Giving an Assistant Access Without Handing Over the Keys
By CodexierPublished 5 min read
The fastest way to get an assistant started is to send them your email password and BankID-protected logins, and it is also the worst. Shared passwords cannot be limited, cannot be traced to a person and cannot be taken back without changing them everywhere. Almost every system a small Swedish company uses has a better way: delegated access, separate user accounts with limited rights, or a password manager that shares a login without revealing it. This guide shows how to set that up and how to close it down cleanly when the assignment ends.
Delegated access instead of shared passwords
| System | Safe way to give access | What to avoid |
|---|---|---|
| Gmail / Google Workspace | Mail delegation, or a separate user with access to a shared inbox | Your password plus a copied 2FA code |
| Outlook / Microsoft 365 | Delegate or send-on-behalf permissions, shared mailboxes | Logging in as you |
| Calendar | Share with edit rights, or delegate | A shared login for the whole account |
| Fortnox or Visma | An own user with the modules and rights the task needs | Using the owner's admin account |
| Bank | An own user who can register payments but not sign them | Sharing BankID or a card reader |
| Skatteverket and Bolagsverket | Register the assistant or firm as a representative with a limited mandate | Logging in with your BankID on their behalf |
Every own account leaves a trail of who did what, which protects the assistant as much as you.
Password managers and vaults
Some tools, such as a social media account, a supplier portal or an old webshop admin, do not support more than one user. For those, a business password manager with shared vaults is the safe option. You put the login in a vault for the assistant, they can use it to sign in, and you can revoke access in one click without changing the password. Many managers can also share without showing the password itself, and log when it is used.
- Create one vault per assistant or per area, such as marketing tools or supplier portals.
- Store two-factor codes in the manager, or add the assistant's own phone as a second factor where possible, not your personal phone.
- Never send logins by email, SMS or chat, where they stay searchable for years.
- Turn on two-factor authentication on the password manager itself; our guide to two-factor authentication covers how.
Least privilege per task
Start from the task list, not the system list. An assistant who books meetings needs your calendar and perhaps to send email on your behalf, not your whole inbox history. An assistant who handles supplier invoices needs to register them in the accounting system, not to change the chart of accounts or see payroll. Write down each task, the system it touches and the minimum right it needs, and grant exactly that. Our guide on letting someone run your calendar shows what this looks like for scheduling.
Read
Enough for most research, reporting and preparation tasks. Start here.
Prepare
Create drafts, register invoices, prepare payments and propose meetings, with you approving.
Act
Send on your behalf or complete tasks alone. Only for well-defined routines after trust is built.
Bank and payment limits
Money needs the tightest controls. Swedish business banks let you add users with different rights: someone who can register and prepare payments, and someone else who signs them with their own BankID. That split is the single most effective protection against both mistakes and invoice fraud, where a fake invoice or a changed bank account number arrives by email. If an assistant must pay small amounts on their own, give them a company card with a low limit rather than account access.
- The assistant registers payments; you or a second person sign them.
- Changes to a supplier's bank details are confirmed by phone to a known number before payment.
- A company card with a low monthly limit for small purchases, if needed.
- A monthly review of payments and card transactions.
Removing access at the end
Keep a simple access log from day one: which systems, which rights, granted when. When the assignment ends, go through the list, remove users and delegations, revoke vault access, cancel representative mandates at Skatteverket and Bolagsverket, and change any password that was ever shared outside the manager. Keeping the list current is what turns offboarding into a fifteen-minute job instead of a worry.
When you do not need an assistant for this: if a task requires full control of your bank or your personal identity, it is not a task to delegate. Our virtual assistant and admin support works with limited permissions and logged hours, and never controls client bank accounts; see pricing or book a call to go through which tasks and accesses make sense.
Frequently asked questions
Can the assistant use my BankID to log in for me?
No. BankID is your personal electronic identity, and letting someone else use it breaks the bank's terms and means they act legally as you. Use their own user accounts and representative mandates instead.
How does an assistant get access to Skatteverket's services?
The company can register a representative with a defined mandate through Skatteverket's e-services, such as for VAT or employer returns. The assistant then logs in with their own BankID and acts within that mandate.
Is a shared password manager secure enough?
A reputable business password manager with two-factor authentication is far safer than any other way of sharing logins. It encrypts the data, controls who sees what and lets you revoke access instantly.
Do we need an agreement with the assistant about data?
Yes. If the assistant handles personal data on your behalf, such as customer emails, a data processing agreement is required under GDPR, plus a confidentiality clause in the assignment.
Delegate admin without giving away control
List the tasks you want off your desk. In fifteen minutes we can go through which accesses each needs and how to set them up safely.
Book a free 15-minute call