Guide · Blog

Digital Asset Management: Don't Lose Access When Staff Leave

One of the public-sector bodies we work with runs a highly active TikTok account. The staff member who managed this account recently moved on to a new job. After she left, the communications team tried logging in with the usual email and password. The platform blocked their access immediately. It redirected them to a new security prompt. The system demanded a passkey to verify their identity. Nobody in the office had any idea what a passkey was. They were completely locked out of their own official channel.

What is a passkey and why does it change everything?

This new technology was built to replace the traditional password. Instead of remembering a string of letters and numbers, your device confirms your identity. A passkey is saved physically inside the device. It never sits on your office servers. The implications for public organisations are massive.

When a mobile phone leaves your building, the digital key leaves with it. This completely changes how we must manage account permissions. In the past, login problems were just an IT issue. Now, a passkey is essentially a hardware problem. It has forced its way into the communications department. If your account gets locked tomorrow morning, you cannot publish urgent updates. You will have to explain to your director why the emergency post is missing.

Therefore, the responsibility for managing access falls entirely on you. You must map all authorised devices in your department right now. This simple action will save you hours of deep frustration.

What to do now: Open the security settings in your main social media account. Check exactly which devices are listed as authorised. Remove any devices belonging to former employees immediately.

How to give employees access without losing control

Stop sharing generic passwords across the whole communications team. Instead, you must assign permissions based on individual roles. When a public body hands the master password to a junior staffer, it creates massive risk. This action completely breaks two-factor authentication.

Two-factor authentication requires both a password and a phone code. If everyone shares the exact same password and code, your security is broken. The organisation has no reliable way to revoke access when someone leaves. Every social media account must have a named corporate owner. This owner should be a permanent, senior employee. You must document the purpose of the account and its exact access model.

Agencies providing social media management must help clients navigate this complex new reality. We always separate the access given to different types of users. We define who manages the accounts and who merely uploads content.

This strict separation of powers keeps your digital assets safe. An employee answering citizen complaints does not need permission to delete the entire account. A media buyer running ads does not need to change the master login details. Distributing limited permissions is your very first line of defense.

What to do now: Define one primary administrator for each digital asset. Ensure the rest of the team receives only the specific permissions they need through their personal user accounts.

When is the right time to disconnect a departing employee?

Teams often deal with access rights only after the employee's farewell party. Professional offboarding protocols establish a very different rule. You must transfer ownership of all digital assets before disconnecting the employee. Once the IT department deletes the employee's official email address, you lose a critical communication channel.

Anyone without access to the registered email or phone number is in serious trouble. Disconnecting contact methods early is a guaranteed recipe for losing public assets.

When we guide government bodies through digital transitions, we often replace existing vendors. We conduct a thorough technical handover with the outgoing agency. This handover must happen before the old vendor receives their final payment. Their phone must be on and available to receive any necessary verification codes. We only approve the final disconnection after verifying the new manager has full access.

Ideally, full control should never rest in the hands of an external vendor. The public body must retain absolute ownership. We have seen too many digital assets trapped under a vendor's control. This is a complete disaster for public transparency.

What to do now: Add a mandatory clause to your official offboarding checklist. This clause must require a digital ownership transfer in the presence of a senior manager.

The checklist: Twenty minutes that save your assets

We have prepared a simple checklist that requires only twenty minutes of your time. For municipalities and public authorities, these twenty minutes are worth their weight in gold. They will prevent severe public embarrassment and a sudden loss of contact with citizens.

  • Recovery email check: Verify that the registered email is a generic departmental address.
  • Phone number verification: Check exactly which number receives the login verification code. This must be a physical device located securely inside the office.
  • Review connected devices: Find the security menu in your app settings. Disconnect any phone, tablet, or computer that you do not immediately recognise.
  • Remove old passkeys: Delete any passkeys linked to the devices of former staff members.
  • Backup emergency codes: Social networks provide static backup codes for severe emergencies. Download these codes immediately and save them in a highly secure folder.

What to do now: Open your calendar and schedule a thirty-minute meeting with yourself tomorrow morning. Go through this exact list for your most important digital asset.

What happens if you are already locked out?

Sometimes we discover the access problem when it is already far too late. The employee has left, their phone was wiped, and there is no password reset option. You must open an official ticket and prepare for a very long bureaucratic process. Your sole objective is to prove the account legally belongs to your public organisation.

For this appeal to succeed, you must provide hard evidence to the support team. You should attach the exact date the account was originally created. Add any previous passwords you have used in the past. You must also state exactly when the last successful activity took place. These specific details are absolutely critical.

If you ran paid media campaigns through this account, attach the official receipts. Advertising invoices bearing your organisation's name serve as excellent proof of ownership. Social media platforms also tend to take paying advertisers much more seriously.

What to do now: Gather the setup data for all your current accounts today. Save this information alongside at least one advertising invoice in a secure file.

Want to grow your organisation's digital presence?

Mashrokit Digital works with government bodies, municipalities and large nonprofits. Let's talk.

Talk to us