Home » Security Camera Shared-User Access Audit Checklist 2026: Viewers, Exports, Removal, and Recovery

Security Camera Shared-User Access Audit Checklist 2026: Viewers, Exports, Removal, and Recovery

Sharing a security camera account is easy. Knowing exactly what each person can still see, export, delete, or change is harder. A useful access audit checks every route into the camera system: the vendor app, browser login, smart-home platform, recorder, support account, saved clips, and account-recovery settings.

This checklist is for households, landlords, small businesses, and anyone taking over an existing camera setup. Use it after a move, breakup, staff change, installer visit, phone replacement, or suspected account exposure. It also works as a yearly privacy check.

Goal: finish with a named owner, a current list of approved users, tested permissions, removed stale access, and a recovery path that does not depend on one missing phone or email address.

What a camera access audit should cover

Do not start by counting names in one app. Start by listing every way someone could reach the cameras or recordings.

Access surface What to inspect Common blind spot
Camera vendor app Owners, admins, viewers, pending invitations, signed-in devices A former user remains signed in after removal
Web portal Browser sessions, saved passwords, download rights The web account has broader rights than the mobile app
Local recorder NVR/DVR users, monitor access, local export, admin password Anyone near the recorder can export footage to USB
Smart-home platform Apple Home, Alexa, Google Home, routines, household members A removed camera-app user still sees feeds through another platform
Integrations Automation services, dashboards, API tokens, third-party apps An old integration token continues to work
Shared clips Public links, emailed files, cloud folders, messaging apps Deleting a camera user does not revoke an exported clip
Support and installation Installer logins, remote-support sessions, temporary codes A contractor account was never disabled
Account recovery Recovery email, phone number, backup codes, second owner The former owner controls password resets

If the system came with a property or changed hands, also use the smart-home security handover checklist. For contractor access, see the installer access checklist.

Before you change anything: build an access inventory

Record the current state before removing users or changing passwords. This gives you a rollback reference and helps identify access that lives outside the main app.

  1. List every camera, doorbell, hub, recorder, display, and cloud service.
  2. Write down the primary account email and the name of the person who controls it.
  3. Export or screenshot the current user list, role list, pending invitations, and signed-in devices.
  4. Note which cameras each user can view and whether they can view live video, history, or both.
  5. List every smart-home household, voice assistant, dashboard, and automation connected to the cameras.
  6. Record the retention period and where downloaded clips are stored.

Keep this record with your other security documentation. The home security documentation checklist explains what belongs in that file.

Map roles to real permissions

Labels such as “viewer,” “member,” and “admin” are not consistent across brands. Test what each role can actually do. Create a temporary test user if the platform allows it, then check the following actions from that account:

  • View live video and hear live audio
  • Use two-way talk, a siren, spotlight, or pan-tilt controls
  • View event history and continuous recordings
  • Download or share a clip
  • Delete an event, recording, or camera
  • Change motion zones, privacy zones, schedules, and notifications
  • Disable recording, microphone capture, or status lights
  • Add or remove users
  • Change billing, subscription, retention, or account ownership
  • Reset the camera or transfer it to another account

Do not assume the app blocks a viewer from exports or settings. Test one action from each permission group and record the result. If a platform only offers all-or-nothing sharing, give access to fewer people and review it more often.

Use the least access each person needs

A household member who only needs a doorbell alert does not need billing control. A dog walker may need a front-door view for one week, not every indoor camera forever. A monitoring employee may need event review but not microphone control.

User type Typical need Access to avoid unless required
Primary owner Full administration, billing, recovery None, but protect with strong MFA
Second trusted owner Emergency administration and recovery Everyday use of the primary owner’s login
Household adult Live view, events, alerts, two-way talk Billing, ownership transfer, user management
Child or guest Selected outdoor views or alerts Indoor cameras, exports, settings, history
Cleaner or pet sitter Time-limited view or entry confirmation Permanent access and full camera history
Installer Setup and diagnostics during a booked window Standing remote access after acceptance
Small-business staff Only the locations and shifts tied to their job Owner controls, unrelated cameras, unrestricted exports

Where the platform supports camera-level sharing, separate indoor, outdoor, nursery, office, and rental-unit cameras. Where it supports schedules, set an expiry date at the time access is granted.

Remove a former user completely

Removing a name from the camera app is only the first step. Use this sequence so old sessions and linked services do not survive the change.

  1. Remove the user from the camera account and cancel any pending invitation tied to them.
  2. Remove them from Apple Home, Alexa, Google Home, shared password managers, and any home dashboard.
  3. Revoke active sessions or choose “sign out all devices” if available.
  4. Change the primary password if the old user ever knew or reused it.
  5. Regenerate API keys, integration tokens, local recorder passwords, and temporary installer codes they could access.
  6. Check account recovery details and replace any phone number or email they control.
  7. Review shared clip links, cloud folders, and exported files. Revoke links where possible.
  8. Test the former user’s old login on a different network. Confirm live view, history, notifications, and integrations all fail.

