Shared control without chaos
Shared access usually means one password known to several people, which is neither shared nor controlled. There are calmer arrangements that survive a change of committee.
* * *
The sticky note exists for a reason. A club has one domain, several people who occasionally need to change something, and no budget for anything complicated. The obvious solution is one login and one password, written on paper in the clubhouse drawer or forwarded in an email thread that now sits in a dozen mailboxes. It works until the day it matters: when the person who last changed the password has left, when the account asks for a code sent to a phone nobody has, or when a member with a grievance still knows exactly how to get in.
Why the single login fails quietly
A shared password produces no record. Nothing shows which person made a change, so a broken website has no starting point for the investigation. It cannot be revoked for one individual, only for everybody at once, which means it is almost never revoked at all. And it accumulates: every year another person is told what it is, and none of them are untold. The failure is rarely dramatic. It is simply that after a few years nobody can say with confidence who is able to move the club's name.
Accounts with roles, not one door
Most registrars and most hosting control panels now allow more than one user on the same account, with different levels of permission. The arrangement that works for a club is one account owned by the organisation, with individual logins for the people who need them: full access for the person responsible, limited access for whoever edits the website or manages mailboxes. Each person signs in as themselves, each can be removed on their own, and the account history shows who did what.
Where a registrar does not support additional users, the fallback is a single account whose credentials live in a password manager owned by the organisation, with the manager itself shared through named individual logins. The principle is the same: identity belongs to a person, ownership belongs to the group.
The recovery address is the real key
Whoever controls the mailbox that receives password resets controls the domain, whatever the account settings say. A club whose registrar account recovers to a personal address at a free mail provider has handed the ultimate authority to one member, usually without either party noticing. The recovery address should be a mailbox on the organisation's own domain, or on an address the committee holds jointly, and it should be one that more than one officer can open.
There is an obvious circularity here: if the recovery mailbox sits on the same domain that has just expired, nothing arrives. A secondary address held elsewhere, checked by a different officer, breaks the loop. Why mail is the first thing to break when a domain changes hands is covered in keeping email working.
Two step verification that does not live on one phone
Second factor codes are worth switching on, and they are also the most common way a volunteer group locks itself out. A code generator installed on one person's phone becomes a single point of failure the moment that phone is replaced or that person resigns. The workable versions are an authenticator whose secret is stored in the organisation's password manager so more than one officer can generate a code, or backup codes printed once and kept with the other papers the treasurer holds. Either way the recovery route has to be tested before it is needed, not discovered during an emergency.
Writing it down, once
Access arrangements that live only in people's heads do not survive a committee. What is needed is short: which registrar holds the name, which account, which mailbox recovers it, where the second factor lives, who currently has access, and the renewal date. That record belongs wherever the club already keeps its bank mandate and its insurance policy, not in a personal drive. It should be reviewed at the same meeting each year, alongside the accounts, and updated when anyone joins or leaves. The full set of things that should move between officers belongs in the same short record.
Access should be granted to people, removed from people, and owned by the organisation. Any arrangement that cannot do all three will fail at the worst moment.
When the person who set it up is already gone
Plenty of committees inherit a situation rather than design one, and the honest first step is an audit: find out where the name is registered, who is listed as registrant, and which mailbox the renewal notices reach. Public registration data will show the registrar even when it hides the contact details, and the way to read it is set out in WHOIS and RDAP. If the answer turns out to be a personal account belonging to somebody who has moved on, that is a transfer problem rather than an access problem, and it is easier to solve while the former volunteer is still contactable and well disposed. Deciding where the account should live afterwards is the subject of who should hold the account.