Digital Estate PlanningEmergency Access and Recovery
Digital Estate Checklist: Accounts Your Family Will Actually Need
A useful digital estate inventory tells someone what exists, why it matters, who should act, and where the authorized access method is stored. It should not be a plaintext spreadsheet containing every password.
This checklist is for planning and organization, not legal advice. Laws, contracts, and provider policies may restrict what another person can access even when they possess working credentials.
Start with the access chain
Before cataloging dozens of services, identify the accounts and devices that unlock everything else.
Primary phone and computers
Record:
- Device type and owner
- Where the device is normally kept
- Whether data is backed up
- Where authorized device-access instructions are stored
- Who should receive or erase the device
- Whether the device contains business or client information
Do not put a device passcode in an unprotected inventory.
Primary email
Email is often the reset channel for other services. Record:
- Provider and email address
- Recovery email and phone
- Whether MFA is enabled
- Whether the provider offers a legacy or inactivity feature
- Intended disposition of messages and files
- Location of the authorized recovery method
Password manager
Record:
- Product and account email
- Where the recovery kit or code is stored
- Whether trusted-contact access exists
- Who may use it and under what conditions
- Whether a recent export or backup exists
- How often the plan is tested
Keep recovery material outside the vault it recovers. See What Happens If You Forget Your Master Password?.
Multifactor authentication
Inventory:
- Authenticator apps
- Hardware security keys
- Backup codes
- Recovery phone numbers
- Passkeys tied to devices or platform accounts
- Which critical accounts depend on each factor
Losing the password manager may be recoverable while losing every MFA method is not—or vice versa.
Financial and household accounts
For each account, record its purpose, institution, account identifier or last four digits, recurring obligations, intended responsible person, and location of legal documentation.
Include:
- Banks and credit unions
- Credit cards and loans
- Investment and retirement accounts
- Payment platforms
- Insurance portals
- Tax-preparation and tax-agency accounts
- Mortgage or rent portals
- Utilities
- Mobile and internet service
- Recurring household services
- Reward points with material value
- Cryptocurrency exchanges and wallets
Do not treat possession of a password as permission to transfer money. Financial institutions commonly require proof of authority and may freeze or restrict accounts after death.
For cryptocurrency, distinguish custodial exchange accounts from self-custodied wallets. A seed phrase may directly control an irreversible asset and deserves a specialized offline succession plan.
Identity and government records
List where authorized copies or originals are kept for:
- Birth and marriage certificates
- Social Security or national identifiers
- Passport and driver's license
- Immigration records
- Property deeds and vehicle titles
- Wills, trusts, and powers of attorney
- Health directives
- Tax returns
- Professional licenses
- Military or benefits records
The inventory should point to the protected location. It should not become an unencrypted identity-theft package.
Photos, files, and creative work
Record:
- Cloud-storage providers
- Photo libraries
- Local drives and backups
- Domain names and websites
- Source-code repositories
- Published writing, videos, or music
- Monetized creator accounts
- Intellectual-property ownership
- Desired preservation or deletion instructions
Verify whether the provider's legacy feature includes the data you care about. Apple, for example, says Legacy Contacts can receive certain account data but cannot access iCloud Keychain passwords, passkeys, payment information, or purchased media. See Apple's Legacy Contact documentation.
Communications and social accounts
Include:
- Messaging apps
- Social-media profiles
- Community and forum accounts
- Personal email archives
- Professional networking profiles
- Dating accounts
- Gaming and virtual-world accounts
Specify whether each should be memorialized, archived, transferred where permitted, or deleted.
Facebook's legacy contact can manage limited parts of a memorialized profile; it does not simply become the deceased person's account. See Facebook's Legacy Contact help.
Business and professional continuity
Business accounts require a separate access plan because personal emergency access may expose client data to the wrong person.
Inventory:
- Domain registrar and DNS
- Hosting and cloud providers
- Source-code repositories
- Deployment systems
- Databases and backups
- Email and collaboration accounts
- Billing and payment processors
- Accounting and payroll
- Customer-support systems
- App-store accounts
- Code-signing and encryption keys
- Vendor contracts
- Client-owned credentials
Document ownership. A personal vault should not be the sole operational dependency for a company.
Subscriptions and recurring obligations
List services that continue charging or require cancellation:
- Streaming and software subscriptions
- Storage plans
- Memberships
- Donations
- Automatic deliveries
- Domains and certificates
- Business SaaS
- App-store subscriptions
Include the payment source and renewal timing without copying full card data into the inventory.
Build a usable record for each item
For every significant account, use fields like:
| Field | What to record |
|---|---|
| Service | Provider and account type |
| Identifier | Email, username, account number, or last four digits |
| Purpose | Why the account matters |
| Priority | Immediate, first month, later, or archive-only |
| Intended action | Maintain, transfer, archive, memorialize, or delete |
| Authorized person | Who should handle it |
| Legal authority | Will, trust, POA, business role, or provider designation |
| Access location | Where the approved recovery method or instructions are stored |
| MFA dependency | Phone, key, app, backup code, or passkey |
| Last verified | Date the information and provider process were checked |
Prioritize by urgency
First 24–72 hours
- Secure devices and the primary email
- Preserve MFA methods
- Prevent unauthorized access
- Identify urgent business and household operations
- Do not rush to delete accounts or devices
First month
- Maintain utilities and housing
- Notify appropriate financial and insurance institutions
- Preserve data and backups
- Cancel clearly unnecessary charges
- Establish lawful business continuity
Later administration
- Archive photos and creative work
- Memorialize or remove social profiles
- Transfer permitted digital property
- Close nonessential accounts
- Remove stale data after preservation decisions are complete
Store the plan safely
Use at least two layers:
- An inventory that identifies accounts and instructions but contains no reusable secrets.
- Protected recovery material stored separately—such as a sealed physical packet, attorney-held instructions, or another appropriate secure mechanism.
Tell the responsible person where both layers are and what authority is required. A secret nobody can find is not a recovery plan; a secret everyone can find is not secure.
The Revised Uniform Fiduciary Access to Digital Assets Act provides a legal framework adopted in many U.S. jurisdictions for fiduciary access to digital assets, but specific state law and provider terms control. Consult a qualified estate attorney for your situation.
Review schedule
Review the inventory:
- At least annually
- After changing password managers
- After changing primary email or phone
- After buying or selling a business
- After marriage, divorce, death, or estrangement
- After changing executors, trustees, or agents
- After acquiring significant digital assets
For provider-specific steps, see What Happens to Your Online Accounts When You Die?. For the division between tools and legal documents, see Password Manager vs. Digital Estate Plan.
The bottom line
Your family does not need a chaotic dump of every password. They need a prioritized map of essential accounts, protected access methods, lawful authority, and clear instructions.
Build the inventory so it remains useful even when a password changes—and protect it so losing one document does not expose your entire life.