← All articles

Rolling out a password manager without a revolt

·2 min read·By Adrian

Also available in ES, RO

Every company has a place where passwords are kept. Often it is a spreadsheet, sometimes a notebook, occasionally a chat message from three years ago. People are not being careless; they were given a problem and no tool.

What a manager actually solves

  • Unique passwords everywhere, so one leak does not cascade
  • Credentials shared without being sent over chat or email
  • Access removed instantly when someone leaves
  • A record of which systems exist and who can reach them
  • Phishing resistance, because the manager will not autofill on a lookalike domain

That last point is underrated and entirely automatic.

Choosing one

The differences that matter for a business:

  • Shared vaults per team, so finance and operations do not see each other's credentials
  • Single sign-on and directory sync, so leavers are removed in one action
  • Recovery for the administrator, tested before you need it
  • Audit logging, so access can be reviewed
  • Zero-knowledge architecture, so the vendor cannot read your vaults

Rolling it out

The technical work is an afternoon. Adoption is the project.

  1. Start with the IT team, for a fortnight, until the workflows are familiar
  2. Move to one willing department and fix the friction they find
  3. Import the existing spreadsheet with them, not for them — that session is where the value becomes obvious
  4. Roll out department by department, with someone present on day one
  5. Delete the spreadsheet, verifiably, once the last credential has moved

The rule that makes it stick

New credentials go straight into the manager. No exceptions, from the first day. A manager that holds ninety percent of your credentials while the spreadsheet holds the rest has not replaced anything.

Do not forget the accounts nobody owns

The domain registrar. The certificate provider. The bank portal. The social accounts. These are usually held by one person, undocumented, and are the ones that hurt most when that person is unreachable. They belong in a shared vault with at least two people holding access.

We include this in IT consulting engagements.

← Blog