adNET Academy Blog

One Login For Five People? That's A Problem.

Written by Lucas Miller | Jul 30, 2026, 8:00:00 PM

Imagine if you will, a small accounting firm splitting the login for one of their newly cloud-only applications amongst all of the staff in both a fit of defiance for forcing them out of the system they've known for years and in protest of now needing to license every single person individually. For a good chunk of the year it chugs along just fine, it's a little annoying when more than one person wants to use it, but they get by.

That is right up until the system flags the account for the multiple simultaneous logins coming in from all over the place and locks everyone out, right in the middle of tax time, until the account is trued up correctly.

Why Shared Logins Feel Like The Easy Choice

Sometimes sharing a login is a snap decision when someone needs a tool in a pinch and someone else already has an account, or like above, it gets passed along instead of paying for another seat. It solves the immediate problem, but it also creates a cost that shows up later, usually at the worst possible time.

One License Equals One Person 

Most software subscriptions come with a terms of service agreement that specifies who can use that login, typically one named individual tied to one email address using the account for their own work. Sharing that login among several people usually violates the agreement the business agreed to when it signed up, on top of the security risk it creates.

Vendors enforce this differently. Some monitor logins and flag or suspend accounts automatically, similar to what happened at the accounting firm above. Others rely on periodic audits around renewal time and when the math isn't mathing, businesses are required to true up immediately and maybe get hit with fines for the period of unauthorized use.

For organizations in regulated fields, like CPAs handling client financial data or medical practices governed by HIPAA, there's an added layer. Shared access is a failure to properly maintain access controls, which will become a big issue in the event of a data breach or similar incident.

The Risk Depends On What The Account Can Do

Not every shared credential carries the same risk. A read-only login to a reporting dashboard that nobody can use to change data or export client information is a different situation than a shared admin login to your accounting platform or your bank's business portal. The risk scales with what the account can actually do and what it can see.

A reasonable test - if the account can access or change things like client data or financial records, it needs an individual login in your identity system. If the account is limited to something like viewing a public dashboard or checking a shared calendar with no sensitive content, sharing it is a minor inconvenience rather than a real exposure. However, most shared logins fall into that first category, which is why they need to be done right.

Audit Logs And Shared Credentials

For medical practices and legal firms handling client data, shared logins create a specific problem beyond convenience. When five people use the same credential, there's no way to determine who actually took a given action inside that tool. Audit logs tied to a shared account only show the account name. They can't identify which of the five people was actually using it at any given moment. If you ever need to demonstrate who accessed what and when, a shared login can't answer that question.

This matters most in a breach or dispute. If a client later questions a change made to their file, or a regulator asks who accessed a specific record and when, an audit log that only shows a shared account name leaves the firm explaining that four people had access and none of them can be ruled out or confirmed.

A shared login can look like a straightforward way to save on per-seat pricing. The savings disappear the moment a software audit results in fines or the access logs can't tell you which employee out of a possible five mixed up the last round of entries. 

What To Do Instead

If cost is the reason a login gets shared in the first place, it's worth checking to see if the vendor offers a lower-cost license tier or a viewer/read-only option, that still ties to an individual identity instead of a shared password. Not every platform offers this, but when they do it can solve the problem without paying full price for every occasional user.

Once everyone has their license, single sign-on makes managing those identities easy. When your identity system is the source of truth for all your connected tools, revoking access is a snap when someone leaves, and avoids having to reset passwords on shared logins. Your audit logs will also have data you can trust.