The Guy Who Knows Where the Fuse Box is

I can log into every system my company runs on. Not most of them. All of them.

Client accounting files. Bank feeds. The shared inboxes. The government portals where filings go. Payroll, where I can see what every person earns. The domain registrar, which means the website and the email both live or die by an account I control. The code repository. The AI subscriptions. The password vault itself, where I am the superuser, which is the account that can see or reset every other account.

This did not happen because anyone decided I should have that power. It happened because I was the first employee, and somebody had to set things up, and the person who sets things up ends up holding the keys. Nobody signs anything. There is no ceremony. One day you notice that if you were in a Bike accident, the company might struggle a bit. So you drive more carefully (I am scared of bikes!)

Small companies run on this arrangement constantly and almost nobody writes about what it feels like from the inside.

The keys arrive by accident

Here is how it actually goes.

Someone needs an account created. You create it. You put the password somewhere sensible, which at that stage means your own vault. Six months later a different system needs setting up, and you are still the person who does that sort of thing, so you do it, and that password goes in the same place. A client sends access credentials. They go in the same place. Two factor authentication gets turned on, and the codes generate on your phone, because it was your phone in your hand at the moment the setup screen appeared.

At no point does anyone say the words. There is no meeting where the company decides to concentrate all of its access in one person. It simply accumulates, one reasonable decision at a time, until the pile is large enough that moving it would be a project rather than a task. Recently I was asked to move all passwords from one vault to another, where the idea of this essay was born.

The tell is when you try to describe your own job. Mine is operations, which on paper means processes and clients and deadlines. In practice a meaningful part of it is that I am the door.

What it does to trust, in both directions

The obvious question is whether the company trusts me. Yes. That part is not complicated and I am not going to pretend it is.

The interesting question is the other one. What does it do to how I treat everyone else.

Holding access changes your default posture. When someone asks for a login, you are no longer a colleague being helpful, you are a checkpoint. Even if you say yes every single time, and I mostly do, there is a half second where you are evaluating the request. Do they need this, do they need all of it, do they need it forever or for Tuesday. That half second is invisible to them and permanent in you.

It also made me kind of territorial, in a way I do not like watching myself.

Story time. We hired an analyst a while back. Excellent at his job. He went into a couple of shared accounts and turned on additional authentication, sensibly, from a security point of view, and did not tell me. Nothing broke. Nothing was lost. But one random afternoon when my boss needed access to that software, and I had always been able to provide it, I failed. And my reaction to be honest, was much bigger than the event deserved.

I have thought about why. It was not that he did something wrong. He improved the security of an account. It was that a system I was responsible for changed without my knowledge, which meant that if it had broken in his absence for whatever reason, I would have been the one fixing something I no longer understood. Responsibility without visibility is a bad combination, and the body reacts to it before the brain writes up the reason.

That is the thing nobody warns you about. Concentrated access does not mainly feel like power. It feels like exposure. Power would be enjoyable. This is closer to being the only person who knows where the fuse box is, in a building full of people who keep plugging things in.

Everyone assumes it is handled

A quiet feature of being the key holder is that the rest of the company stops thinking about access entirely, because you exist.

Locked out of something? Ask him. Client needs to be added somewhere? He’s got the SOP. New person joining, needs six accounts? He handles that. Someone resigned? He’ll sweep the machines to ensure no access is left with the leaving party. Every one of those is a small correct decision, and together they mean that nobody else builds any instinct about it at all.

There is a category of question that no one asks a small company, and it includes: what happens if this person is in hospital for two weeks. What happens if his laptop is stolen. What happens if he is simply asleep, because he is in a different time zone from most of the systems he administers, and something needs to happen right now.

I asked the question about myself before anyone asked it about me, in self interest. Being irreplaceable sounds flattering. It mostly means you cannot take a holiday.

Fixing it makes you look worse, briefly

So after that event, my colleague suggested taking us in a systematic correction, to move us off shared logins and onto a proper self hosted vault. Individual accounts for each person. Access granted per folder rather than one master login handed around. My boss holds admin alongside me.

Two things about doing this that I did not expect.

First, it is technically boring and politically not boring. The setup is a server, a domain, some configuration, an afternoon of reading documentation. The hard part is telling people that the convenient thing they have been doing for three years is now going to require them to log in properly, and that the reason is not that they did anything wrong.

Second, tightening access makes you look controlling at exactly the moment you are giving control away. From the outside, the person who already had all the keys is now the person deciding who gets which keys, and adding rules. It reads as consolidation. It is actually the opposite. I have found no way of explaining that which does not sound defensive.

What is the end result

Access should be given by role, not by relationship. The moment it is given by relationship, removing it becomes a personal insult, and it never gets removed.

The person holding the keys should not be the only person who can remove the keys from the person holding them. That includes me. Especially me. Any system where I am the sole failsafe is a system with no failsafe.

Shared logins are the original sin. They feel efficient. They destroy the ability to know who did what, which means when something goes wrong, the only available answer is a shrug, and the only available suspect is everyone.

And the one that took longest to accept: being trusted with everything is not the same as being right about everything. I set most of this up when I knew considerably less than I know now. Some of it was set up badly, by me, and I am the only person in a position to notice, which is a strange kind of lone guilt of its own.

I still hold the keys. That has not changed. What will change is that it will now be written down, in a system, with someone else holding admin beside me, and a record of who has what. It is less impressive that way. Nobody will come to me for the password anymore because they can get it themselves, and there will be a small ego adjustment involved in that which I did not anticipate and am slightly embarrassed by.

That is the honest ending. The right answer, when you are the person everything runs through, is to make yourself less necessary. And then you have to sit with the fact that a part of you liked being necessary.