You Don't Need a Password Manager. You Need Three.
Congratulations, you’ve graduated from the sticky note on the monitor to a shared spreadsheet of passwords, or maybe even one shared password manager account for the whole team. That’s real progress. It’s also not done, and I say that as someone who has watched this exact setup fail in exactly the same way at more small businesses than I can count.
Here’s the uncomfortable truth: one shared vault, with one shared master password, that everyone on the team uses for everything, is not meaningfully more secure than the sticky note. You’ve just made the single point of failure harder to see.
The problem with one vault for everyone
When every login lives in one shared vault:
- Anyone with access to the vault has access to everything, whether they need the accounting login or not.
- When someone leaves the company, you either change the master password (and re-share it with everyone still there, which people hate enough that it quietly stops happening) or you leave a former employee with standing access to your bank feed.
- There’s no way to tell who actually used which credential, or when — which matters a great deal on the one day it turns out to matter.
None of this means “don’t use a password manager.” It means one vault is doing the job of three, and that’s the fix.
The three vaults that actually work
1. Personal vaults, per person. Every team member gets their own individual password manager account, for their own accounts — their email, their personal logins, anything that isn’t shared company access. This is the easy one; most good password managers (1Password and Bitwarden are both solid, reasonably priced choices) support this by default.
2. A shared team vault, scoped by role. Shared logins that a team genuinely needs — the social media account, the shared design tool, the office Wi-Fi — live in a shared vault, but access to that vault is granted per person and revoked the day someone leaves. This is the difference between “everyone has the master password” and “everyone has their own login, which grants them access to the vault, which can be individually turned off.”
3. A locked-down admin vault, for the keys to the kingdom. Domain registrar, DNS, hosting, banking, the accounts that could genuinely sink the business if compromised — these live in a smaller vault with the tightest access, ideally just the owner and one trusted second person, with two-factor authentication required and no exceptions. This is your break-glass vault. It should be boring, rarely touched, and extremely hard to get into.
Why the separation matters more than the tool
The specific software you pick matters far less than this structure. A $3-a-month password manager used with three properly scoped vaults beats an expensive enterprise tool used as one giant shared bucket, every time. The goal isn’t a fancier lock — it’s making sure that no single leaked password, and no single departing employee, has a blast radius bigger than it needs to.
Set this up once, and it runs itself. It’s a couple of hours of work that quietly removes one of the most common ways small businesses actually get burned.
Team credentials still living in a spreadsheet, or one shared login everyone knows? This is a quick, high-impact fix — get in touch and I'll help you set up the structure properly.