Join our Newsletter — 33% off our NHI Course

How should people organise access to their digital accounts before they die?

The practical first step is to create a complete inventory of accounts, then document how each one can be accessed and what should happen to it. A strong plan also names a trusted digital executor, stores credentials securely, and keeps instructions updated as accounts change. The goal is to make administration possible without exposing the account holder’s privacy or creating unnecessary security risk.

What a practical pre-death account plan needs to cover

Organising digital accounts before death is mainly about reducing ambiguity. Every important account should be identified, classified by purpose, and paired with a clear instruction about whether it should be closed, memorialised, transferred, or left untouched. That planning matters because account providers often have strict access rules, and family members or executors cannot assume they will be able to act without prior authorisation or documentation.

The plan also needs to separate convenience from control. A password list alone is not enough if nobody knows which accounts contain financial records, business information, photos, or private correspondence. The same is true for shared devices and password managers: they can help with administration, but they also concentrate sensitive access and can become a problem if they are not governed carefully. For a practical overview of machine-readable access and identity lifecycle concerns, the OWASP Non-Human Identity Top 10 is useful where account access depends on stored credentials, tokens, or delegated access paths.

In practice, many families discover the real problem only after the account holder is incapacitated or deceased, when access decisions become harder to reverse and the evidence needed to act is no longer easy to assemble.

How to structure access, instructions, and custody

A useful structure starts with three layers: the account inventory, the access method, and the disposition instruction. The inventory should name the service, the purpose of the account, whether it is personal or work-related, and whether it contains sensitive content. The access method should explain how the account can be reached if needed, but not in a way that forces open exposure of credentials. The disposition instruction should state what the trusted person is meant to do, because “access” and “permission to act” are not the same thing.

That distinction matters most for accounts that mix personal privacy with legal or financial value. Email can unlock other services, cloud storage may contain documents that have estate value, and social accounts may need a different treatment from banking or investment services. If a platform offers a legacy contact, memorialisation, or account deletion process, the plan should reflect the provider’s own workflow rather than assuming a universal approach. Some services also require proof of death, executor authority, or court documents before they will release information.

  • Keep the inventory complete enough that a trustee can see what exists without having to guess.
  • Store sensitive access details separately from the instructions so the plan does not become a single point of compromise.
  • Use secure custody for credentials or recovery methods, especially where password resets, multi-factor authentication, or recovery email accounts are involved.
  • Review the plan whenever an account changes, a recovery method is updated, or a new service is added.

For organisations and families that want a control-oriented view of secure handling, NIST SP 800-53 Rev. 5 remains relevant where the issue is custodianship, access restriction, auditability, and controlled disclosure. Where the provider’s own legacy-access rules are the limiting factor, those terms govern the outcome more than any private instruction does.

This guidance breaks down when the account holder never documented recovery paths, when two-factor authentication is tied to a device no one else can unlock, or when service terms require a legal process that the family cannot bypass.

Common edge cases that change the plan

Tighter control often increases administration overhead, so families have to balance privacy, security, and ease of settlement rather than treat all accounts the same.

Some accounts should not be handled as if they were ordinary personal logins. Joint accounts, business accounts, and accounts tied to a fiduciary role may involve other owners, employers, or legal obligations. In those cases, the key question is not only “who can sign in?” but “who has the right to decide?” A photo library and a trading account may both be digital assets, but they do not carry the same access or retention expectations.

There is also a real tradeoff between centralising everything for convenience and avoiding a high-value document that exposes too much if it is stolen. A single file with all passwords, recovery answers, and instructions is efficient, but it becomes an attractive target and may also age badly if it is not updated. A more resilient approach usually separates the catalog from the sensitive access store, with clear fallback steps for the executor.

Where the provider offers official after-death tools, those should usually take precedence over informal workarounds. Where no such tool exists, the plan should focus on what can be proven, what can be authorised, and what should never be accessed at all. That is the point where good planning stops being about convenience and becomes a matter of legal and operational restraint.

Risk and Threat Considerations

The main risk is overexposure of accounts before they are needed. Pre-death planning often creates a concentrated store of credentials, recovery methods, and private instructions, which can expose financial accounts, email, cloud storage, and identity data if it is poorly protected. It also creates governance risk if the plan gives someone practical access without clear authority to act.

Failure mechanism: Risk materialises when credentials, recovery channels, or executor instructions are stored in a way that is easy to misuse, easy to lose, or too broad for the account’s sensitivity. Attackers and opportunistic insiders often target email and recovery paths because they can reset other accounts, while legitimate family users can also cause unintended disclosure if the custody arrangement is unclear.

Impact: The result can be account compromise, privacy breach, unauthorised transfers, loss of important records, or disputes over who was meant to see or close each account. In the estate context, weak access design can also delay administration because providers need proof, authority, or identity evidence that the plan did not preserve.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 PR.AC-1 — Identity and Credential Management Account access planning depends on controlled credentials and recovery paths.
Recommendation — Inventory and govern account credentials so access remains authorised and traceable.
CIS Controls v8 4 — Secure Configuration of Enterprise Assets and Software Protects stored account access methods and recovery settings from unsafe exposure.
5 — Account Management Directly addresses account ownership, lifecycle, and deprovisioning decisions.
Recommendation — Harden storage and recovery settings to reduce unauthorized account takeover risk. Document ownership and deprovision accounts according to the intended post-death action.
NIST SP 800-63 IAL2 — Identity Assurance Level 2 Provider proofing and authority checks often govern post-death access requests.
AAL2 — Authenticator Assurance Level 2 Recovery and MFA dependencies affect whether accounts remain reachable after death.
Recommendation — Match access requests to the assurance evidence providers require before disclosure. Preserve authenticators and recovery methods so designated access paths still work.

Practitioner Guidance

What to prioritise: Separate “what exists” from “how to get in.” A complete inventory is useful only if each account also has a disposition instruction, a sensitivity label, and a named owner for administration.

What to verify: Check whether the recovery method depends on a phone, email account, authenticator app, or device that would become inaccessible at the same time as the primary account. That dependency is often the hidden failure point.

Common mistake: Treating the plan as a password vault only. The more important decision is usually whether the trusted person is allowed to access, preserve, transfer, or delete the account after death.

What good looks like: A trustee can identify the account, understand the intended action, and produce the right proof or authority without needing to guess, improvise, or overreach.

Practitioner takeaway: The best plan is not the one that maximises access, but the one that makes the right action possible while keeping recovery paths narrow enough that the plan itself does not become a security liability.