Skip to content
Will your site survive Black Friday? Free peak-readiness audit →
SECURITY

Separating development credentials between ecommerce clients

When engineers manage several stores, isolating GitHub, cloud, analytics, SSH and monitoring access per client reduces accidental cross-client access.

By VISIBI Security team·Reviewed by Saeed Ak, Co-founder & CTO·Updated 29 September 2026·6 min read
QUICK ANSWER

When engineers manage several stores, isolating GitHub, cloud, analytics, SSH and monitoring access per client reduces accidental cross-client access.

FROM OUR ENGINEERING WORKREAL CASE

When engineers manage several stores, we isolate client-specific GitHub, cloud, analytics, SSH and monitoring credentials to reduce accidental cross-client access.

KEY TAKEAWAYS
✓Shared credentials across clients multiply risk.
✓Use per-client accounts, keys and vault entries.
✓Offboarding should remove access in one step.

What to separate

  • Git hosting organisations and deploy keys
  • Cloud accounts and IAM roles
  • SSH keys per environment
  • Analytics and ad account access
  • Monitoring and alerting tools
  • Password vault collections
RELATED GUIDEHow to stop spam and bot attacks on Adobe Commerce Cloud → Protect your site before it’s hackedManaged security with WAF, scanning and unlimited cleanups.Get a free security scan →

Good practice

Use SSO where possible, least-privilege roles, per-client vaults and regular access reviews.

Common mistakes to avoid

✕Waiting until after a breach to act
✕Restoring a backup without fixing the entry point
✕Leaving old plugins, extensions and admin users in place
✕Relying on a single tool instead of layered defences
HOW VISIBI CAN HELP

How we help with security

01ScanFree scan for malware, vulnerabilities and blocklisting.
02Clean & patchEngineers remove threats and close the entry point.
03HardenWAF, 2FA, least privilege and platform hardening.
04MonitorContinuous scanning with unlimited cleanups on our plans.
Get a free security scan →Free · No obligation · Reply within 24 hours

Frequently asked questions

Why does this matter to clients?

It limits the impact of any single compromised account.

Should agencies use client-owned accounts?

Yes — clients should own their accounts and grant access.

How do you handle this?

Client-owned accounts, SSO and per-client credentials.

SA
Reviewed by Saeed Ak · Co-founder & CTO25 years engineering high-traffic ecommerce, cloud and security platforms. Written by the VISIBI Security team.Meet the team →
Was this guide helpful?
Share:LinkedInXEmail
RELATED SERVICES

Keep reading

SECURITY · 9 MINHow to stop spam and bot attacks on Adobe Commerce CloudRead →SECURITY · 9 MINWordPress security checklist: 15 steps to protect your site in 2026Read →SECURITY · 8 MINMagecart and card skimming: how to protect your checkoutRead →
FREE · NO OBLIGATION

Protect your site before it’s hacked

Managed security with WAF, scanning and unlimited cleanups.

Get a free security scan →Talk to a specialist
✓ Senior specialist, not a bot✓ Reply within 24 hours✓ Clients in 18 countries
SECURITY SCAN PREVIEWEXAMPLE
What attackers can see right now
Unpatched vulnerabilities6
Unknown checkout scripts2
Blocklist statusClean
Your free review shows your real numbers.