Shared Account Management
Purpose & Scope
This procedure defines how shared accounts are identified, approved, secured, accessed, and reviewed at Evercam, to ensure accountability and prevent unauthorised or untraceable use of credentials.
This policy applies to all shared accounts used for business, operational, or technical purposes, including:
Shared logins to third-party SaaS platforms where per-user licensing is not feasible
Service/system accounts used for integrations, automation, or scheduled jobs
Emergency/break-glass accounts (where applicable)
Roles and Responsibilities
Role | Responsibility |
|---|---|
System Owner (Approver) | Reviews and approves business need, approves the list of authorised personnel |
Vault Administrator | Provisions the credentials in Zoho Vault, sets access restrictions |
Information Security | Conducts periodic access reviews and maintains the shared account register |
Procedure
Requesting a Shared Account
The requester submits a business justification for why a shared (rather than individual) account is required — e.g., platform limitation, vendor-mandated single login, service account needed for automation.
The justification, along with the proposed list of personnel who require access, is submitted to the System Owner for approval. The System Owner is accountable for authorising shared account use on the system(s) they own.
Approval is documented (email, ticket, or sign-off in the shared account register) and retained as audit evidence.
Provisioning and Storage
Approved shared account credentials are stored in Zoho Vault — no shared credentials are stored in plaintext, spreadsheets, chat tools.
Access to each vault entry is restricted to the named, approved personnel only, via Zoho Vault's group/user-level sharing permissions.
Access Management
Access to a shared account in Zoho Vault is granted only to personnel explicitly listed in the approved request.
Any request to add or remove a user from a shared account's access list follows the same approval process as initial provisioning, with the System Owner's sign-off.
Access is revoked immediately upon:
Role change removing the business need
Termination or offboarding (per the Offboarding/Termination Procedure)
System Owner's decision to revoke
Evidence Retained for Audit
Business justification and System Owner approval records for each shared account
Zoho Vault screenshots showing: restricted access group/user list, sharing permissions, and (where available) access/audit logs
Evidence that root login is disabled (e.g., server configuration screenshots or a config management/Drata test result)
Created by: Compliance Team
Creation date: 29.09.2026
Document Approver: CTO