Shared Login Prohibition
What a definition is not
A definition is SPEQ’s plain-language decode of how a term is used in practice, cited to the documents that define it. It is a practitioner reference, not legal or regulatory advice, it does not replace the definition in the source, and where a regulator’s wording differs the regulator’s wording governs.
The requirement that every individual who uses a GxP computerized system have their own unique login credential, and that generic, group, or shared accounts (such as a single “operator” password used by an entire shift) never be used, because a shared login makes it impossible to attribute an action in the audit trail to a specific person.
Attributability — knowing exactly who performed an action and when — is one of the foundational ALCOA principles, and it depends entirely on each user having their own credential. A shared or generic login breaks that link: any action recorded under it could have been performed by anyone with the password.
Shared logins are a recurring inspection finding, particularly on laboratory instruments and manufacturing equipment where a single administrator-level account is sometimes used by an entire team “for convenience,” often because unique accounts were never set up or because too many users were given elevated access rather than routine operator rights.
Remediation typically requires issuing individual accounts to every user, restricting administrator rights to the minimum number of people who genuinely need them, and, where a legacy system genuinely cannot support unique logins, documenting compensating controls and a plan to replace or upgrade the system.
- —Every user must have a unique, individually attributable credential
- —Generic or group accounts break attributability in the audit trail
- —A frequent inspection finding on laboratory instruments and shop-floor equipment
- —Administrator-level access should be restricted to the minimum number of users who need it
MHRA GXP Data Integrity Guidance (2018); PIC/S PI 041-1; 21 CFR Part 11
Frequently asked questions
What is Shared Login Prohibition?
The requirement that every individual who uses a GxP computerized system have their own unique login credential, and that generic, group, or shared accounts (such as a single “operator” password used by an entire shift) never be used, because a shared login makes it impossible to attribute an action in the audit trail to a specific person.
Which regulations cover Shared Login Prohibition?
MHRA GXP Data Integrity Guidance (2018); PIC/S PI 041-1; 21 CFR Part 11