codexier.

Business Operations

Giving an Assistant Access Without Handing Over the Keys

By CodexierPublished 5 min read

The fastest way to get an assistant started is to send them your email password and BankID-protected logins, and it is also the worst. Shared passwords cannot be limited, cannot be traced to a person and cannot be taken back without changing them everywhere. Almost every system a small Swedish company uses has a better way: delegated access, separate user accounts with limited rights, or a password manager that shares a login without revealing it. This guide shows how to set that up and how to close it down cleanly when the assignment ends.

Delegated access instead of shared passwords

SystemSafe way to give accessWhat to avoid
Gmail / Google WorkspaceMail delegation, or a separate user with access to a shared inboxYour password plus a copied 2FA code
Outlook / Microsoft 365Delegate or send-on-behalf permissions, shared mailboxesLogging in as you
CalendarShare with edit rights, or delegateA shared login for the whole account
Fortnox or VismaAn own user with the modules and rights the task needsUsing the owner's admin account
BankAn own user who can register payments but not sign themSharing BankID or a card reader
Skatteverket and BolagsverketRegister the assistant or firm as a representative with a limited mandateLogging in with your BankID on their behalf

Every own account leaves a trail of who did what, which protects the assistant as much as you.

Password managers and vaults

Some tools, such as a social media account, a supplier portal or an old webshop admin, do not support more than one user. For those, a business password manager with shared vaults is the safe option. You put the login in a vault for the assistant, they can use it to sign in, and you can revoke access in one click without changing the password. Many managers can also share without showing the password itself, and log when it is used.

  • Create one vault per assistant or per area, such as marketing tools or supplier portals.
  • Store two-factor codes in the manager, or add the assistant's own phone as a second factor where possible, not your personal phone.
  • Never send logins by email, SMS or chat, where they stay searchable for years.
  • Turn on two-factor authentication on the password manager itself; our guide to two-factor authentication covers how.

Least privilege per task

Start from the task list, not the system list. An assistant who books meetings needs your calendar and perhaps to send email on your behalf, not your whole inbox history. An assistant who handles supplier invoices needs to register them in the accounting system, not to change the chart of accounts or see payroll. Write down each task, the system it touches and the minimum right it needs, and grant exactly that. Our guide on letting someone run your calendar shows what this looks like for scheduling.

Read

Enough for most research, reporting and preparation tasks. Start here.

Prepare

Create drafts, register invoices, prepare payments and propose meetings, with you approving.

Act

Send on your behalf or complete tasks alone. Only for well-defined routines after trust is built.

Bank and payment limits

Money needs the tightest controls. Swedish business banks let you add users with different rights: someone who can register and prepare payments, and someone else who signs them with their own BankID. That split is the single most effective protection against both mistakes and invoice fraud, where a fake invoice or a changed bank account number arrives by email. If an assistant must pay small amounts on their own, give them a company card with a low limit rather than account access.

  1. The assistant registers payments; you or a second person sign them.
  2. Changes to a supplier's bank details are confirmed by phone to a known number before payment.
  3. A company card with a low monthly limit for small purchases, if needed.
  4. A monthly review of payments and card transactions.

Removing access at the end

Keep a simple access log from day one: which systems, which rights, granted when. When the assignment ends, go through the list, remove users and delegations, revoke vault access, cancel representative mandates at Skatteverket and Bolagsverket, and change any password that was ever shared outside the manager. Keeping the list current is what turns offboarding into a fifteen-minute job instead of a worry.

When you do not need an assistant for this: if a task requires full control of your bank or your personal identity, it is not a task to delegate. Our virtual assistant and admin support works with limited permissions and logged hours, and never controls client bank accounts; see pricing or book a call to go through which tasks and accesses make sense.

Frequently asked questions

Can the assistant use my BankID to log in for me?

No. BankID is your personal electronic identity, and letting someone else use it breaks the bank's terms and means they act legally as you. Use their own user accounts and representative mandates instead.

How does an assistant get access to Skatteverket's services?

The company can register a representative with a defined mandate through Skatteverket's e-services, such as for VAT or employer returns. The assistant then logs in with their own BankID and acts within that mandate.

Is a shared password manager secure enough?

A reputable business password manager with two-factor authentication is far safer than any other way of sharing logins. It encrypts the data, controls who sees what and lets you revoke access instantly.

Do we need an agreement with the assistant about data?

Yes. If the assistant handles personal data on your behalf, such as customer emails, a data processing agreement is required under GDPR, plus a confidentiality clause in the assignment.

Delegate admin without giving away control

List the tasks you want off your desk. In fifteen minutes we can go through which accesses each needs and how to set them up safely.

Book a free 15-minute call