A young agency owner posted a routine status video to YouTube — and broadcast his client’s website and Google Ads admin logins to the entire internet. An Access Checklist is the simple tool that keeps a mistake like that from ever locking you out of your own business.
Learn From a Leak That Went Public
Late one night, an agency owner recorded a weekly status update and shared his screen to show which access he had and still needed. He never noticed that the screen displayed the client’s admin credentials — website, Google Ads, and more — for anyone to grab.
Millions of bots crawl the web hunting for exactly that. Once they are in, the damage is real: credit card spending, ransom notes, spam posts, and backdoor malware that is painfully hard to find and remove. This owner got locked out entirely — and only got back in because one of our team rescued the site using the very credentials he had published.
Before you publish any screen recording, watch it back at full size and pause on every browser tab, dashboard, and settings panel. Blur or cut any frame that shows a login, an API key, or an account ID. One careless frame is all a bot needs.
Lock Down Every Point of Access
Think about how many plugins live on your site, how many systems your business touches, how many pixels are passing data, and how many people hold a key. Onboarding and offboarding contractors is normal, and each one carries a different level of access. The question is whether you are firmly in control of all of it.
In our site audits, we uncover backdoor spam about 20% of the time — usually traced to WordPress plugins that are out of date or no longer supported. The Access Checklist is the first of the 10 components of Digital Plumbing, and it maps every system, owner, and risk so nothing slips through the cracks.
| System to log | Who should hold access | Risk if it leaks |
|---|---|---|
| Website admin | Owner plus one trusted manager | Lockout, ransom, spam posts |
| Google Ads | Owner and the ad operator | Unauthorized credit card spending |
| Tracking pixels | Whoever manages analytics | Data passed to the wrong hands |
| Plugins | Reviewed and updated regularly | Backdoor malware (the 20% finding) |
| People with logins | Removed the day they leave | Lingering access after offboarding |
Open your client’s WordPress plugin list and sort by last update. Any plugin not updated in over a year, or marked no longer supported, is a prime backdoor — that is what drives the 20% spam rate we see in audits. Flag each one to update or replace before it becomes the way in.
Audit Your Own Access Today
Getting your Access Checklist locked down means you never have to worry about being exposed. List every system, name the person responsible, and remove anyone who no longer needs in. It is the unglamorous work that protects the calls, jobs, and revenue your site already generates.
Doing this well also signals that you run a tight, trustworthy operation — the same discipline behind how we demonstrate trust and authority with E-E-A-T. If you want a second set of eyes, a full Quick Audit checks your access, plumbing, and exposure in one pass.
We map every login, plugin, and pixel in your business so a single leaked screen can never lock you out.

