Password management
Credentials shared without a spreadsheet.
Nothing matches that yet
Try a broader category, or add the product you were looking for.
Add a productWhat this category covers
Storing credentials so that people stop keeping them in a spreadsheet: personal vaults, shared team vaults, secrets used by applications and the recovery arrangements around all of it.
Two audiences buy from this shelf. Individuals want convenience and safety. Organisations want sharing, provisioning, revocation and evidence, which is a different product with the same core.
Broader access control and monitoring sits in security. Compliance evidence belongs in compliance and GRC.
Why the spreadsheet has to go
Shared credentials in a document have four problems that no amount of care removes.
Everyone who ever had access still has it, including people who left. Nobody knows which passwords are reused elsewhere. Changing one means telling everybody. And there is no record of who opened what, which is the first question asked after an incident.
A password manager fixes all four by making sharing a controlled action rather than a copy. That is the actual purchase, not the convenience of automatic filling.
How the encryption is meant to work
The claim worth checking is that the vendor cannot read your vault.
In a well-designed product, encryption and decryption happen on your device and the vendor stores material it cannot open. That has a consequence people discover late: losing the master credential can mean losing the vault permanently, which is why recovery design matters as much as encryption.
Look at what recovery exists. Business plans usually offer administrator-assisted recovery or an emergency contact. Ask how that works, since a recovery route that lets an administrator read every vault is a different security model from one that does not.
Independent audits and published architecture are worth more than a page of reassuring adjectives. Ask when the last one was and whether the report is readable.
What a team actually needs
- Shared vaults by team or project, with access granted per group.
- Provisioning, so joining and leaving are automatic rather than remembered.
- Revocation that removes access immediately, not at next login.
- Audit logs showing who accessed which item and when.
- Secrets for applications, kept out of code and rotated without downtime.
Offboarding is the requirement most often underestimated. Access left behind after someone leaves is the standard finding in a first security review, and it is exactly what this category is meant to prevent.
Adoption is the hard part
A vault nobody uses is a spreadsheet with extra steps.
The deciding factors are ordinary: whether autofill works reliably on the sites and applications your staff use, whether the phone experience is tolerable, and whether saving a new credential takes one action. Where any of those fails, people revert to reusing a password they can remember.
Browser extensions are the main point of contact and vary in quality. Test yours on the awkward cases: an application with an unusual login form, a site that logs you out constantly, and a shared account used by four people at once.
Beyond passwords
Two developments change what this software is for.
Passkeys remove the password for services that support them, and the better managers now store and sync them across devices. That list is growing, and support is worth checking rather than assuming.
Application secrets are the other direction. Keys, tokens and certificates used by systems rather than people need rotation, scoped access and an audit trail, and several products in this category now cover both worlds. Pricing runs per user per month with business features setting the tier, alongside the usual habits described in what pricing pages hide.
Rolling out a vault to a team
The migration is straightforward and the habit change is not, so plan for the second.
Start with the shared credentials that already worry you: administrative accounts, supplier portals, anything currently in a document. Moving those first delivers visible value and removes the worst exposure.
Then bring people across individually, with a short session rather than an email. Most resistance comes from autofill behaving differently rather than from any objection in principle.
Give staff a free family or personal plan where the vendor offers one. Credential reuse between work and home is a genuine risk, and the cheapest way to reduce it is to make the safe option available everywhere.
Finish by turning off the old routes. A shared document left in place will still be used by somebody six months later.
Questions people ask
- Is a password manager safer than a browser?
- Yes for shared and business use. Browser storage is convenient, tied to one profile, and has no concept of team sharing, recovery or audit, which is what an organisation actually needs.
- What happens if we lose the master password?
- That depends on the recovery design. Business products offer administrator recovery or emergency access. Personal ones frequently offer nothing, and the vault is unrecoverable by design.
- Should we self-host the vault?
- Only with the skill to run it properly. Self-hosting removes vendor risk and adds availability risk, since a vault nobody can reach during an incident is its own kind of failure.
- Do we still need passwords with single sign-on?
- Yes. Single sign-on covers the applications that support it, and every organisation has a list that does not: legacy systems, shared accounts, hardware panels and supplier portals.
- How is this priced?
- Per user per month, cheaper for personal and family plans, with business tiers adding shared vaults, provisioning and reporting. Free accounts for staff at home are a common and worthwhile inclusion.