The importance of named user logins

The importance of named user logins

The importance of named user logins

Why are named user logins so important when accessing NewZapp? Particularly for organisations with formal governance, information security, data protection or audit requirements.

Why named user logins matter

This article is especially relevant for larger organisations such as NHS bodies, local authorities, universities, colleges, public sector organisations, charities and enterprise teams, where shared system access is often discouraged or prohibited by internal policy.

A named user login means that each person accessing NewZapp uses their own individual account, rather than several people sharing one generic login such as “marketing@”, “comms@” or “admin@”.

While shared logins can seem convenient, they create avoidable risks around security, accountability, governance and compliance.

National Cyber Security Centre governance on SaaS security.

NCSC expects:

  • each real person has their own login
  • each user is uniquely identifiable
  • access is linked to that person’s identity
  • permissions are granted through roles, groups, or policies
  • audit logs show which named user did what
  • users can be individually onboarded, changed, suspended, or removed

 

For more information please follow this link.

1. Clear accountability

With named user logins, actions can be linked to the individual who carried them out.

This helps organisations understand who:

Created or edited a campaign
Uploaded or changed data
Sent a communication
Accessed reports
Changed account settings
Exported or downloaded information

This is important for internal audit, data protection reviews, incident investigation and general good governance.

With a shared login, it can be difficult or impossible to confirm who performed a specific action.

With named user logins, actions can be linked to the individual who carried them out.

2. Better data protection and governance

Many organisations have obligations under data protection, information governance and cyber security policies to control access to systems that hold or process personal data.

Named user access supports this by helping organisations demonstrate that:

  • Access is granted only to appropriate people
  • Users have access levels suitable for their role
  • Activity can be reviewed if required
  • Leavers can be removed without disrupting the whole team
  • Shared credentials are not being passed around informally

 

For sectors such as the NHS, local government and education, this often aligns with existing internal governance expectations.

 

3. Reduced risk when people leave or change roles

Staff movement is normal. People leave, change departments, move projects or no longer need access.

Named user logins make this much easier to manage.

If someone leaves the organisation, their individual access can be removed without affecting anyone else. With a shared login, the password may need to be changed and redistributed, and there is still a risk that former users may know or retain the credentials.

Named logins keep access cleaner, safer and easier to control.

Reduced risk when people leave or change roles

4. Stronger security

Shared logins often lead to shared passwords, saved credentials, informal forwarding of access details and weaker control over who can get into an account.

Named user logins help reduce these risks.

They also support stronger security practices such as:

  • Role-based permissions
  • Password control
  • Multi-factor authentication where available
  • User-level access reviews
  • Faster response if suspicious activity is identified

In simple terms: one person, one login, one clear record.


5. Easier auditing and investigation

If an issue occurs, such as an email being sent in error, data being changed, or an account setting being updated, named user access gives the organisation a clearer audit trail.

This helps answer important questions quickly:

  • Who made the change?
  • When did it happen?
  • Was it expected?
  • Was the user authorised?
  • Does any follow-up action need to be taken?


Without named access, these questions become much harder to answer.

Easier auditing and investigation

6. Supports internal policy requirements

Many larger organisations already have policies that require individual access to systems, particularly where personal data, communications data or customer records are involved.

This may include policies covering:

  • Information governance
  • Cyber security
  • Data protection
  • Acceptable use
  • Records management
  • Supplier assurance
  • Audit and compliance
  • Access control
  • Leavers and movers processes

 

Using named user logins in NewZapp helps support these requirements and makes it easier for teams to evidence good practice.

7. Avoids unnecessary operational risk

Shared accounts can create practical problems as well as security risks.

For example:

  • A password change can lock out the whole team
  • It may be unclear who owns an action
  • Access may continue for people who no longer need it
  • Credentials may be stored or shared insecurely
  • Internal audit teams may challenge the use of shared access

Named user logins reduce these issues and make account management more straightforward.

What we recommend

Each person who needs to access NewZapp should have their own named user login.

Access should be reviewed regularly, especially when people join, leave or change role.

In summary

Named user logins are not just an administrative preference. They are an important part of good security, clear accountability and responsible data governance.

For organisations such as NHS bodies, councils, universities and other larger teams, named access helps support existing governance expectations and gives both the organisation and its users better protection.

It is a simple step that significantly improves control, transparency and trust.

Book A Demo

Filter Categories

Are your internal emails reaching every member of staff? For communications teams in large organisations, the answer is often less certain than you'd expect. Messages that never arrive at the inbox can undermine trust, delay critical updates, and leave colleagues without the information they need to do their jobs safely.
AI is reshaping internal communications, offering efficiency and personalisation while raising ethical concerns. Discover key insights from our latest survey on AI adoption, challenges, and opportunities for internal comms teams
NewZapp Communications gives you a UK-hosted, ISO 27001 certified email platform built specifically for internal communicators. But several other tools compete for that same spot on your shortlist.
A GDPR-compliant platform should provide appropriate security controls, a data processing agreement and clear information about where data is stored. It should also support data access, correction, export and deletion requests.
Effective internal communications require listening as well as broadcasting. Integrated survey tools allow you to gather feedback, measure sentiment, and identify concerns before they escalate.
Schools, colleges and universities are busy, complex communities. Staff, students, leadership teams, governors and support departments all need timely information.

The Collaboration Clutter Crisis: Why Slack and Microsoft Teams Are Failing Internal Communications

Internal communication has become lost in the noise of tools like Slack and Microsoft Teams, where important updates compete with chat, notifications and channel clutter. While these platforms excel at quick collaboration, they’re not designed for delivering messages that need attention, comprehension or action. As a result, critical updates get buried, employees miss information, and organisations face widening gaps in alignment and engagement — especially among frontline or non-desk staff who may not use these tools at all.

Read The Blog »

The Culture Chameleon: Why Colour-Changing Organisations Eventually Face the Consequences

This article explores the “culture chameleon” effect: when organisations change colours publicly while living a different reality internally. Through the BrewDog case and echoes from Uber, Wells Fargo, Boeing and WeWork, it reveals the cultural and reputational consequences of contradiction and shows how internal communicators help anchor authenticity and protect organisational trust.

Read The Blog »

NHS Trust Rankings 2025: Could Internal Comms Decide Your Place?

Royal Papworth Hospital NHS Foundation Trust, a leading heart and lung hospital in the UK, was facing significant challenges with its internal communication system. The Trust needed to modernise its approach, as persistent issues with its legacy communications platform, were affecting staff engagement and timely communication

Read The Blog »