Shared Account Management

Purpose & Scope

This procedure defines how shared accounts are identified, approved, secured, accessed, and reviewed at Evercam, to ensure accountability and prevent unauthorised or untraceable use of credentials.

This policy applies to all shared accounts used for business, operational, or technical purposes, including:

  • Shared logins to third-party SaaS platforms where per-user licensing is not feasible

  • Service/system accounts used for integrations, automation, or scheduled jobs

  • Emergency/break-glass accounts (where applicable)


Roles and Responsibilities

Role

Responsibility

System Owner (Approver)

Reviews and approves business need, approves the list of authorised personnel

Vault Administrator

Provisions the credentials in Zoho Vault, sets access restrictions

Information Security

Conducts periodic access reviews and maintains the shared account register

Procedure

Requesting a Shared Account

  1. The requester submits a business justification for why a shared (rather than individual) account is required — e.g., platform limitation, vendor-mandated single login, service account needed for automation.

  2. The justification, along with the proposed list of personnel who require access, is submitted to the System Owner for approval. The System Owner is accountable for authorising shared account use on the system(s) they own.

  3. Approval is documented (email, ticket, or sign-off in the shared account register) and retained as audit evidence.

Provisioning and Storage

  1. Approved shared account credentials are stored in Zoho Vault — no shared credentials are stored in plaintext, spreadsheets, chat tools.

  2. Access to each vault entry is restricted to the named, approved personnel only, via Zoho Vault's group/user-level sharing permissions.


Access Management

  1. Access to a shared account in Zoho Vault is granted only to personnel explicitly listed in the approved request.

  2. Any request to add or remove a user from a shared account's access list follows the same approval process as initial provisioning, with the System Owner's sign-off.

  3. Access is revoked immediately upon:

    • Role change removing the business need

    • Termination or offboarding (per the Offboarding/Termination Procedure)

    • System Owner's decision to revoke


Evidence Retained for Audit

  • Business justification and System Owner approval records for each shared account

  • Zoho Vault screenshots showing: restricted access group/user list, sharing permissions, and (where available) access/audit logs

  • Evidence that root login is disabled (e.g., server configuration screenshots or a config management/Drata test result)


Created by: Compliance Team

Creation date: 29.09.2026

Document Approver: CTO