Account security is accountable at both the individual and organisational level. The public figure owns the risk of authentication strength and recovery controls, while staff and IT teams must govern delegated access, device hygiene, and role separation. Shared access should be documented, reviewed, and limited to what each person genuinely needs to do their job.
Why This Matters for Security Teams
Shared social media access is not a simple “who has the password” issue. It is a governance problem that mixes identity assurance, recovery control, device trust, and posting authority. Politicians and their staff often operate under time pressure, which makes informal sharing tempting, but informal access tends to blur accountability when an account is hijacked, a post is disputed, or a recovery channel is compromised.
That matters because the real control points are not limited to login. Security teams must know who can approve authentication changes, who can recover the account, who can post on behalf of the public figure, and how access is removed when staff rotate or leave. NIST SP 800-53 Rev 5 security controls are useful here because they force teams to treat access governance, auditability, and account lifecycle as separate responsibilities, not one shared bucket. The same principle shows up in the Ultimate Guide to NHIs, where weak lifecycle control and excessive access are recurring failure modes across identities.
In practice, many security teams encounter account abuse only after a public post, credential reset, or staff departure has already created the incident.
How It Works in Practice
The accountable model is layered. The politician or public officeholder usually owns the primary account relationship, meaning the strongest authentication method, recovery email or phone, and final approval for sensitive changes should stay under their control or under a clearly documented executive process. Staff do not “own” the account just because they operate it day to day. Instead, they receive delegated authority for defined tasks such as drafting posts, scheduling content, monitoring replies, or escalating suspicious activity.
Good practice separates those permissions. Shared credentials should be avoided where the platform supports role-based access, business manager controls, or delegated publishing workflows. Where that is not possible, access should be tracked as an exception, time-bound, and reviewed. This is consistent with the accountability model in the OWASP Non-Human Identity Top 10, which emphasizes least privilege, secret handling, and lifecycle control for non-human access paths. Even though a social account is human-facing, the operational pattern is similar: multiple actors may use one identity surface, so the control plane must record who did what, from where, and under which approval.
- Use role separation for drafting, approval, publishing, and recovery actions.
- Require phishing-resistant MFA on the primary account and on recovery channels.
- Use separate work devices or managed profiles for staff access.
- Log all delegated access, especially login events, content changes, and password or recovery updates.
- Remove access immediately when staff change roles or leave.
The most practical governance rule is simple: the account owner controls authentication and recovery, while the organisation controls delegated operation and oversight. The 52 NHI Breaches Analysis shows that weak ownership and poor lifecycle discipline repeatedly turn routine access into material exposure. These controls tend to break down in fast-moving campaigns and crisis communications, because multiple people need rapid posting rights but no one wants to pause long enough to assign clear authority.
Common Variations and Edge Cases
Tighter access controls often increase operational friction, so organisations have to balance speed against assurance. That tradeoff is real in politics, where message timing matters and teams may work across nights, events, and emergencies. The answer is not to give everyone the password. It is to define which functions can be delegated, which must remain with the principal, and which require dual approval or step-up verification.
Best practice is evolving for platforms that support multi-user business access, but there is no universal standard yet for how political offices should document shared social media authority. Some offices need a comms director to approve content while a digital staffer publishes it. Others need external agencies or volunteers to prepare drafts without any posting rights. In each case, the accountable party should be explicit in policy, and the access path should match that policy.
This issue becomes more dangerous when recovery channels are personal, staff use unmanaged devices, or outside contractors have access to connected apps and analytics tools. The State of Non-Human Identity Security reports that 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, which is a strong reminder that delegated access often expands beyond the obvious login. Current guidance suggests treating the account, the connected tools, and the recovery channels as one security boundary, not separate problems.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10, OWASP Agentic AI Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-1 | Addresses identity proofing and access authorization for shared account use. |
| NIST SP 800-63 | Relevant to strong authentication and account recovery assurance for public-facing identities. | |
| OWASP Non-Human Identity Top 10 | NHI-01 | Shared account access creates lifecycle and ownership risks similar to other non-human access paths. |
| OWASP Agentic AI Top 10 | A1 | Delegated publishing workflows behave like tool-using agents with bounded authority. |
| CSA MAESTRO | Shared social access needs policy, separation, and monitoring across operational roles. |
Document who may approve, use, and recover shared accounts, then review those permissions regularly.
Related resources from NHI Mgmt Group
- How should security teams manage shared social media account access without relying on password sharing?
- Who should be accountable for reviewing access to social media accounts and suspicious account activity?
- Who is accountable when physical access decisions do not match HR status or security policy?
- How should security teams run access reviews for non-human identities?