Sending a password by email, text or chat creates a copy that can be forwarded, searched or left behind. A shared spreadsheet has the same problem. It also becomes difficult to remove access when someone changes roles or leaves.
A business password manager is usually a safer option. It stores work passwords in a protected vault and lets the business control who can use each login.
What a business password manager should do
Keep work passwords in one managed place
Staff should not have to remember dozens of passwords or save them in notebooks and shared files. A password manager can create and store a different password for every account while the business retains control of shared work logins.
Review the provider's current security information and make sure the product is intended for business use. Each employee still needs their own account, a strong main password and multi-factor authentication.
Share access without sending the password in a message
A business vault can give selected staff access to a login without copying it into email or chat. Some products can also hide the password characters, although this does not guarantee that a user can never recover or copy the password.
Use the product's permission settings and test how sharing works before relying on that feature.
Give each person their own account
Do not have the whole team sign in to the password manager with one shared account. Individual accounts make it easier to remove access and review who used a shared login.
When an employee leaves, disable their password manager account and rotate any important passwords they could view or copy.
Create unique passwords and keep useful records
Use the built-in generator to create a long, different password for each service. Check whether the chosen product records access or changes to shared items and how long it keeps those records.
Give contractors access only to the accounts needed for their work. Set an end date where the product allows it, then remove access when the job is finished.
A password manager is only part of the answer
Use multi-factor authentication on the password manager and on important business accounts. Limit administrator access, keep recovery details current and review shared items regularly.
Where a service supports separate user accounts, use them instead of sharing one password. Separate accounts provide clearer access control and make offboarding easier.
Still sharing passwords in email or a spreadsheet? Ask JCPIT about a password-sharing review. We will confirm the scope and access before reviewing the current process or planning a move to individually controlled accounts and an appropriate password manager.