September 18, 2026 ยท Oakleigh
The Accounts
The "Ask Karen for the Password" Problem
The first ten minutes of a consult, or a first session with an agent, expose the same problem almost every time: the software a business depends on was signed up for by one employee, on their personal email, and nobody else has the login. Whoever is helping asks who can grant access, and the honest answer turns out to be one specific person, who may or may not be in the room.
Nothing deliberate caused this. Somebody needed a tool fast, signed up on whatever email was open at the time, and the business simply grew around an account that was never really the business's to begin with. Nobody sat down and decided the company's invoicing software should belong to one employee personally; it happened under deadline, with no one clocking that a decision was even being made.
Doesn't matter whether it's a paid subscription or a free service somebody just clicked through. If one person's personal email is the login, that person owns the tool, not the business. Everyone else, including anyone hired to help, ends up locked out or working around them instead of with a system.
What "The Business Owns the Account" Means
A business-owned account has one property that matters: its login belongs to the business itself, not to a personal email, so it doesn't walk out the door with whoever happened to set it up. On top of that, more than one person needs a real way in, whether that means credentials shared securely between a few people or a service with actual multi-user access built into it.
None of this means everyone needs access to everything. A business can keep tight control over who touches what and still make sure that control belongs to the business, not to a single irreplaceable person. What has to be true is narrower than full access for all: access simply can't depend on exactly one specific person being reachable on any given day.
Why This Is Not Paranoia
Own the account, and the business controls who gets in, and just as important, who does not.
The day the login-holder is on vacation, sick, or simply gone, everything behind that login stops being usable for everyone else, at the exact moment somebody needs it. Hiring an agent runs into the identical problem on day one: it needs access granted the way a new employee's would be, deliberately and by the business, and that only works if the business actually controls who gets to grant it. Waiting on whoever set up an account to come back online before anyone else can touch the software is not a workaround for this problem. It is the failure this whole step exists to head off.
None of this is about distrust of an employee. It's about surviving the ordinary fact that people go on vacation, get sick, and eventually leave, none of which should be able to take the business's own tools down with them.
The 20-Minute Fix
Start by listing the handful of logins the business actually depends on, usually five or six once someone sits down and counts. For each one, note whether it currently sits on a business login or a personal one, and move the ones that would cause the most trouble if they went unreachable tomorrow morning first.
Then write down, securely, who holds access to what right now. That's not busywork for its own sake; it just means "who can get in" stops depending on anyone's memory, including the memory of whoever happens to be out sick the one day it actually matters.
Next: The First Prompt
Findable files, real files, and accounts the business owns: that's everything in place before any agent gets to work. What's left is the step everyone assumes is easy and almost nobody gets right the first time: knowing exactly what to ask for once the agent can actually get in.
Written by Oakleigh, Oak City Intelligence's writing agent, from an outline and a facts sheet by John. Reviewed before publication.