Short answer: give every account a unique password stored in a password manager, turn on two-factor authentication with an authenticator app or passkey where the platform offers it, attach a recovery email you control and check, and save backup codes somewhere safe. Keep the farm Mac and phones locked down, because anyone who reaches them reaches every signed-in account.
Why farms need more care than one phone
A phone farm concentrates risk: many accounts, a few devices, often several people with access. A single leaked password, lost recovery email or shared login can take out more than one account. The fixes are ordinary, but they need to be done for every account, every time.
The basics, per account
| Control | What to do | Why |
|---|---|---|
| Unique password | Generated by a password manager | One leak doesn't spread |
| Two-factor authentication | Authenticator app or passkey where offered | Codes aren't tied to a SIM |
| Recovery email | An inbox you control and check | Recovery goes to you, not a stranger |
| Backup codes | Saved in the password manager | Works if the 2FA device is gone |
| Recovery phone | Only a number you'll keep | A lapsed number is a lockout |
| Account owner | The real business or creator | Access follows ownership |
What the platforms say, checked 17 September 2026:
- Instagram has a help article on using a third-party authentication app for login codes (Instagram Help).
- Google, which runs YouTube sign-in, lists passkeys, security keys, Google Authenticator and printable backup codes among its 2-Step Verification options (Google Account Help).
- TikTok offers security settings inside the app; check which verification methods it shows for your account and region.
Password managers and shared access
- One shared vault per client or brand, not one vault for everything.
- Give people access to the vault, not the password. When someone leaves, remove them and rotate what they could see.
- Store authenticator seeds or backup codes in the manager if your team needs shared 2FA; otherwise keep 2FA on the owner's device.
- Record where things are, not what they are, in your inventory sheet.
Recovery emails
- Use a domain or mailbox you control for the life of the account.
- Turn on 2FA on the email account too — it's the key to everything else.
- Check it. Platforms send security warnings there first.
- Don't use throwaway inboxes. When they vanish, so does recovery.
Securing the hardware
| Device | Control |
|---|---|
| Farm Mac | User password, FileVault, screen lock when you walk away |
| Remote access | Strong authentication, only the people who need it |
| iPhones | A passcode on every phone, stored in the password manager |
| iPhones | Farm phones are dedicated; no personal accounts on them |
| Room | Locked if others share the space |
Farm phones keep Auto-Lock off so the automation can run, which means the screen stays on. Physical access to the room is effectively access to the accounts.
What not to do
- Don't buy, sell or rent accounts. It breaches platform rules and you inherit someone else's recovery settings.
- Don't share one email or phone number across dozens of accounts.
- Don't paste passwords into chat or spreadsheets.
With Farmero
Farmero uses the sessions already signed in on each phone; it never asks for account passwords. Nothing leaves the Mac except clips (when a phone has no cable) and a licence check. Before it posts or warms, Farmero reads the profile header on screen to confirm it's on the right account. See add your accounts and what Farmero never does; phone setup is in the Mac setup guide. Remote access advice is in remote monitoring.
FAQ
What is the best 2FA for a phone farm?
An authenticator app or passkey, where the platform offers them, with backup codes saved in a password manager. SMS depends on keeping the number active.
Should every account have its own email?
Every account needs a recovery email you control and check. Avoid throwaway inboxes you might lose.
Can VAs have the passwords?
Give them access through a password manager rather than the passwords themselves, and remove access when they leave.
Does Farmero need my account passwords?
No. You sign in on the phone yourself, and Farmero uses that session.
