Philippines staffing guide

Secure account handoff for a Philippines virtual assistant

A Filipino virtual assistant should get enough access to finish the assigned work, but nothing extra. This guide shows how to set up named accounts, small roles, MFA, review notes, and a clean exit.

13 min readUpdated 2026-07-27

Start with these rules

  • Build access from the task list, not from a copy of another employee's account.
  • Use a named account, a password manager, MFA, and the smallest useful role.
  • Keep payments, account ownership, exports, and unusual customer decisions with the manager.
  • Review access during the role and remove it from a written checklist when the work ends.

Access starts with the first real task

Do not begin with a list of every app your company uses. Begin with the first work lane, such as sorting a shared inbox, updating approved CRM fields, or preparing research in a team folder.

For each task, name the record the assistant must read, the action they may take, and the decision that must come back to the owner. This small map often shows that a Filipino assistant needs a shared mailbox role or one project folder, not an owner's full account.

Share of United States fraud reports that included a monetary loss in 2023 and 2024Two horizontal bars show 27 percent in 2023 and 38 percent in 2024, an increase of 11 percentage points.Fraud reports with money lostUnited States consumer reports to the FTC202327%202438%0%10%20%30%40%Unit: percent of fraud reports. Change: +11 percentage points. Source: FTC, 10 March 2025.
Method note: The bars reproduce the two percentages in the FTC's 2024 fraud release and show the difference in percentage points. The data covers United States consumer reports, not Filipino assistants, and it does not estimate the risk of remote work.

Use fraud data as context, not a claim about Filipino staff

The FTC reported on 10 March 2025 that United States consumers said they lost more than $12.5 billion to fraud in 2024, which was 25% higher than the prior year. The agency received 2.6 million fraud reports for 2024, close to the 2023 count.

The share of reports that included a monetary loss rose from 27% in 2023 to 38% in 2024. The same release said reported losses to imposter scams reached $2.95 billion in 2024.

These are United States consumer figures, not incident counts for the Philippines or virtual assistants. They matter here because an inbox, CRM, or store account may expose a Filipino assistant to fake requests that look like a boss, customer, or vendor.

“The data we’re releasing today shows that scammers’ tactics are constantly evolving.”

Christopher Mufarrige, Director of the FTC's Bureau of Consumer Protection, Federal Trade Commission, 10 March 2025

Create a named account instead of sharing the owner's login

A named account tells you who signed in and makes removal much easier. It also lets the company set a smaller role for the assistant while the owner keeps billing, account recovery, exports, and administrator settings.

Use a work email address controlled by the company when the app permits it. Put the employee name or role in the profile, record the manager who approved it, and avoid aliases that hide which person is doing the work.

Access ownership table

Example access limits for a Philippines-based virtual assistant
Work laneUseful accessKeep with the ownerReview proof
Shared inboxRead assigned mail, apply labels, and draft approved replies.Account recovery, forwarding rules, deletion policy, and unusual promises.Handled list, flagged messages, and changed rules.
CRM supportEdit assigned contacts, notes, stages, and follow-up dates.Full exports, user administration, automation changes, and record deletion.Changed records, duplicate log, and owner questions.
Ecommerce supportView orders and use approved customer service actions.Payouts, bank details, store ownership, fraud decisions, and large exceptions.Order actions, exception list, and reopened cases.
Research supportUse a project folder, approved sources, and a clean output file.Private archives, unrelated client files, and company-wide sharing controls.Source list, file history, and final folder check.

Use the smallest role that can complete the lane

NIST SP 800-207, published in August 2020, says access should not be trusted only because of a user's location or device ownership. Authentication and authorization should happen before a session reaches a company resource.

For a Philippines-based assistant, that means the manager checks the person, device, and requested task instead of treating remote work as one large permission. Start with view, draft, or assigned-record access and add a stronger action only after the task proves it needs one.

Put passwords in a manager, then add MFA

CISA advises people to create long, random, unique passwords with a password manager. The assistant should receive the item through that tool rather than through chat, a spreadsheet, a screen recording, or a reusable starter password.

Turn on a second sign-in check for email, CRM, store, cloud storage, and other sensitive work. CISA's MFA guide explains that the second step can block access even when someone steals the password.

Five-step access lifecycle for a Philippines virtual assistantThe manager maps the task, creates a named account, adds only needed access, reviews a weekly record, and removes access at the end of the role.One owner, five access checks1MapTask and data2NameSeparate account3LimitSmallest role4ReviewSign-ins and use5RemoveClose and recordThe access register follows every stepAccount owner · role · MFA method · approval date · review date · removal proofIf nobody owns a step, stop the handoff and fix the record first.
The same manager should own the access record from setup through removal. This keeps a Philippines-based assistant from collecting old permissions as the role changes.

