Week 05 · lesson

Protect the Account, Protect the Team

Receive: An Account Is Part of the Equipment

A team account is not just a profile. It may hold a roster, tournament registration, saved work, purchases, team messages, and access to a stream or bracket. Losing it can interrupt everyone else’s work. That is why a password passed around in chat is not teamwork. It is a single point of failure with emojis.

Learning target: I can explain how an account is protected, recognize a suspicious request, and choose a safe handoff instead of trying to solve an access problem alone.

Process: Separate Access From Trust

Authentication is how a service checks that the person signing in is allowed to use an account. A strong setup uses a unique password and multi-factor authentication (MFA), which adds a second proof such as an authenticator prompt or security key. The second proof is useful only when its code stays private. No teammate, organizer, friend, or “support agent” needs your code.

ClaimWhat is actually true
“We all need the password so somebody can help.”The team needs an adult-approved ownership and access process, not shared credentials.
“The message has the event logo, so it must be real.”Logos can be copied. Use the organizer’s official site or a verified school contact path.
“I changed the password, so the problem is solved.”Review recovery email, active sessions, MFA, and tell the account owner or advisor.

Useful words: credential means a password, code, or other sign-in proof; phishing is a message designed to trick someone into giving up access; recovery method is the approved way to regain access; and least access means each person receives only the access their role actually needs.

Practice: Trace the Message

Read this message: “Tournament verification expires in ten minutes. Send the code from your phone or your team loses its slot.”

Before choosing an action, answer three questions:

  1. What is the message asking the student to reveal?
  2. What pressure tactic is it using?
  3. What official source could verify whether the request is real?

The safe answer is not to click, reply, or forward a code. Open a new browser tab, find the event’s official site independently, and show the message to the advisor or approved account owner. Urgency is not evidence.

Apply: Build an Account-Safety Card

Create a one-page card for one school esports account. Do not write a real password, recovery answer, or personal contact information on the card.

ItemSafe plan
Account purposeWhat team work does this account support?
Approved ownerWhich adult or school-approved role owns recovery decisions?
Access boundaryWho needs access, and what should never be shared?
Verification routeWhere will the team independently verify event messages?
Suspicious-message responseWhat is the first safe action and who receives the handoff?

Correct: Check the Decision

Your plan is strong when it does all four things: it keeps credentials out of messages and documents; it names a responsible owner; it verifies through an independently located official source; and it gives students a handoff path. “Ask the group chat” does not meet the last requirement.

Prove: Exit Evidence

In four sentences, explain why a team should not share MFA codes. Include one suspicious-message signal, one verification step, and the person or role who should receive a concern.

Takeaway

Secure access is not secrecy between teammates. It is a clear, limited process that keeps one mistake from becoming a team-wide problem.