Menu
← All articles

Setting Up Access Rights Properly in Coaching Software

Setting Up Access Rights Properly in Coaching Software

Title card with illustrations of a lock and access rights

Set up an authorization matrix right away, enable multi-factor authentication and use only unique accounts, never shared login details. Give each role exactly enough access to do the job, no more. Choose software with a data processing agreement and European hosting, such as Exantur, so that client data stays protected without you needing any technical knowledge yourself.


In short:

  • Shared accounts undermine accountability and traceability, which is why every user account is unique and tied to a person.
  • Access rights must be reviewed regularly and adjusted immediately when staff or roles change, in order to limit risks.
  • Multi-factor authentication and logging are essential technical measures that make the difference between theoretical and actual data security.
  • An authorization matrix with minimal data and review dates helps you keep an overview and prevent unnecessary access.
  • Coaching software should be hosted on European servers, with a data processing agreement and options for team role management and audit logs.

Exantur
exantur.com
Manage access to client data
Exantur brings together client relationships, team roles and sensitive coaching information with MFA, EU hosting, audit logs and organization isolation.
Explore secure coaching software

Table of contents

Why need-to-know and unique accounts form the foundation

Access management comes down to a simple idea: someone only gets the data needed for their task. This is called the need-to-know principle. An assistant who only manages calendars doesn't need to see session notes. An accountant doesn't need access to a client's personal breakthroughs.

This principle is also known as the least-privilege principle: everyone gets the smallest possible set of rights needed to function. The fewer people who have access to sensitive data, the smaller the risk in the event of a mistake or a data breach.

Shared accounts undermine this immediately. If three people use the same login, you can no longer trace who performed which action. That makes accountability impossible and logging worthless. Every user should therefore have their own unique account.

The following points form the core of secure access management:

  • Every user gets exactly the data needed for their own task, no more.
  • Never shared accounts: every employee or freelancer logs in with their own identity.
  • Rights are tied to a function or role, not to a person as an individual.
  • Access is reviewed periodically and adjusted where necessary.

The European privacy watchdog EDPB advises reviewing access rights regularly, ideally every six months, and adjusting them immediately upon onboarding, offboarding or a change of role. That same guideline is explicit about shared accounts: they have no place in an organization that processes personal data.

Step-by-step plan for a simple authorization matrix

An authorization matrix sounds technical, but in practice it's a clear document. It records who may view and edit which data. Follow these steps to set one up yourself.

  1. Make a list of all roles in your practice, for example coach, assistant, accountant and possibly a second coach.
  2. Describe for each role which tasks that person performs, without going into systems or technology.
  3. Link to each task the minimal data required, for example only calendars, or also session notes and invoices.
  4. Record the matrix in a document and have a second person, or yourself at a later moment, review the choices.
  5. Test the access in practice and adjust where someone turns out to have too many or too few rights.

Pro tip: start with the role that sees the most sensitive data, usually that of the coach themselves, and work from there towards the roles with less access.

The Dutch Data Protection Authority advises introducing an authorization matrix even at a low risk level and keeping it detailed and up to date.

Adjusting rights on onboarding, role changes and departure

Access rights are not a one-time setting. They change along with who works in your practice and what that person does. Without a fixed procedure, old rights pile up, and that's precisely where risks arise.

So build in three fixed moments:

  • For a new employee or temporary help: create a unique account with only the rights that belong to the role, never a copy of an existing account.
  • On a change of role: adjust rights immediately, even if the change seems temporary.
  • On departure: close the account immediately, not only at the next review.
  • Regularly check the list of active accounts and remove rights that no one needs any more.

This approach aligns with the EDPB's advice to review rights immediately upon onboarding, offboarding or a change of role, instead of waiting for an annual review. Regular checks are manageable, even for a small practice with a few employees.

MFA, logging and the risk assessment of external software

A few technical settings make the difference between software that is secure on paper and software that actually is. These settings are not a technical specialism, but switches you can flip yourself or that you may expect from your provider.

