Your best crew lead just gave notice. Two weeks, no drama, moving closer to family. You shake his hand, you mean it when you say good luck. Then Thursday night you are lying awake running through what he still has access to. The shared login for the scheduling app that every foreman uses. The QuickBooks credentials taped inside a truck's glove box compartment because somebody wrote them down years ago and nobody ever changed it. The payment processor account tied to his personal phone number for two-factor codes. The customer list on the shared drive. You built this business on trust, and trust is exactly why nobody ever set up individual logins in the first place.
This is not a hypothetical for home services companies. Crews share one login for the dispatch board because setting up separate accounts felt like a hassle nobody had time for. Estimating software gets one password that gets texted to whoever needs it that week. The payment terminal login was set up by a guy who left eighteen months ago and is technically still an admin on the account. None of this was negligence. It was just how the business grew, one text message and one shared password at a time, while everyone was busy actually running jobs.
Why this always slips through the cracks
The problem is not that owners do not care about security. It is that access control was never treated as part of onboarding or offboarding in the first place. When someone joins your crew, you hand them a login because it is faster than requesting a new seat. When they leave, the exit conversation covers the truck, the tools, maybe a final check. Nobody asks what apps that person could still open from their personal phone on the drive home. And because most of these tools bill per seat, shared logins also felt like they were saving you money, not creating a liability.
The fix is not complicated, but it does require treating logins the same way you treat keys to the shop. Every person gets their own, every departure includes a shutoff step, and nothing important lives on a shared password that outlives the people who knew it.
- Individual logins for every crew member on scheduling, invoicing, and payment tools, not one shared account passed around by text
- A written offboarding checklist that gets pulled out the day someone gives notice, not the day they walk out for the last time
- Two-factor authentication tied to a company device or number, not a departing employee's personal phone
- A single list of every system the business touches, so nobody is trying to remember what a former employee could still log into six months later
- A remote access setup where you can see and revoke logins from your phone whether you are behind the counter or three states away
None of this requires new software most of the time. It requires an hour of setup work and a checklist that gets used every single time someone leaves, not just when you remember. The businesses that get burned are not the ones without security software. They are the ones where the exit interview covers the truck and the tools but never gets to the seven different logins that person is still carrying around in their head.
Kolton Consulting sets up work-from-anywhere systems for home services companies on the Gulf Coast, which includes the boring but critical part nobody wants to deal with: individual logins, controlled remote access, and an offboarding process that actually shuts the door when someone leaves. You should be able to run this business the same whether you are on-site or on the road, without wondering at midnight what a former employee can still open.
A shared password is not a system. It is a liability waiting for someone to give notice.