← all articles

How to secure seller accounts and offboard staff without losing access

This is the scenario that ends most seller-staff relationships badly: a VA or ops hire has your Shopee login memorised, the OTP for account recovery goes to her personal phone, and the day she resigns (or you let her go) you’re locked out of your own shop until support gets to your ticket. Nobody plans to lose an account this way.

This is for anyone selling on Shopee, Lazada or TikTok Shop in Southeast Asia who has more than one person touching the account, a VA doing chat replies, a packer with the seller centre open, a marketing hire running promos, and who is currently sharing one login across all of them because setting up anything more formal felt like a hassle at the time.

By the end of this, every login that matters has 2FA on it, staff work through scoped sub-accounts instead of your master password, and someone’s last day is a five minute checklist instead of a scramble to figure out what they still have access to.

what you need

  • a password manager with a shared or team vault. Bitwarden’s Teams plan runs about US$4 per user per month (as of September 2026, check bitwarden.com/pricing since it moves)
  • an authenticator app on a device the business controls, Google Authenticator or Authy both work fine
  • optionally a hardware key like a YubiKey 5 NFC, roughly US$55 as of September 2026, though I wouldn’t bother with this until you’re running a real operation
  • a company owned email mailbox for account recovery, something like [email protected], not a staff member’s personal gmail
  • a phone number and SIM registered to the business or a director, not a staff member’s personal line
  • admin access to whichever seller centre you run, Shopee, Lazada or TikTok Shop, to actually create the sub-accounts
  • a written offboarding checklist, a single Google Doc is enough to start

step by step

1. audit who actually has access right now

List every place a login currently lives. Check the staff list already inside your seller centre (Lazada calls it Staff Accounts under Account Info, Shopee has Shop Staff under Account Health, TikTok Shop has it under Shop Settings), then check WhatsApp threads, shared spreadsheets, and browser saved passwords on any shared laptop.

Expected output: a list that’s usually longer and messier than you expected.

If it breaks: if you genuinely can’t reconstruct every place a password was ever pasted, don’t try to be exhaustive. Rotate the master password once you’ve done what auditing you can (step 5), and everything not on your list stops working on its own.

2. move the recovery email off anyone’s personal inbox

Set up a role based mailbox the business owns, then go into each seller centre’s account settings and change the recovery or contact email to it.

Expected output: the platform sends a confirmation to the new address, you confirm it, and the old personal email stops receiving recovery codes.

If it breaks: some platforms require the old email to approve the change first. If that old email belongs to someone who’s already left, you’ll need to go through the platform’s identity verification flow, which can take a few days. Do this step long before anyone’s last day, not on it.

3. get the recovery phone number under the business’s name

This is the one people skip. If OTPs currently land on a staff member’s personal mobile, get a second SIM registered to the company or a director and set that as the recovery number instead.

Expected output: OTP texts land on a phone the business controls, not one that walks out the door with a resignation letter.

If it breaks: if your team is remote and nobody’s physically holding a company phone, this is exactly the gap a dedicated device closes. cloudf.one rents real Android phones on dedicated hardware in Singapore, each with its own persistent Singapore mobile IP, controlled from a browser, so the OTP and the login session both sit on hardware the business owns rather than in someone’s pocket. It’s Singapore only, so it fits if your shop’s registered market is Singapore or if a Singapore number is what the platform expects, not a general fix for every market.

4. turn on 2FA everywhere, with an app or key, not SMS alone

Enable two factor authentication on the seller centre login itself and on the recovery email account. Use an authenticator app or hardware key rather than relying on SMS as the only factor. Google’s own instructions for setting up 2-Step Verification are a fine starting point if your recovery email is Gmail, and NIST’s SP 800-63B guidance explains why SMS is treated as a weaker authenticator than an app or key. CISA’s own advice is blunter: turning on MFA is one of the single most effective things you can do against account takeover.

Expected output: logging in now asks for a second code from something the business controls, not just a password.

If it breaks: if a platform only offers SMS 2FA and won’t do app based codes, that’s a platform limitation, not something to route around. Just make sure the SMS number is the business owned one from step 3.

5. put every credential in a shared password manager

Create a shared vault and move every seller centre, email and courier portal login into it. Rotate anything currently sitting in a WhatsApp message or a spreadsheet.

Expected output: staff open an item in the vault to log in, they never see or memorise the actual password.

If it breaks: rotating a password that’s quietly tied to a webhook, an API key or an automation can break that integration silently. Check what’s connected before you rotate anything that isn’t purely a human login.

When you do need to rotate something manually, generate the replacement properly rather than typing something memorable:

openssl rand -base64 24

That gives you a random 24 character string. Paste it straight into the vault.

6. replace shared logins with staff sub-accounts

Instead of handing out the master password, create scoped accounts per staff member. We’ve written the click by click version for Lazada’s staff account setup if you want it in full, and Shopee and TikTok Shop both have equivalent role based systems in their own seller centres.

