required. Full access to reservations, cast shifts, dispatch, and analytics.
- No card required
- Free data migration support
- All features unlocked for 30 days