OdinTask field-service app OdinTask ODINTASK · GUIDE
security

Shared Logins in a Trades Business: The Real Risk and Fix

11 July 2026 · 9 min · securityadmintime clockcompliancefield service

Shared logins in a trades business break the one thing your records exist to prove: who did what, and when. If four sparkies sign in as info@, every signed protocol, every clock-in, every price change and every deleted job carries the same name, and that name is nobody. The fix is neither complicated nor expensive: one account per person, a role that matches the job, an offboarding checklist you run the day someone leaves, and a lost-phone procedure you have actually tested. Here are all four.

What shared logins in a trades business actually destroy

People assume the risk of a shared account is a hacker. The realistic damage is quieter, and it lands on you.

Attest and sign-off stop meaning anything

An attested self-inspection (in Sweden, an egenkontroll; in the UK, your test certificate or handover sign-off) is a statement by a named, competent person that the work was checked. Its whole value is the name. When the record says the account was kontor@firma.se, you have a document that proves an inspection happened somewhere, by someone, with no way to link it to the person who holds the qualification.

You find out this matters at the worst moment: a customer disputes a job eighteen months on, or an insurer asks who signed off the consumer unit. "One of the lads" is not an answer that survives a claim.

Time-clock records become unusable

A time clock on a shared account produces overlapping, physically impossible shifts: one account clocked in at two addresses at once. You cannot run payroll from that, you cannot bill hours from it with a straight face, and you cannot defend it if someone challenges their pay.

The obligation is real in every market. In the UK, the Working Time Regulations 1998 require adequate records of hours, kept two years (gov.uk). In New Zealand, wage and time records must be kept for years, not months. In Sweden, construction sites run an electronic staff ledger (personalliggare) registering each individual on site, and the ID06 card system exists because "the company was here" is not enough; see Skatteverket. Every one of those regimes assumes a person, not a mailbox.

The audit trail turns into noise

Every decent system logs who changed a price, who deleted a photo, who marked an invoice paid. With shared logins the log still fills up, it just tells you nothing. When a quote gets discounted heavily and nobody remembers agreeing to it, you have a perfect record of a mystery.

Offboarding becomes impossible

This is the one that costs money. A shared password cannot be revoked from one person. When someone leaves you either change it for the whole firm, then spend a fortnight fielding "I can't get in" calls from six vans, or you do nothing and accept that a former employee still has your customer list and your margins on their personal phone. Most firms do nothing.

Five records that need a name on them

RecordWhy a shared account breaks itWho asks for it
Signed protocol / self-inspectionCannot tie the sign-off to a competent personCustomer, insurer, regulator
Clock-in / clock-outOverlapping shifts, no per-person totalsPayroll, employee, labour inspectorate
Site attendance ledgerRegisters a company, not an individualTax authority, main contractor
Quote and price changesNo accountable author for a discountYou, at month end
Customer data accessNo way to show who read or exported whatGDPR / privacy complaint

On that last row: GDPR Article 32 asks for security appropriate to the risk, Article 5(1)(f) makes you responsible for confidentiality. A shared login does not automatically break the law. It does make the first question after any incident, who had access?, unanswerable.

Account hygiene for a small firm: the routine

You do not need a policy document. You need four habits.

1. One account per person, including the boss

Real name, personal work email. No info@, no shared iPad account everyone taps into. If a person is on your payroll or your subcontractor list, they get an account.

Subcontractors are where firms cheat. Give them their own account with a narrow role and an end date in your calendar. Passing them the crew password because "they're only here for the loft conversion" is how a login outlives the job by three years.

2. Roles that match the job, not the seniority

Two roles cover most 1–20 person firms:

This is not distrust. Fewer people with the dangerous permission means fewer accidental deletions, fewer leaked margins, and a much smaller mess when a phone goes missing.

In OdinTask this shows up in the billing: an admin seat and an on-site worker seat are separate things, which is what keeps per-person accounts sane rather than a per-head tax on the whole crew. Figures live on the pricing page, because they change.

3. Passwords: stop trying to remember them

4. Review the list quarterly

Open your user list four times a year, next to your VAT return so you never forget. Three questions per row: does this person still work here, is their role still right, have they signed in this quarter? Three noes means deactivate. Ten minutes, and it is the highest-value security task a small firm does.

The day someone quits: a 30-minute checklist

Do this on their last day, not the following Monday. That gap is where the customer list walks out.