  • Enable multi-factor authentication (MFA) for every account with access to client data: alongside a password, the system asks for a second confirmation, for example via a code on your phone.
  • Make sure the system keeps logging: an overview of who viewed or changed which data and when.
  • Review those logs regularly, not just after an incident.
  • Use a separate admin account for settings and limit the number of people with admin rights to a small number.
  • Carry out a short risk assessment before you connect a new external tool to your coaching software, and disable features you don't use, with handy tips on LMS Single Sign On for IT.

MFA is recommended by the Dutch Data Protection Authority as an extra layer of security for systems that process personal data, such as business email and chat services. For coaching software with client files the same logic applies: one password is not enough.

Logging is no needless luxury here. The Dutch Data Protection Authority calls logging and audit trails an essential measure for tracing who carried out which processing, and for preventing or limiting data breaches.

Depiction of logging and a reliable audit trail

Template: matrix and checklist ready to use

A good matrix doesn't have to be complicated. Five columns are enough to keep an overview and, during a review, to quickly show who has access and why.

Role Necessary data Access level Responsible party Review date
Coach Session notes, goals, contact details Full, own clients Coach themselves Every six months
Assistant Calendar, bookings View and schedule only Coach Every six months
Accountant Invoices Financial data only Coach On contract change
Second coach Own client files Full, own clients Practice owner Every six months

Alongside the matrix, a short checklist helps you forget nothing:

  • Every user has their own unique account, never shared.
  • MFA is enabled for all accounts with access to client data.
  • Logging is switched on and reviewed periodically.
  • A review date is in the calendar, at most six months away.
  • When in doubt about a risky connection, a data protection officer (DPO), someone who oversees the careful handling of personal data, is consulted.

Update the matrix as soon as a role changes, someone leaves or you connect a new tool: this prevents the document from drifting apart from the practice.

What I often come across in practice

Shared accounts remain popular because they feel easy: one login, no hassle with passwords. But that convenience actually costs you control. Replace them with unique accounts with clear roles; that takes just ten minutes per person, one time.

For a small practice the order is simple: first unique accounts and MFA, then an extensive matrix. Start small and build out.

— Martijn

How Exantur handles access rights and privacy

Choosing coaching software that is set up with GDPR in mind saves you the legwork. Exantur works with unique user accounts, multi-factor authentication and a dedicated, shielded portal for clients, so that they only see their own goals, assignments and progress.

Data is stored on European servers and the software comes with a data processing agreement, a mandatory document between you and your software provider about how personal data is processed. Larger practices also get audit logs and team roles to set access per employee. This way you don't have to build a technical system yourself to meet the basics of good access management. You can read more about the security setup on Exantur's security page. If you'd like to try it out yourself, take a look at the trial period and plans.

Sources

This article contains general information and does not replace the advice of a qualified lawyer. Consult a qualified legal professional about your own situation before acting on the basis of this content.

Frequently asked questions

What exactly is an authorization matrix?

An authorization matrix is an overview of who in your practice may view or edit which data. The Dutch Data Protection Authority advises introducing one even from a low risk level and keeping it up to date.

How often should I review access rights?

Review rights at least every six months and immediately upon a change of role, onboarding or departure. This advice comes from the EDPB and prevents old rights from lingering.

Are shared accounts allowed under the GDPR?

No, every user should have their own unique account so that actions remain traceable. Shared accounts make logging and accountability impossible and go against the principle of careful data processing.

As a coach, do I always have to appoint a data protection officer?

Not every coaching practice is required to appoint a data protection officer; that depends on the scale and type of processing. An external DPO on a contract basis is an option for independent review, even when it is not legally required.

What role does logging play in preventing data breaches?

Logging keeps track of who viewed or changed which data, helping to detect unusual access early. The Dutch Data Protection Authority calls this an essential measure for preventing or limiting data breaches.

Recommendations