← Back to stories
Technology

Shared passwords in a team: why a password manager beats a forwarded message

A password pasted into a chat stays there forever. Here is how to grant and revoke access without rotating every credential.

CreativeMedia2 min read
Администратор настраивает общий доступ к рабочим аккаунтам через менеджер паролей.

A new hire needs access to the ad account, and someone drops the login and password into the team chat. Six months later that person leaves, and the password is still sitting in the chat history, visible to people who no longer work with you.

Keep credentials in one place

Set up a shared vault in a password manager and move every work account into it: social networks, hosting, the domain, ad accounts. A password in a chat, spreadsheet or note can't be revoked, because everyone who saw it keeps a copy. In a vault, access is granted to a person and removed in one step.

Split access by role

Not everyone needs everything. An intern may only need the social accounts, while the domain and billing belong to one or two people. Where a service allows it, create separate user accounts instead of one shared login, so you can see who changed what.

Turn on a second factor and name an owner

For critical services, enable two-factor authentication and check whose phone receives the codes. If it's the personal number of someone who has left, you lose access along with them. Assign one person to look after the vault and review who has access to what once a quarter. When someone leaves, rotate only the passwords they could reach rather than everything.