The Web Account Inventory: Do This First

  • Season: 1, Episode: 3

Nearly every web account audit finds the same three things: an orphaned account, an unknown auto-renewal, and an ex-employee who still has admin access. Every organization believes it's the exception. Almost none of them are.

This is the episode host Bryan Mills would have you hear first: the web account inventory, the single register of everything your organization owns, rents, or depends on online, and the foundation every later episode runs against. Bryan walks the full discovery hunt, inbox archaeology, twelve months of card statements read aloud, DNS records as a witness list, and the website testifying against its own makers, then slows down for the number one trap of inherited web stacks: the difference between access, who can log in, and ownership, whose name and card the account is registered under. The two feel identical on a normal day and behave nothing alike on a bad one.

The episode closes with where everything you find should live: a password manager instead of the shared spreadsheet, and the one-page "hit by a bus" file that makes your work survivable. The myth busted this week, "we know what we have," comes with a gift inside: the inventory usually pays for itself in canceled waste, and found money is how you sell the project to leadership.

Quick win: twenty minutes searching the org inbox for "renewal," "invoice," and "verify your account." Expect at least one genuine surprise.

In This Episode

  • What counts as a web account: the full perimeter, from domains and hosting to integrations, payment platforms, shadow accounts, and the fast-multiplying AI tool layer

  • The discovery hunt: inbox archaeology, statement descriptors and following the money, ICANN Lookup and DNS records as clues, page source and footer credits, and the exit interview worth booking

  • Access versus ownership: the vendor-owns-your-domain pattern, the audit columns to fill in, and the role-based address standard that survives every staff change

  • The password manager rollout that actually sticks, MFA custody, and the passphrase guidance for the vault's master password

  • The "hit by a bus" one-pager: what goes in it, what must never go in it, and the sealed-envelope problem

  • Myth busted: "we know what we have"

Links

  • Updated with launch.

Timestamps

  • 0:00 Introduction to Web Account Audtis

  • 1:10 What this episode covers

  • 1:50 The Shift: sprawl is the new normal

  • 3:15 Drawing the perimeter, and ranking what breaks

  • 5:50 The discovery hunt: inboxes, statements, DNS, and the website's own testimony

  • 10:20 Access versus ownership, and what it costs to get your domain back

  • 14:30 The password manager, the rollout, and MFA custody

  • 15:20 The "hit by a bus" one-pager

  • 16:00 Myth busted: "we know what we have," and the found-money reframe

  • 18:10 Quick win: three inbox searches, twenty minutes

  • 20:00 Worksheet and where to find it

  • 20:30 Close and Episode 4 tease