Write an access register that a manager can read in five minutes

The register can be a protected company sheet or ticket list. Give each row the person's name, tool, role, task reason, approving manager, MFA method, setup date, last review date, and planned removal step.

Do not place passwords, backup codes, or private answers in the register. Link to the password-manager item or administration page, then limit the register itself to the people who manage access.

Match the setup to Philippine privacy duties

Section 20 of the Philippine Data Privacy Act of 2012 says personal information controllers must use reasonable and appropriate organizational, physical, and technical measures. It also calls for protection against unlawful access, fraudulent misuse, alteration, disclosure, and other unlawful processing.

This article is an operating guide, not legal advice, and the law's application depends on the parties and data involved. A company should still make the daily controls visible: approved work purpose, limited records, secure sign-in, an incident contact, and a removal record.

Run a first-week access test

On day one, ask the assistant to sign in while the manager is available and complete one low-risk task. Check that the correct account, MFA method, folder, and role work without opening unrelated records.

During days two through four, review sign-in notices, changed records, drafts, and blocked actions each morning. A block may be correct because it keeps an owner-only decision with the manager, or it may show that one narrow permission is missing.

Give the assistant a plain suspicious-request rule

A Filipino assistant working in an inbox may see a message that asks for an urgent payment, password reset, customer export, forwarding rule, or bank change. The rule should say to stop, preserve the message, and contact the named owner through a second known channel.

Do not ask the assistant to decide whether a polished message is harmless. Give them a short list of actions that always need owner approval, even when the sender appears to be a senior leader or long-time vendor.

Remove access from a checklist, not from memory

Offboarding starts before the final shift by checking the access register against the current task list. Choose who receives open work, shared files, drafts, customer exceptions, and any device or key owned by the company.

At the agreed end time, disable the named work account, revoke active sessions, remove group and folder membership, rotate any credential that had to be shared, and recover company records. Then check forwarding rules, connected apps, API tokens, recovery methods, and scheduled automations.

Save a short removal record with the person, tools checked, manager, date, open issues, and proof. Do not delete useful work history merely to make the account disappear.

Use a copy-ready access request and exit note

The manager should make each request specific enough to approve or reject. The assistant should close the role with a list of open items rather than a vague message saying everything is done.

Manager's access request

"Please create a named account for [person] to complete [task]. Give it [role] for [records], keep [owner-only actions] blocked, and send the setup record to [manager] by [date]."

Assistant's exit note

"Open work is listed at [link]. I returned [files or devices], removed personal copies, and sent [unresolved access or customer items] to [owner] for review."

Questions to ask before the role starts

  • Which named accounts and delegated roles can the company create?
  • Who owns setup, MFA recovery, weekly review, and final removal?
  • Which customer, money, export, and account changes always need approval?
  • Where should the assistant report a strange sign-in or urgent request?
  • How will the company preserve work and close sessions when the role ends?

Related Philippines staffing paths

Use the executive assistance page to map owner-only decisions, or review calendar and inbox support for delegated account work. Teams with source-heavy tasks can also review research and data support.

For overnight account use, read the Philippines virtual assistant night shift guide. It covers queue limits, morning records, protected hours, and escalation while the daytime owner is offline.

Sources

  1. Federal Trade Commission, New FTC Data Show a Big Jump in Reported Losses to Fraud to $12.5 Billion in 2024, 10 March 2025. United States consumer-report data used here as broad fraud context, not as a measure of Filipino assistants or remote staffing.
  2. National Institute of Standards and Technology, SP 800-207 Zero Trust Architecture, August 2020. Guidance on checking the user and device before access to a work resource is allowed.
  3. National Institute of Standards and Technology, SP 800-46 Revision 2, Guide to Enterprise Telework, Remote Access, and BYOD Security, July 2016. Guidance for remote devices, connections, access servers, and telework security policy.
  4. Cybersecurity and Infrastructure Security Agency, Turn On MFA. Steps for adding a second identity check to work accounts.
  5. Cybersecurity and Infrastructure Security Agency, Use Strong Passwords. Advice on long, random, unique passwords and password managers.
  6. Republic Act No. 10173, Data Privacy Act of 2012, Philippines. Section 20 requires reasonable and appropriate organizational, physical, and technical measures for personal information.