  1. Deactivate, do not delete. Deleting a user can orphan their signed protocols, time records and job history — exactly the trail you need if that work is questioned. Deactivate instead: they cannot sign in, the history keeps their name on it.
  2. Reassign open work. Scheduled jobs, unfinished quotes, draft invoices, service agreements they own. Do it before deactivating so nothing lands in limbo.
  3. Close the time clock. Close any open shift and export their hours to payroll now, while you remember the context.
  4. Revoke email and shared drives. Forward the mailbox to yourself for 90 days, then close it. Check for forwarding rules they set up: a forward to a personal address survives everything else on this list.
  5. Remove the phone. Company handset: collect it. Their own: remove the work account and confirm the field app is signed out, in front of them.
  6. Kill the shared stuff they knew: supplier portals, the wholesaler account, the alarm code, the yard key code, the office Wi-Fi. These are the ones firms miss.
  7. Write the date down. One line: who, when, what was revoked.

If the departure is not friendly, do all of it within the hour they are told.

Lost or stolen phone: the first hour

A van phone with the field app on it is a customer database with a screen. Keep these steps on the office wall.

  1. Sign the account out everywhere from a laptop. In any decent system this is one action on that user, and it kills the session on the device.
  2. Force a password change on that person's account and re-enrol their two-factor. Their account, not the whole firm's — only possible because you did not share the login.
  3. Remote lock or wipe the handset via Find My iPhone or Google Find Hub. Lock first if it might be under a floorboard on site; wipe if it is truly gone.
  4. Check the audit trail for activity after they last had it. Signed in from where? Anything exported?
  5. Notify if data walked. Under GDPR you have 72 hours to report a personal-data breach to the supervisory authority (in Sweden, IMY) if it is likely to be a risk to people. A locked, encrypted, wiped phone usually is not. An unlocked one full of customer addresses might be. Decide deliberately, write down why.
  6. Get them working again. New device, new sign-in. Whatever was queued on the dead phone is gone, but the job on the server is not.

"We're four people, we trust each other"

Per-person accounts are not about trust. They are about proving things later, to people who do not know your crew. Your best electrician's signature is worth something precisely because nobody else could have made it. And the cost objection cuts the other way: extra seats are a monthly line item, while one disputed job you cannot prove lands all at once, at the worst possible time.

Migrating off shared logins this week

No project plan needed. One evening:

From then on, every signed protocol, every clock-in and every price change carries a name. Records that trace to a person hold up in a dispute; records that trace to a mailbox do not.

If you want accounts, roles, the geofenced time clock, attested protocols and the audit trail in one place instead of five, that is what OdinTask is for. Start a free 14-day trial and set it up with real names from day one. Far easier than untangling it in year three.

FAQ

Is it illegal for a trades business to share one login?

Not by itself, in most countries. What gets you into trouble is the consequence. GDPR Article 32 requires security appropriate to the risk, and working-time and site-attendance rules assume records identify an individual. A shared login makes it impossible to show who accessed customer data or who worked which hours, so you fail the record-keeping obligation rather than a password rule.

Should I delete or deactivate a user when someone leaves?

Deactivate. Deleting the user can orphan their signed protocols, time records and job history, which is exactly the evidence you need if that work is disputed later. Deactivating blocks sign-in immediately while keeping their name on the records they created. Only delete if you have a genuine legal obligation to erase the data, and take a copy of what you must retain first.

How many admin accounts should a small firm have?

Two or three, and no more. Admins see money: margins, price lists, invoices, payroll export and settings. Typically that is the owner and whoever does the books, with a second owner or office manager as backup so a lost phone does not lock you out. Everyone else works fine on a field-worker role that shows their own jobs, schedule, time clock and protocols.

What do I do first if an employee's work phone is stolen?

From a laptop, sign that user out of all sessions and force a password change on their account, then remote lock or wipe the handset with Find My iPhone or Google Find Hub. Check the audit trail for any activity after they lost it. If unencrypted customer data was exposed, GDPR gives you 72 hours to report the breach to the supervisory authority.

Do subcontractors need their own accounts?

Yes, if they touch your system at all. Give them a field-worker role limited to the jobs they are on, and put an end date in your calendar for the day the contract finishes. Handing over the crew password because it is a short job is how a login outlives the work by years, with nobody left who can revoke it individually.

Should we still force everyone to change passwords every 90 days?

No. Scheduled rotation produces predictable passwords and sticky notes in the van, which is worse than a strong password left alone. Modern guidance from bodies like NCSC and NIST is to change on suspicion of compromise, not on a calendar. Put the effort into a password manager and two-factor authentication with an authenticator app instead.

One system for your field-service business

Booking, quotes with ROT, scheduling, an offline app, time tracking and invoicing — in your own brand.

Try OdinTask free