Outsourcing Assistant guide

Secure onboarding for a Filipino virtual assistant

A practical plan for giving a Filipino virtual assistant the access needed to work without handing over every account on day one. It covers task scope, login rules, approval lines, review, and a clean exit plan.

Key takeaway: A secure handoff is not a pile of passwords. Give the assistant a narrow work lane, a separate account, clear approval rules, and a short review cycle before you expand access.
193,407phishing or spoofing complaintsReported to FBI IC3 in 2024.21,442business email compromise complaintsReported to FBI IC3 in 2024.$2.77Breported business email compromise lossesFBI IC3 total for 2024; rounded here from $2,770,151,146.

Start before the first login

Write down what the Filipino virtual assistant will do during the first ten business days. Name the inboxes, calendars, folders, customer records, and reports involved, then mark which actions need approval. This stops a common mistake: giving broad access because the task list is still vague.

The location of the assistant does not change the owner's duty to control business data. A Philippines-based assistant may work while the owner sleeps, so the handoff must say who can answer an urgent question and what must wait. If nobody is available, the safe default is to save a draft and leave a note for review.

Map the work and the data

Take one recurring task, such as inbox triage, and trace it from start to finish. The assistant may need to read new messages, apply labels, draft routine replies, and list items that need the owner. That does not mean the assistant needs access to private legal threads, banking notices, password resets, or every old message in the account.

Use four labels for each step: view, draft, send, and approve. Most new assistant work should begin in the first two labels. The owner or a named manager keeps the last two for refunds, contract language, changes to account ownership, money movement, and promises that could bind the business.

First-access map for a new Filipino virtual assistant
Work areaGood starting accessOwner keepsProof to review
InboxLabels and reply draftsSensitive threads, final sends, forwarding rulesDraft sample and exception log
CalendarView and draft invitesPriority moves and private eventsConflict list before changes
CRMAssigned records and notesExports, deletions, field rulesChanged-record report
Cloud filesOne work folderBilling, legal, payroll, and master foldersShared-link and activity check
Support deskRoutine draft queueRefunds, credits, and policy exceptionsTicket sample with manager notes

Use a simple access ladder

Create a separate user account whenever the tool allows it. Turn on multi-factor authentication, keep recovery methods with the business, and grant only the folder, queue, or calendar the assistant needs. Shared owner passwords make it hard to see who changed a record and hard to remove access later.

Start with read-only or draft access, then review a real sample. Expand one permission at a time after the assistant follows the checklist and asks about exceptions instead of guessing. Record every change in a small access log with the tool, permission, approver, date granted, and date to review.

Protect inbox and message work

The FBI's 2024 Internet Crime Report recorded 193,407 phishing or spoofing complaints. It also recorded 21,442 business email compromise complaints and $2,770,151,146 in reported losses tied to that crime type. These are complaint figures, not a prediction of what will happen to one business, but they show why an assistant needs a written rule for payment changes and urgent requests.

Tell the assistant to verify any request that changes bank details, login methods, account owners, or delivery instructions through a second channel already on file. A reply to the same email thread is not a second check. The assistant should pause the task, capture the request, and contact the named owner through the approved chat, phone number, or ticket queue.

Two email-linked complaint categories in the 2024 IC3 reportHorizontal bars compare complaint counts for phishing or spoofing and business email compromise.2024 FBI IC3 complaint countsPhishing / spoofing193,407 complaintsBusiness email compromise21,442 complaintsUnit: complaints received by FBI IC3
Two email-linked complaint categories in the 2024 IC3 report. Units are complaints received by FBI IC3 in 2024. The bars use the larger category as 100%; these are reported crime categories, not a risk forecast for one company.

The CSF has been a vital tool for many organizations, helping them anticipate and deal with cybersecurity threats.

Laurie E. Locascio, Under Secretary of Commerce for Standards and Technology and NIST Director. Read the source.

