Knowledge base Β· Security

How do you work securely with a virtual assistant?

Outsourcing almost never falls down on the tasks themselves, but on the question of how you give someone access without handing over your passwords. That is very solvable: a password manager, a separate account per person with limited permissions, and clear agreements recorded before anyone logs in.

The short answer

You never hand over loose passwords. Access runs through a shared vault in a password manager and through a separate account per person, with only the permissions the work needs and two-factor authentication switched on. You record what applies to personal data in a data processing agreement, and when the work ends you withdraw everything.

When you hand over work for the first time, it rarely goes wrong on the tasks themselves. The sticking point is access. You have to let someone into your mailbox, your website or your bookkeeping, and that feels uncomfortable. That reaction makes sense. Below I set out how I arrange it in practice, so you know what to expect and what you are entitled to ask for.

How do you share access without giving out your passwords?

By never making the password itself the thing you send. A password you put in a chat message or an email is still sitting there years later. You no longer know who read it, whether it was copied, or where else it ended up. So this is how I work:

  • A shared vault in a password manager. 1Password or Bitwarden, for example. You put the login details in a separate vault and share only that vault. Want to stop? Remove the vault and the access is gone straight away.
  • A separate account rather than a shared password. Almost every system lets you add a second user. The log then shows who did what, and you do not have to change your own password when someone leaves.
  • Two-factor authentication switched on. On your email, your hosting and your webshop that is the bare minimum. On your assistant's account too.
  • Never by email or chat. Not even quickly, and not with the promise that you will delete the message afterwards.

In practice the vault is the dullest and easiest answer. You have nothing to remember, you can see in one overview who can reach what, and you can undo it whenever you like.

Which permissions do you grant and which do you not?

The starting point is simple: only the permissions the work genuinely needs, and nothing on top. This has little to do with distrust. The fewer doors that stand open, the smaller the chance that something breaks by accident, and the easier it is to see later what actually happened.

SystemWhat accessWhy this way
WordPressEditor role, not AdministratorPublishing and updating pages needs no access to users, plugins or the database.
Google Workspace or Microsoft 365Delegated access or a shared mailboxThe account stays yours and you can remove the delegation again in a minute.
BookkeepingA separate user with a limited role, no payment rightsPreparing invoices is a different job from approving payments.
WebshopShop manager account, no payment settingsHandling orders and customer questions does not require the keys to your payouts.
Social mediaAccess through the business page or business managerYour personal profile stays yours, and access is withdrawn per person.
PasswordsShared vault in the password managerOne place to grant access, one place to take it away again.
A workable baseline. The exact roles depend on your systems and on what you outsource.

With WordPress I still often see everyone made an Administrator, simply because that is quickest. For publishing posts or updating a page, the Editor role is plenty. If I do need more once, to update a plugin for instance, I ask for it and you set it back afterwards.

What does the GDPR say when you outsource work?

As soon as someone processes personal data on your behalf, think of customer names in your inbox or addresses in your webshop, you are in GDPR territory. In most cases you are the controller and the virtual assistant acts as processor: on your instructions and within the limits you set.

The instrument for that is a data processing agreement. It records which data is processed, for what purpose, for how long, which security measures apply and what happens if something goes wrong. Alongside it you agree on confidentiality and on where the data is kept. I work in your own environment as much as possible and with providers that store data inside the EU, because that keeps the question of international transfers a lot simpler.

I am not a lawyer and this is not legal advice. If you handle sensitive data, medical or financial for example, have your agreement checked by someone who is qualified for it. How I handle data myself is set out in my privacy statement.

What do you agree on up front?

Most trouble comes from vagueness rather than bad intent. So I put these points on paper at the start, even for small assignments.

  1. Which systems and which role. One line per system: who gets access, and with which permissions.
  2. What may and may not be done independently. Answering customer questions, yes. Making payments or committing to contracts, no.
  3. Who else is allowed to look. If your assistant works with a team, agree that access is never passed on without checking with you first.
  4. What happens at the end. Switch off accounts, withdraw the vault, return or delete shared documents. Put a date next to it, so nobody has to improvise later.
  5. What you do after an incident. One simple rule, report it immediately, keeps a small problem from turning into a large one.

Still looking for someone? How to choose a virtual assistant walks you through the selection. If you would rather first work out which tasks suit this, have a look at which tasks you can outsource or at outsourcing email management, since the inbox is usually the first thing to move across. Unsure about your own situation? Ask me through contact.

FAQ

Frequently asked questions

Do I have to share my password with a virtual assistant?

No. In almost every system you can create a separate user or delegate access without handing over your password. If that genuinely is not possible somewhere, share the login details through a shared vault in a password manager. Nothing then sits in an email, and you can withdraw the access at any moment.

Do I need a data processing agreement?

If your assistant processes personal data on your instructions, customer contact or orders for instance, a data processing agreement is the usual instrument under the GDPR. In that situation you are normally the controller and the assistant is the processor. If you are unsure about your own case, have the agreement reviewed by a lawyer.

What happens to the access when the work ends?

You withdraw it, ideally on the last working day. That means switching off or deleting user accounts, stopping the shared vault, revoking shared documents and folders, and refreshing passwords where needed. Agree those steps at the start and the ending becomes a matter of ticking boxes.

Where is my data kept?

That is a question you should ask up front, and the answer should be concrete. I work in your own environment as much as possible, so in your mailbox, your drive and your systems, and with providers that store data inside the EU. That way the data stays yours and it stays clear where it lives.

Your Virtual Assistant.eu

Want to set this up properly from day one?

Book a no obligation intro call. We go through which access is genuinely needed and what we record before anyone looks into your systems.

Book an intro call