Safer AI Workspace: Secure the Accounts Connected to Your Work

Safer AI Workspace: Secure the Accounts Connected to Your Work

A careful computer setup still depends on the accounts connected to it.

If someone gets into my email, they may be able to request password resets elsewhere. If they control my domain account, they may be able to change where my website or email points.

That makes account security part of this development project, even before I have written much code.

My review starts with email, the service that manages my domain, and my password manager. Then I will check GitHub, hosting, payment services, and the AI tools I use.

For accounts that support them, passkeys and compatible security keys are worth reviewing. They are designed to resist fake sign-in sites. An authenticator app can add a second sign-in step where that is the available option. The recovery method matters alongside the sign-in method.

I want to know how I would get back into an account if I lost my phone or laptop. Depending on the service, that may involve recovery codes, another registered key, or a documented account recovery process. I will store recovery information securely outside the device I might lose.

I also want to review active sessions, older devices, and connected apps. Changing a password is not always the same as signing every session out. An integration I approved months ago may still have access.

For business or client work, account ownership needs to be clear. A client should be able to control the services their project depends on. Where the service supports it, I would use an individual collaborator account with the access needed for the work.

This part of the setup applies regardless of whether the computer runs Windows, macOS, or Linux. A browser-based AI tool also relies on these accounts.

One useful action today: open the security settings for your main email account. Review sign-in protection, recovery options, and devices or apps you no longer recognize or need.