Organisations should give each guardian an independent identity and assign them equal permissions within the same family context. That approach avoids password sharing, lets one guardian lose access without affecting another, and keeps each action tied to the correct person. It also supports cases such as co-parents, dual custody, and other scenarios where the same dependent must be managed by more than one adult.
How should access be structured when more than one guardian manages the same dependent?
The right model is separate access per adult, not shared credentials. Each guardian should have their own identity, their own authentication, and the same permissions inside the dependent’s family context. That preserves accountability, supports independent offboarding, and lets organisations revoke one adult’s access without interrupting the other’s legitimate access.
Why separate guardian identities matter for access control and accountability
Shared logins blur who acted, who approved, and who should be contacted when access changes. Separate identities keep audit trails clean and make it possible to assign the same rights to multiple guardians without collapsing them into one account. That is especially important when the dependency is operationally sensitive, such as healthcare, schooling, travel, or custody-related admin.
It also prevents the common failure mode where one password reset, MFA reset, or account compromise unintentionally locks out both guardians. Privileged Access Management Guide is useful here because the core design principle is the same: access should be individually owned, individually reviewable, and individually revocable.
How to model the family context without creating unnecessary privilege
The family relationship should determine entitlement, not the login itself. In practice, that means each guardian can be granted equal permissions for the same dependent, while the system still records them as distinct actors. If the organisation supports roles, use a shared guardian role with per-person assignment rather than a common account shared by the household.
This approach also scales better when family arrangements change. A co-parent may need continuous access, while a temporary caregiver may need time-bounded access. A strong access model lets those cases differ without changing the underlying identity design. Break-Glass and Emergency Access Account Guide reinforces the same principle for exceptional access: emergency or alternate access should remain distinct from normal named access.
What good operational practice looks like when guardians change
Each guardian should be able to authenticate on their own, recover their own account, and lose access independently if a court order, family change, or administrative update requires it. That is the practical test of whether the design really supports multiple guardians. If one adult’s access can only be removed by changing everyone’s credentials, the model is too weak.
For platforms that already rely on role and privilege governance, the access pattern should align with least privilege and clear ownership. CIS Controls v8 and NIST SP 800-53 Rev 5 Security and Privacy Controls both support this style of individually assigned access, reviewable permissions, and traceable administrative action.
Risk and Threat Considerations
Shared guardian access creates avoidable exposure: it weakens accountability, makes revocation imprecise, and increases the chance that one compromised password exposes the full family relationship. It also creates operational risk when access changes, because organisations cannot reliably remove one adult without disrupting the other.
Failure mechanism: A single shared credential, token, or recovery path is used by multiple adults, so authentication events, password resets, and revocations apply to the household account rather than the person. That breaks attribution and can leave access either overbroad or brittle.
Impact: Organisations lose audit clarity, cannot cleanly separate legitimate access from disputed or revoked access, and may expose dependent records or actions to unnecessary risk. A shared account can also become a persistence path if one guardian’s device or password is compromised.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-2 — Identification and Authentication (Organizational Users) | Multiple guardians need individual named authentication to preserve accountability. |
| AC-2 — Account Management | The question is about creating, maintaining, and revoking access for more than one adult. | |
| Recommendation — Assign each guardian a separate authenticated identity and avoid shared accounts. Provision and remove each guardian’s access independently. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Separate guardian access is an access-control design choice with distinct permissions and revocation needs. |
| A.5.16 — Identity management | The scenario requires distinct identities for adults who share the same dependent context. | |
| Recommendation — Define per-person access rules for each guardian role. Maintain unique identities for each guardian and link them to the same family context. | ||
| CIS Controls v8 | CIS-5 — Account Management | Independent guardian access depends on managing accounts individually rather than sharing credentials. |
| Recommendation — Use separate accounts and disable them individually when access changes. | ||
Practitioner Guidance
What to verify: Confirm that the platform can assign equal permissions to multiple named adults without merging them into one credential set. The useful test is whether each guardian can be independently onboarded, reviewed, suspended, and removed.
Decision rule: If two adults are both expected to manage the same dependent, treat them as separate principals with the same role, not as one household user. If the process only works through password sharing, redesign it before rollout.
Practitioner takeaway: The strongest design is not “one account for the family”, it is one account per guardian with shared scope and independent control, because that preserves both convenience and accountability.
Related resources from NHI Mgmt Group
- When do NHI access reviews create more value than a one-time cleanup?
- What should organisations do when the same actor is using multiple stolen cards across one account or address?
- How should organisations control admin access when one account can manage other users' transactions through an API?
- How should security teams run access reviews for non-human identities?