A password change may not end every signed-in session, and deleting a user cannot retrieve a file already downloaded to another device. Record that limitation rather than treating the audit as proof that every past copy is gone.

Check smart-home and voice-assistant access

Camera feeds often appear on smart displays, TVs, watches, and automation dashboards. Review the household members and linked accounts in each platform separately. Then run these tests:

  • Ask each smart display to show a camera feed.
  • Check whether voice recognition or a PIN is required.
  • Review routines that display, announce, arm, or disable camera-related actions.
  • Confirm removed members no longer belong to the smart-home household.
  • Inspect shared tablets and TVs for saved logins.
  • Verify privacy-sensitive indoor feeds do not appear on devices in guest areas.

If the camera supports privacy zones or scheduled indoor recording, test those controls from both the camera app and the smart-home platform. A zone drawn in one app may not apply to a separate recording path.

Audit the recorder and local network

Systems with an NVR, DVR, NAS, or local hub need a second access review. Open the recorder’s user-management screen and check named users, default accounts, remote access, local monitor permissions, export rights, and password age.

Change default or installer credentials. Disable unused services and port-forwarding rules. If remote viewing is required, use the vendor’s supported encrypted method or a properly managed VPN rather than exposing recorder ports directly to the internet.

Then stand in front of the recorder and ask a simple question: could a visitor, former employee, tenant, or contractor reach the console or USB export port? Physical access can bypass carefully configured app roles.

Review installer and support access

Installers and support agents may use temporary invitations, device codes, screen sharing, or vendor-side diagnostics. After the work is complete:

  • Close the support case and end any remote-support session.
  • Remove temporary users and one-time setup codes.
  • Change any password disclosed during troubleshooting.
  • Check whether diagnostic logs or sample clips were uploaded.
  • Record who accessed the system, why, and when the access ended.

If the installer supplied the original owner account, move ownership to an email and phone number controlled by the customer. A permanent installer-owned account creates a recovery and privacy risk.

Fix account ownership and recovery

The account should not fail when one person loses a phone, changes jobs, or becomes unavailable. Confirm:

  • The primary email belongs to the current owner and can receive password-reset messages.
  • The recovery phone is current and protected by a carrier PIN.
  • Multi-factor authentication is enabled for owners and administrators.
  • Backup codes are stored offline in a secure place.
  • A second trusted owner can restore service without sharing the primary password.
  • Subscription and payment notices reach the right person.

Never share one owner password among several people. Named accounts create a clearer audit trail and allow one person’s access to be removed without disrupting everyone else.

Test the system under failure conditions

An access audit is incomplete until you test what happens when normal connectivity fails. Use a safe maintenance window and record the results.

  1. Internet outage: confirm whether local live view and recording continue.
  2. Power interruption: verify recorder, hub, network, and camera recovery.
  3. Cloud-service outage: identify which controls disappear and whether local footage remains available.
  4. Phone loss: confirm the owner can sign in from a replacement device without relying on the missing phone.
  5. Role removal: remove the temporary test user and confirm old sessions, alerts, and smart-home views stop.

Document each change in a simple record. The home security system change-log checklist provides a practical format.

40-minute shared-user access audit

Minutes 0–10: inventory

  • List devices, services, owners, members, pending invites, integrations, and recovery contacts.
  • Capture the current settings before changing them.

Minutes 10–20: permission tests

  • Use a test account to check live view, history, export, deletion, settings, and user management.
  • Compare app, web, recorder, and smart-home access.

Minutes 20–30: cleanup

  • Remove stale users, invites, sessions, installer access, integrations, and shared links.
  • Update passwords, MFA, recovery details, and backup codes where needed.

Minutes 30–40: verification

  • Test an approved user, a removed user, and the recovery process.
  • Confirm selected smart displays and local recorders behave as documented.
  • Record the date, owner, changes, unresolved limits, and next review date.

When to repeat the audit

Repeat the audit after any change in residents, staff, contractors, property ownership, phones, routers, smart-home households, or camera subscriptions. For a stable household, review access at least once a year. For rental properties, shared homes, and small businesses with staff turnover, review it quarterly.

Frequently asked questions

Does changing the camera password remove every shared user?

Not always. Some platforms keep invited members, trusted devices, API tokens, or smart-home links active after a password change. Remove users and sessions explicitly, then test the old access path.

Can a removed user still see downloaded camera clips?

Yes. Removing account access does not erase files already downloaded, copied to cloud storage, or sent through messaging apps. Revoke live shared links where possible and document any copies you cannot control.

Should an installer keep permanent access to security cameras?

Usually no. Give an installer time-limited access for setup or support, then remove it and change any credentials they used. Keep standing access only when a written service agreement requires it and the platform records each access event.

How many camera account owners should a household have?

One primary owner and one trusted backup owner is a practical setup for many households. Each should use a named account with multi-factor authentication. Other users should receive narrower roles based on what they need to do.

Have your say!

0 0