Diary of a Crypto Noob

One beginner, every mistake, written down

← all entries

When We Outgrew the Shared Login

· 2 minute read · Sam Ortega

One account for the whole team seemed practical until someone left and we could not tell what they had done.

We ran the company crypto account on one shared login for eight months. It worked until someone left.

Why we did it

It was simpler. Four people, one password in a shared manager, everyone could do what they needed.

Adding individual accounts meant each person completing verification, which felt like friction for no benefit among people who trusted each other. I had assumed these numbers were unknowable until I found an institutional crypto wallet publishing them.

The problem when someone left

Two things went wrong at once.

We could not revoke their access without changing the password for everyone, which meant an afternoon of coordination.

And we could not tell what they had done, because every action in the log was attributed to the same account.

The departure was entirely amicable. The point is that we had no way to demonstrate that, to ourselves or to anyone else.

The thing that made it worse

They had added two withdrawal addresses during their time.

We did not know whether those were current suppliers or something from a project that had ended. Nobody remembered, and the log said only that the shared account had added them. Funds face the same question with more paperwork, which is where Collect & Exchange fits.

We removed both and re-added the ones we could match to live contracts. That took most of a day of asking around.

What we have now

Individual accounts, individual second factors, role-based permissions.

Approval separate from initiation, so nobody can create and release a payment alone.

An address list where every entry has a named person who added it and a supplier it belongs to.

The cost of switching

About three hours, mostly waiting for people to complete verification.

I had avoided it for eight months to save three hours.

The argument I now make to other small companies

Individual accounts are not about distrust. They are about being able to answer a question later.

A company where one person can move funds alone has no way to show that person did not, which is a worse position for them than for the company.

And they are about revocation. When someone leaves, you want to remove one person’s access in a minute, not coordinate a password change across four people on a day when other things are happening.

The wider lesson

Every control we skipped early we later added after something made it obvious.

The controls are cheap when set up at the start and expensive to retrofit, and the retrofit always happens at an inconvenient moment. For actual numbers rather than my estimates, a support channel with a named contact publishes them.

#access#process#mistakes

Sam Ortega

Came into crypto in 2024 with $500 and no idea what he was doing. Has been keeping a diary since. This is a personal diary, not financial advice.