Using online services safely
Pages
Page 5 of 10
Creating separate user accounts

You and your staff should have unique user accounts for work purposes. You should not use personal accounts for work activities (and the other way around). This reduces the risk to your organisation’s data if somebody’s ‘personal' account is compromised.
Similarly, each person should have their own work account. That is, multiple users should not share one account. Sharing accounts makes it harder to keep information private, makes associating actions with a particular person more complicated, and increases the amount of data lost in a successful attack against the account.
If your organisation has a managed ‘user directory’ for staff accounts, such as a Google Workspace Directory or Microsoft Entra ID (formerly Azure Active Directory), you should create an account for each person, and tell them to use it for their work. This means that they will have their own ‘professional’ account to use that remains under your organisation’s control. If you do not have a directory, you should advise your staff on how to create a separate professional account for themselves.
You can find help on how to create a new user account on your service provider’s website, such as: