In this guide
Strong sign-in protects a co-op only if the right people can still regain access when circumstances change. A volunteer replacing a phone, a secretary leaving office or an administrator being unavailable should not turn into an organisational lockout.
Plan authentication and recovery together. Start with the accounts that can control other accounts: primary email, the domain registrar, collaboration administration, password manager, hosting and backup administration. Use named identities wherever supported, with additional authorised administrators rather than one shared login.
Choose the strongest suitable supported method
The NCSC's 2026 guidance recommends passkeys where services support them, and two-step verification where they do not. Passkeys reduce exposure to credential phishing, but the devices and credential accounts that hold them still need protection.
Check how a particular service implements the available methods. A passkey may be stored on a device, on a hardware security key or synchronised through a credential manager. These arrangements have different consequences if a device is lost. An authenticator app, security key and SMS code are also different options, with different recovery and usability tradeoffs.
Choose a method people can actually use. If a member cannot use a personal smartphone for work, consider supported hardware keys or another appropriate option. Test the chosen method with their browser, device and accessibility needs before making it compulsory.
Record the recovery route without exposing secrets
For each important account, record the account owner, configured sign-in methods, spare method, recovery contact and location of protected recovery material. Store codes and keys securely, not in a general committee spreadsheet. Record when the recovery route was checked.
- Is a second authorised administrator available if the primary administrator is absent?
- Can a lost phone be replaced without access to that same phone?
- Does recovery depend on an email service that may also be unavailable?
- Who controls any account that synchronises passkeys?
- Can a former role holder still receive recovery messages?
- What evidence would the provider require if automated recovery fails?
An illustrative community co-op might give each administrator their own sign-in identity, configure a spare supported security key and keep its recovery instructions in a restricted continuity record. The spare key's physical location and access authority should be known to the appropriate people. It should not sit anonymously in a drawer.
Run a recovery rehearsal before you need it
- Choose a suitable test account or a low-risk service with a clearly documented recovery procedure.
- Confirm the existing working sign-in and keep it available while setting up alternatives.
- Register the spare method through the provider's legitimate settings.
- In a separate supported sign-in session, verify that the spare method works.
- Check where alerts go and whether an authorised person can understand them.
- Record the result and any remaining dependency.
Do not deliberately lock out the only administrator to make the rehearsal realistic. For a critical service, ask your support provider to help test the procedure without putting the live organisation at risk. Follow the service's current documentation, because available recovery steps can change.
After a phone replacement, verify the new method before removing the old one, then remove obsolete credentials when the transition is complete. The same discipline applies to lost hardware keys, departed administrators and old recovery addresses.
Treat unexpected prompts as a signal
Do not approve a sign-in request merely to make repeated notifications stop. Use a known route to inspect the account and contact your administrator. If you entered a password into a suspicious page or approved an unexpected request, report it promptly; account sessions and connected applications may also need review.
Keep recovery assistance accountable. A convincing caller claiming to be the new treasurer should not receive a reset because they know the co-op's name. Verify identity and authority through an established independent route.
Use the password-manager guide to organise remaining credentials and include recovery ownership in your digital handover. Start the review with the technology health check.