Do you need software for this?

Yes. This is one of the few places on this site where the answer is unqualified, because the alternatives — a shared document, a browser, memory — fail in ways that are expensive and hard to detect. For another perspective on the same kind of decision, Monitask covers the topic in this explanation.

Passwords for a Small Team

No affiliate links on this site, and nothing here is ranked.

Why this one is different

Most of this site argues that the smaller option is usually adequate. Here the smaller options fail at the thing that matters.

A shared document holding credentials is readable by anybody with access to the drive, copied when it is downloaded, and impossible to revoke — and it leaves with whoever had a copy.

Individual browser storage works for one person and provides no way to share, no way to remove access, and no record of who has what.

And memory produces reused passwords, which is the failure mode that converts one compromised service into all of them.

What the task actually requires

Storage that is encrypted and that the provider cannot read.

Sharing without copying — somebody gets access to an entry rather than a copy of it, so that removal is possible.

Removal that works. When somebody leaves, access ends. This is the requirement a document cannot meet at all.

A record of what exists. Which services the business has accounts with, which is separately valuable — most firms cannot list them.

And recovery. What happens when the person who set it up is unavailable.

What to check

Whether the provider can read your data. The answer should be no, by design, and the mechanism should be documented.

What happens if you lose the master credential. Recovery arrangements differ substantially and this is the question people discover the answer to at the worst moment.

Emergency access. A way for somebody else to get in if you are unavailable, with a delay and a notification — which matters more in a small firm than in a large one, because there is no IT department to fall back on.

Export. Credentials are the data you least want locked into one provider, and a documented export is not optional here.

And what happens when a subscription lapses. Read-only, locked, or exported — the difference is whether a missed payment costs you access to everything.

What it does not solve

Weak passwords you choose yourself. The tool generates good ones; it cannot stop somebody using a memorable one for the important account.

Accounts nobody put in it. A vault holding half the credentials is the same partial-adoption failure as anywhere else, with worse consequences.

And the second factor, which is a separate control and the one that actually stops most account takeovers. A password manager plus reused second factors is a partial answer.

Setting it up so it holds

Put everything in it, including the things that feel too minor. The forgotten account is the one that gets compromised.

Share by group rather than individually, so that removing somebody is one action rather than twelve.

Record the recovery arrangement somewhere physical — a sealed envelope, a safe — because a digital record of how to recover digital access is circular.

And review access when anybody's role changes, not only when they leave. It is the same quarterly habit as the bill.

The inventory you get for free

A side effect worth the subscription on its own.

Filling a password manager produces a list of every service the business has an account with — which is the thing nobody can otherwise produce and which is the starting point for reading the bill.

Most firms doing this for the first time find accounts they had forgotten, including several that are still charging.

Do the two exercises together. The vault fill and the subscription review answer each other's questions, and the combined afternoon is the single most useful administrative day available to a small firm.

Shared logins, which should mostly not exist

Where several people use one account, the record of who did what is gone.

Sometimes unavoidable — a supplier portal with one seat, a legacy service — and where it is, note who has it and treat a departure as a password change rather than a removal.

Where the service supports separate users, use them, even at extra cost. The cost buys attribution, and attribution is what makes a mistake findable and a dispute resolvable.

The browser question

Browser password storage has improved and it is not the same product.

It handles one person's logins competently. It does not share, does not revoke, and does not produce an inventory — which are three of the five requirements above.

For a sole trader with no sharing requirement, it is arguably adequate, provided the account it syncs to is itself protected properly. For anybody with a second person, it is not.

Cost, in proportion

Among the cheapest per-seat tools a business buys, and one of very few where the paid tier is worth taking immediately rather than waiting until a free limit gets in the way.

The free tiers in this category are genuinely capable for one person and commonly limit sharing, which is the feature a team needs. That is a funnel, and it is an honest one because the limit is exactly the feature. For another point of comparison, consult Todoist.

The short version

  • This is one of the few categories where the paid tool is the immediate answer, because the alternatives fail expensively and invisibly
  • A shared document cannot revoke access, browser storage cannot share, and memory produces reuse
  • The task needs encryption the provider cannot read, sharing without copying, working removal, an inventory, and recovery
  • Check the recovery arrangement, emergency access, export, and what happens if the subscription lapses
  • It does not solve weak choices, accounts nobody added, or the second factor, which is what actually stops takeovers
  • Put everything in it, share by group, keep the recovery arrangement physical, and review access when roles change