Back to blog
Guide

The Password Everyone Knows

One login, shared by everyone, changed the last time somebody left badly. What shared access actually costs, and the small number of changes that fix it without buying anything.

There is one login for the booking system. Everyone uses it. It was last changed when somebody left on bad terms, two years ago.

Nobody thinks this is ideal. Nobody has had a reason urgent enough to change it.

What a shared login costs

You cannot tell who did anything. ⚠️ The largest cost and the least obvious. A booking deleted, a price changed, a record altered — the system knows it happened and not who.

Leavers keep access. Until somebody changes it, which happens when there is a reason, which is exactly when it is too late.

Nobody can be trusted with more. ⚠️ Because everyone has everything, you cannot give one person more authority — permissions only exist if accounts do.

Mistakes cannot be corrected at the source. Someone is doing something wrong. You cannot see who, so you tell everybody, which is worse for the people doing it right.

Why it persists

Individual accounts feel like admin. Setting up, removing, resetting.

People forget passwords. ⚠️ A real operational cost, especially with casual staff, and it lands at the busiest moment.

It works. Until it does not, and then it fails all at once.

Nobody owns it. ⚠️ The recurring theme — access has no owner, so it drifts.

The minimum worth doing

Not a project. Four things:

Individual accounts for anyone who changes records. ⚠️ Not for everyone — for the people whose actions you would want to trace.

Remove access on the last day. A line on the leaving checklist, and there should be a leaving checklist.

One person owns the list of who has access. Reviewed quarterly. It takes ten minutes and it will contain surprises.

Different levels where the system allows. ⚠️ Not everyone needs to be able to delete things — and most of the damage that gets done is done by people who did not intend to.

The leaver case

The one that causes real harm.

Access removed the same day. ⚠️ Not "when we get round to it" — a departing member of staff with live access to guest data is a genuine exposure, whatever the circumstances of their leaving.

And the shared password changes too, if there is one. Otherwise removing their account achieves nothing.

Guest data deserves the higher bar

⚠️ In this industry specifically. Your records contain information guests would be seriously unhappy to see travel.

Who can see the guest list is a real question, and "everyone with the shared login" is a poor answer to it — regardless of how much you trust the current team, because the current team is not permanent.

Three to hold

People with access against people currently employed. ⚠️ Compare the two lists. There will be a gap.

Whether an action can be traced to a person. Pick a recent change and try. The answer is the whole assessment.

Days from leaving to access removal. Should be zero. Measure it on the last three leavers.

Where the record has to sit

Knowing who did something requires the system to know who was acting. A shared account cannot provide that no matter how carefully the rest is managed — the information was never captured.

tasteck records changes against the staff account that made them, so a change history answers who as well as what.

Nobody is careless. The shared login was the practical answer when there were three of you, and nothing since has forced the question.

Free, no signup, ~5 minutes

Map out your operations in 5 minutes

Eight questions cover reservations, customer management, shifts, and settlement. Results shown instantly with industry benchmark. Sales emails only if you request them.

Your answers are not stored. The assessment runs entirely in your browser.

Try tasteck free for 30 days

No credit card required. Full access to reservations, cast shifts, dispatch, and analytics.

  • No card required
  • Free data migration support
  • All features unlocked for 30 days