Expected output: each staff member logs in with their own credentials, scoped to what their role actually needs. Chat support doesn’t need access to your payout details, a packer doesn’t need access to promotions.

If it breaks: shops set up years ago on a single account with no sub-account structure at all take more care to migrate on a live shop. Do it during a quiet week, not the one before a mega sale.

7. write the last day checklist before you need it

Put together one page covering: disable the sub-account first, don’t delete it outright in case orders are mid fulfilment, remove them from the password manager’s shared vault, revoke any shared 2FA device, change the master password regardless of whether they only had a sub-account, and check any chat groups tied to the shop.

Expected output: on someone’s actual last day, offboarding is a checklist, not a scramble.

If it breaks: if you only remember to revoke access weeks after someone’s left, check the account activity or login history in the seller centre first. Most platforms log recent logins by device and rough location, so you can at least see whether the account was touched after they were gone.

This isn’t legal advice on termination or notice periods. Singapore’s Ministry of Manpower has guidelines on termination of employment if you need the actual rules for a contract, and the equivalent authority applies if you’re hiring outside Singapore.

8. run a dry run before you actually need it

Pick a low stakes sub-account and walk through disabling it for real. Confirm they’re locked out, confirm orders and chats aren’t disrupted, then re-enable it if it was only a test.

Expected output: you know the checklist actually works before your first real offboarding.

If it breaks: if disabling the account also breaks something you didn’t expect, an automation logged in under that account, say, better to find that out on a Tuesday afternoon test than on someone’s real last day.

I’ll be honest, none of this was in place for the first couple of years we ran our own shops. We got lucky rather than careful, and I wouldn’t recommend testing that particular luck twice.

common pitfalls

  • sharing one login across three or four staff over WhatsApp because sub-accounts felt like a hassle to set up. it’s the single biggest reason sellers end up locked out of accounts they can’t get back into.
  • using a staff member’s personal phone number as the account’s recovery number and never changing it, so when they leave, on good terms or not, they still technically control your recovery path.
  • disabling access weeks after someone’s actual last day because nobody owned the offboarding step. put a name against it, not “someone will handle it.”
  • reusing a departed staff member’s laptop or phone for the next hire without clearing saved sessions and stored browser passwords first.
  • spinning up a second shop under the same business to dodge a suspension or penalty. this violates the seller agreement on every platform I sell on, and it tends to get both shops suspended instead of saving the one that was struggling. if a shop’s actually in trouble, work through the platform’s real appeal process, and it helps to understand how Shopee’s penalty points work before you’re staring at a suspension notice rather than after.

scaling this

At small scale, one or two staff, low order volume, a shared vault and 2FA on the two or three logins that actually matter is enough. The risk here is that “informal” quietly turns into “doesn’t exist,” so write the checklist down even at this size.

At five to ten staff split across fulfilment, chat and marketing, role based sub-accounts stop being optional. You want exactly one person, usually the founder or ops lead, who’s the only one who ever knows the actual master password, and a quarterly habit of pulling the staff list in each seller centre to confirm everyone on it still works there.

Past that, multi-country or multi-shop operations mean managing this across markets and sometimes multiple legal entities, each with its own recovery email, phone number and staff list under that platform’s local seller agreement. At that point a quarterly access audit stops being a side task for whoever remembers and becomes an actual job for someone. A consistent login location, a dedicated device or a steady Singapore IP if that’s genuinely your registered market, matters less for convenience at this scale and more for avoiding the location or session flags that trigger extra verification on every login.

where to go next

The detailed sub-account walkthrough is how to give staff access in Lazada Seller Center. Security problems on these platforms tend to show up first as account health problems, so it’s worth reading how Shopee penalty points work before you need it rather than after. And if an offboarding hiccup disrupted your fulfilment team specifically, how to keep your Shopee days to ship rate healthy is worth a read to make sure nothing slipped while access was being sorted out. The rest of the how-to library is at /blog/.

Written by Xavier Fok

disclosure: this article may contain affiliate links. if you buy through them we may earn a commission at no extra cost to you. verdicts are independent of payouts. last reviewed by Xavier Fok on 2026-09-28.

free download
Multi-store setup checklist for Shopee, Lazada and TikTok Shop

What each platform allows for running more than one shop, and what to set up per store, as of September 2026. Leave your email and we will also tell you when we publish a new guide, a few times a month at most.

from the team behind this site
A dedicated real phone for each store you run

cloudf.one hosts real Android phones in Singapore, each on its own persistent Singapore mobile IP, and you open them from the browser. Useful if you run Singapore stores and want one phone per store or brand instead of a drawer of handsets.

see how cloudf.one works →
read on
More from the desk

Store operations, platform rules, fees and pricing for Shopee, Lazada and TikTok Shop sellers, with dates on anything that can change.

browse all articles →