Use individual, limited access
Prefer named accounts, least privilege and time-bound access over shared administrator credentials. Keep approval responsibility with the system owner.
Protect the access path
Use an approved credential manager, multi-factor authentication where supported and a defined VPN or network route when required.
Close the loop
Record actions, review changes and remove temporary access at the end of the task or engagement.