SEO work often requires access to several client systems, and permissions can accumulate as projects evolve. A simple access register helps a small agency understand which accounts it uses, who owns them and what needs reviewing when staff or client relationships change.
Record systems, not passwords
The register should identify the platform, account context, agency user and access purpose without becoming a document full of shared credentials. Passwords and authentication secrets belong in appropriate secure systems, not general project notes.
Prefer identifiable user access
Where platforms support it, use named accounts and suitable permissions rather than sharing a client's primary login. Individual access is easier to review and remove and creates clearer responsibility when several people work on the account.
Note who owns each account
Distinguish client-owned properties from agency-managed tools and clarify who can grant or revoke access. Ownership uncertainty becomes particularly troublesome during staff changes, provider transitions or urgent technical work.
Review access when roles change
When an agency team member leaves a project or no longer needs a system, remove unnecessary permissions rather than waiting for a wider annual cleanup. The same principle applies when client contacts change.
Include access review in offboarding
A client handover should confirm that the client retains appropriate control of its accounts and that agency permissions are removed when responsibilities end. This prevents dormant access from surviving long after the working relationship.
Keep the register useful enough to maintain
Capture the fields needed to understand ownership, purpose and current access without turning the register into a complex asset-management system. A concise record that teams update consistently is more valuable than a detailed document that quickly becomes inaccurate.