Write rules for a Philippines-based schedule

Set a clear work window in Philippine Time and write the matching owner-review window beside it. Do not make the assistant guess whether a late-night message is urgent. Define urgency with examples, such as a locked customer account or a same-day calendar conflict, and give one escalation route for those cases.

Keep normal work in a queue that the next person can read. A short end-of-shift note should list completed items, drafts waiting for approval, blocked work, and unusual requests. This gives the owner a useful morning review and gives the assistant a clean place to continue during the next Philippine shift.

Run a ten-day launch

On days one and two, show the assistant the task and let the assistant watch a real example. On days three through five, the assistant completes a small batch in draft mode while the manager checks each result. Fix the checklist when the same question appears twice, because the missing detail belongs in the process rather than in somebody's memory.

During the second week, sample the work instead of checking every simple item. Keep full review for exceptions, sensitive messages, new contacts, and account changes. At the end of day ten, decide which permission can stay, which can grow, and which should be removed because the task never needed it.

The four-step access ladderA separate process graphic showing how a manager can expand access after review.A controlled access path1. View
See only the records needed for one task.
2. Draft
Prepare work without sending or changing ownership.
3. Act
Complete approved routine actions after review.
4. Review
Keep, narrow, or remove access using real work evidence.
Manager rule: expand one permission only after a reviewed work sample.
The four-step access ladder. A separate process graphic showing how a manager can expand access after review.

Review the lane, not just the person

Track a few facts that the manager can verify: work completed, items returned for correction, exceptions raised, and approvals requested before action. A mistake may point to weak training, a missing example, or access that is too broad. Fix the source of the problem before blaming speed or effort.

NIST released Cybersecurity Framework 2.0 on February 26, 2024, with a new focus on governance for organizations of every size. That fits a small assistant lane well: the owner names the rules, the assistant follows them, and both sides know how a concern gets reported. The framework does not replace legal advice, but it gives a useful structure for deciding who owns each risk.

Plan the exit on day one

Keep a list of every account, shared folder, forwarding rule, API token, device, and group the assistant can use. When the role ends or changes, disable the separate account, revoke active sessions, rotate any secret that had to be shared, and transfer open work to the named manager. Do this promptly rather than waiting for the next monthly review.

Check mailbox rules, recovery contacts, shared links, and calendar delegates after access is removed. Save the final handoff note with unfinished work and the owner for each item. A calm exit is easier when the access log and task queue were kept current from the first week.

Keep planning the handoff

Questions people ask

Should a Filipino virtual assistant use the owner password?

No. Create a separate user or delegated account when the tool supports it. The business should keep recovery methods and owner-level settings.

What access should the assistant get first?

Begin with the smallest view or draft permission that supports one real task. Expand access only after the first work sample passes review.

Can the assistant send email on day one?

Start with drafts for routine replies and a clear exception list. Direct sending can come later for approved message types after the manager has checked the work.

How should the team handle time-zone gaps?

Use one written escalation route and an end-of-shift note. Anything outside the urgent examples should wait in the approval queue.

What should happen when the role ends?

Disable the separate account, revoke sessions, check forwarding and recovery settings, rotate shared secrets, and transfer open tasks to a named owner. Record each action in the access log.

Sources

The figures and guidance above come from the original publishers. Each note says how the source was used.

  1. FBI Internet Crime Complaint Center, 2024 IC3 Annual ReportComplaint counts and reported loss figures used in the data cards and chart.
  2. NIST, Cybersecurity Framework 2.0 release, February 26, 2024Governance context and the exact Laurie E. Locascio quote.
  3. NIST SP 800-53 Revision 5, Update 1Primary guidance for access control, account management, and security review.
  4. CISA Secure Our World: Use Strong PasswordsPlain guidance for unique passwords, password managers, and safer account setup.
  5. IT and Business Process Association of the PhilippinesPhilippine IT-BPM industry context; the site reports a 1.9 million talent workforce and $40 billion in revenue.
OA-SECURE-ONBOARDING-2026