How we work 5 min read security backups

A password manager for your business: why a shared spreadsheet isn't a system

Passwords are the keys to your entire business: to email, the bank, the register, the accounting system, the website and the social media accounts. It's strange, then, how casually they're usually kept. One password is on a sticky note under the keyboard. Another one "the browser remembered." A third lives in a shared spreadsheet on the drive that half the office can open. A fourth is known to one person only, and while they're on vacation, no one can use it.

Every one of these feels convenient right up until the first time it lets you down. Here's why not to do it that way — and what a proper team password manager looks like when we're the ones responsible for the secrets.

A shared spreadsheet is a hole, not a vault

The most common "password manager" in a small business is a file with columns — service, login, password — sitting somewhere on a shared drive. The problem isn't that it's inconvenient. The problem is that it leaks from several directions at once.

A file like that can't be taken back. Give the bookkeeper access and they see every password, including the ones that are none of their business. A manager leaves — and a copy of the spreadsheet stays behind in their email or their downloads, and you never even find out. There's no log: who looked at which password, and when, is anyone's guess. There's no history: someone accidentally deletes a row, and the password is gone for good.

Browser passwords aren't much better. They're tied to a single account, synced through a cloud you don't control, and handed to anyone who sits at an unlocked computer for a second. Convenient — yes. But here the convenience works against you.

Every client gets their own separate vault

We do it differently. Every client gets their own password manager — separate, isolated from everyone else's, on a server under our care, hosted in Europe. Not a shared "everyone's" account where your secrets sit next to strangers', but your own space, and the keys to it are yours.

Inside, the secrets are organized by folders and teams: accounting sees the accounting ones, the warehouse sees the warehouse ones, the director sees everything. Each employee gets their own login, not one "spreadsheet password" for the whole office. And every access leaves a trace: you can see who used what, and when.

Technically it's the open-source Vaultwarden — the same engine behind Bitwarden, the one the familiar apps on your phone, in your browser and on your computer already work with. There's no new interface to learn: it looks and works like a password manager you may have used at home before — only under your control, not in someone else's cloud. And the vault itself is encrypted and backed up — like all the data we're responsible for.

The second lock — inside, not next to it

A password is only the first lock. The second is one-time codes (people call them 2FA or TOTP): those six-digit numbers that refresh every thirty seconds. They're often kept in a separate app on one person's phone — and when that phone goes missing or dies at the wrong moment, no one can get into an important service.

We keep those codes right next to the passwords, in the same protected vault. Then access doesn't hang on one person's single device: if it comes to it, a colleague with the right permissions can step in — no panic, no "where's that phone now" — though it's fair to say plainly that keeping both factors in one place means a compromised vault costs you both, which is exactly why that vault's own password has to be the strongest one you own.

What rollout looks like

Getting started isn't dramatic or drawn-out:

  • first we gather all the secrets scattered across spreadsheets, browsers and sticky notes into one place;
  • we structure them by department and set who is allowed to see what;
  • we give each employee their own login and, where needed, turn on one-time codes;
  • we show the team how to use it — that's fifteen minutes, not a day-long training;
  • we hand you the administrative keys, so the master access sits with you, not "somewhere at a contractor's."

After that the old password spreadsheet gets deleted — not tucked into an archive, deleted — because it's no longer needed, and keeping it around is dangerous.

The best test is when someone leaves

The real value of a vault like this shows not day to day, but on the day someone quits. In the world of the shared spreadsheet, a resignation means a frantic scramble to reset a dozen passwords, hoping none were missed. In the world of a proper manager it's one calm step: you close the person's access — and every secret is instantly out of their reach, with no mass password reset to do.

A password only one person knows isn't security. It's a hostage.

The same tool, by the way, holds our own secrets too. We don't recommend anything to clients that we don't use ourselves.

Three questions for your own IT

You don't have to work with us to get your passwords in order. Just ask whoever's responsible for your IT three questions:

  1. Where exactly are the passwords to our services kept — and are they in a shared spreadsheet that could be quietly copied?
  2. What happens to access when a key employee resigns tomorrow?
  3. Can you see who used a specific password, and when?

If the answers are calm and specific — great. If not, start with a free audit: we'll look together at where the keys to your business are kept right now, and tell you honestly what's worth changing. Managing secrets is part of our Shield, but you can put this one area in order on its own, too.

Need help with your IT?

A free audit of your infrastructure — we find the weak spots and show an honest plan. No strings attached.

Free audit