Salta al contenuto principale

Practical guide

Emergency access when the manager is unavailable

A sudden absence of the manager, due to illness or incapacity, must not bring the management of the condominiums to a halt. If the credentials to the management system, bank account and archives live only in one person's head, an unexpected event turns a temporary problem into a paralysis. Setting up emergency access means ensuring that, when needed, an authorized person can operate without forcing anything, but with controls that preserve security. This guide explains how to organize delegations, credential custody and traceability, holding together service continuity and the confidentiality of the owners' personal data.

Checklist for emergency access

  1. Map the critical access points: management system, bank account, certified email, document archive
  2. Identify at least one trusted person authorized to step in
  3. Store credentials in a password manager, not on sheets or clear-text files
  4. Define in writing when and how emergency access is activated
  5. Assign differentiated roles and permissions, avoiding unnecessary full access
  6. Enable two-factor authentication with a recovery method shared securely
  7. Record every emergency access: who, when and why
  8. Periodically review authorizations and credentials, revoking what is no longer needed

The risk of a single point of access

Many firms, especially those run by a single professional, concentrate all access in one person. The management system password, the online banking of the condominium account, the certified email box and the archive are reachable only by them. As long as all goes well the setup holds, but a sudden illness or a prolonged incapacity blocks payments, deadlines and communications for dozens of condominiums.

The risk does not concern only extreme emergencies. Even a holiday, a short hospital stay or a technical problem with the device running the authentication can leave the firm without access to its own tools. Planning an emergency path is a continuity measure, not a luxury.

How to store credentials securely

Emergency access must not become a security hole. Writing passwords on a sheet in a drawer or in a text file on the computer is as dangerous as planning nothing at all. The correct tool is a password manager, which keeps credentials encrypted and lets you share them in a controlled way with a trusted person.

Two-factor authentication, now indispensable for accounts and management systems, requires extra care: the second factor must be recoverable by the authorized person too, for example with recovery codes stored securely. Without this precaution, the protection that defends against attacks ends up blocking legitimate emergency access as well.

  • Encrypted password manager instead of sheets and clear-text files
  • Controlled sharing of credentials with the authorized person
  • Two-step verification recovery codes stored securely
  • No password sent via email or unprotected messages

Roles, permissions and the least-privilege principle

Emergency access does not mean total access. A good management system lets you assign differentiated roles and permissions, so a collaborator can handle what is needed without necessarily having control over everything. The principle is to give each person the minimum needed to do their task, reducing the risk surface.

This approach also protects the owners' personal data, which Regulation EU 2016/679 requires to be protected by limiting access to those who genuinely need it. Broad access granted for convenience and never revoked is one of the most common causes of data exposure.

Traceability and revocation of access

Every emergency access must be traced: who entered, when and why. Traceability is not mistrust but protection for everyone, because it allows reconstructing who did what and demonstrating the correctness of the actions taken in case of a dispute.

Access must be reviewed over time. Authorizations granted to a collaborator who has left the firm, or activated for a single emergency now over, must be revoked. A periodic review of users and credentials keeps the system clean and reduces the number of open doors onto the condominium's data.

Managing roles and access with AmministraPro

AmministraPro lets you assign roles and permissions to the firm's members and protect accounts with two-factor authentication, so an authorized collaborator can step in when needed, operating only on what falls within their remit. The traceability of operations helps reconstruct every access.

The user management and security features are described on the /funzioni page, while the plans for teams of different sizes are compared on the /prezzi page.

Frequently asked questions

How do I avoid blocking the owners if I suddenly fall ill?

Set up emergency access in advance: identify a trusted authorized person, store credentials in a password manager that can be shared securely, and make the second authentication factor recoverable. This way, when needed, the handling of payments, deadlines and communications continues without forcing anything.

Where do I store the passwords for an emergency?

In a password manager, which keeps them encrypted and lets you share them in a controlled way with an authorized person. Avoid sheets in a drawer, text files on the computer or sending them via email and unprotected messages: convenient but insecure, they also expose the owners' personal data.

Should the emergency person have access to everything?

No. The least-privilege principle applies: assign differentiated roles and permissions, so the authorized person handles only what is needed. This reduces the risk and respects Regulation EU 2016/679, which requires limiting access to personal data to those who genuinely need it.

Is it necessary to trace emergency access?

Yes. Recording who entered, when and why protects everyone: it allows reconstructing operations and demonstrating the correctness of the actions taken in case of a dispute. Traceability should be paired with a periodic review that revokes authorizations no longer needed.

Try AmministraPro

Accounting, thousandths-based cost splitting, meetings, communications and artificial intelligence in a single Italian software, compliant with UNI 10801 and GDPR.