A practical review of who can enter returns, carrier and refund systems, with sensible controls for authentication, shared access and staff changes.
Treat returns access as an operational control
Returns work often crosses more systems than the main storefront suggests. A team may use an ecommerce administration area, a returns portal, carrier accounts, a shared support inbox and a payment or order-management tool during one case. Each login can expose customer details or allow someone to alter a return, issue a label or move a refund forward. An access review should therefore follow the whole returns journey, rather than stopping at the website account.
Start with a simple register of the services used from the first customer request to final reconciliation. Record the service owner, the people or roles with access, the level of permission granted, the authentication method and the route for recovering an account. Include integrations and automation accounts where they can change returns data. This is an operational inventory, not a reason to collect passwords or authentication codes in a spreadsheet.
Match permissions to the work people actually do
Compare each account with the person's current duties. A support colleague who only checks return status may not need permission to change carrier settings, export customer records or approve refunds. Warehouse staff may need to record receipt and condition without needing broader order administration. Where a service offers distinct roles, choose the narrowest role that still lets the person complete normal work without unsafe workarounds.
Pay particular attention to administrators, refund approvers and anyone who can change bank, billing, domain or integration settings. Keep the number of powerful accounts small enough to oversee, but do not create a single point of failure. Name an accountable owner for approving privileged access and arrange a documented backup for genuine absences. Review temporary access after projects, agency cover and seasonal staffing, because an expiry date is easier to manage than an open-ended promise to revisit it.
Strengthen authentication without sharing identities
The National Cyber Security Centre's corporate guidance explains that administrators should consider the strength of multi-factor authentication used for online services, along with common pitfalls and whether a chosen service supports the required protection. For a returns access review, check every important service for available MFA and record whether it is enforced for all relevant staff, merely offered, or unavailable. Prioritise administrative and sensitive accounts when closing gaps, while planning for the wider team rather than leaving protection optional indefinitely.
Give each person an individual account wherever the service permits it. Shared credentials make it harder to remove one person's access, understand who performed an action and investigate mistakes. If a supplier only supports one operational login, document that limitation, restrict who can use it and ask the supplier about named users or stronger access options. Do not improvise by sending passwords or recovery codes through ordinary chat or email; choose a controlled method that fits the organisation's security arrangements.
Put passwords and recovery routes under control
The NCSC advises against reusing passwords and describes password managers as a way to keep unique credentials without expecting people to remember each one. For accounts that still depend on passwords, check that staff are not recycling a storefront, email or carrier password across services. An approved password manager can support unique generation and controlled access, but its own primary account and recovery arrangements need careful ownership. The NCSC also recommends enabling two-step verification on the password-manager account.
Review recovery at the same time as sign-in. Confirm that reset emails, recovery contacts and backup methods belong to the business and reach current authorised people. Remove former employees' personal addresses and telephone numbers from account recovery. Keep emergency access instructions in a protected location, test that the route works, and record who may authorise its use. Recovery codes should be treated as credentials: limit access, store them securely and replace them after use or suspected exposure.
Make access changes part of normal returns operations
Build a short joiner, mover and leaver checklist around the inventory. New starters should receive only the accounts their role requires and know how to report a suspicious sign-in or unexpected authentication prompt. When somebody changes role, reassess old permissions instead of simply adding new ones. When they leave, disable individual access promptly, rotate any genuinely shared credential they knew, transfer ownership of automations and check recovery contacts. Record completion so that offboarding does not depend on memory.
Finish the review with a controlled exercise. Choose a non-customer test case and confirm that the right roles can view it, update it and follow the normal approval route, while roles outside the process cannot reach sensitive functions. Check that an authorised backup can recover access without relying on a former colleague or personal device. Log gaps with an owner and target date, then schedule the next review after material system or staffing changes. The aim is a repeatable control, not a one-day password tidy-up.
Practical next steps
- Inventory every service used across the returns journey.
- Match each permission to a current operational responsibility.
- Prioritise strong MFA for administrative and sensitive accounts.
- Use individual identities instead of shared logins where possible.
- Control password recovery, backup methods and emergency access.
- Include returns systems in joiner, mover and leaver checks.
Primary sources
Back to News