Password Managers for Small Companies
By CodexierPublished 4 min read
Most small companies have one: a spreadsheet, a note or a shared document with the logins for the website, the webshop, social media, the bank and the accounting system. It works until a laptop is stolen, an email account is phished or an employee leaves on bad terms. A business password manager replaces it with shared vaults, access by role and a clean way to remove access. This guide shows how to set one up.
Why the password spreadsheet is a risk
- Anyone who opens the file sees every password, with no record of who looked.
- The file is copied to laptops, email attachments and phones, and each copy is a new leak point.
- Passwords are reused, because inventing and typing unique ones is tedious.
- When someone leaves, nobody knows which passwords they saw, so nothing gets changed.
- If the email account holding the file is phished, the attacker gets everything at once.
Business password managers
Business versions of well-known password managers add what a company needs on top of the personal product: central administration, shared vaults, access policies, audit logs and recovery if someone forgets their master password. The main options are similar in capability; choose on usability for your team and the features below.
| Feature | Why it matters |
|---|---|
| Shared vaults with permissions | Teams see only the logins they need |
| Admin recovery | The company is not locked out if a person forgets or leaves |
| Audit log | Shows who accessed or changed a shared login |
| Browser extension and mobile app | People use it only if filling in passwords is easier than typing them |
| Storage of two-factor codes or passkeys | Shared accounts can use two-factor without one person's phone |
| EU data options and end-to-end encryption | The provider cannot read your vault, and data handling fits GDPR |
Shared vaults and roles
Management
Bank, domain registrar, hosting and admin accounts. Owners only.
Marketing
Social media, Google Business Profile, ads accounts and the newsletter tool.
Operations
Webshop admin, booking system, suppliers' portals and shipping tools.
Finance
Accounting system, payment providers such as Klarna and Swish admin, and expense tools.
Personal logins such as BankID stay personal and never go into a shared vault. Where a service allows several users, give each person their own login instead of sharing one; it makes offboarding and auditing far easier.
Onboarding and offboarding
- New employee: create their account, add them to the vaults their role needs, and show them the browser extension on day one.
- Role change: move vault membership rather than adding more.
- Leaver: remove their account the same day they leave.
- Then change the passwords in every shared vault they could access, starting with the most critical.
- Check the audit log for unusual activity in the weeks before they left.
Integrations often use keys that sit in the same vault. Our guide to documenting integrations covers how to handle those when a developer leaves.
Combining with two-factor
A password manager protects passwords; two-factor authentication protects the account even if a password leaks. Use both. Protect the password manager itself with a strong master password and an authenticator app or security key. Then turn on two-factor for email, the website admin, the webshop, the domain registrar and financial services. Our guide on two-factor authentication everywhere goes through the order.
When you do not need outside help: a small team can set up a business password manager in an afternoon following the steps above. If you also want the website, hosting and admin accounts hardened at the same time, our performance and security optimisation covers that; see the pricing page or book a short call.
Frequently asked questions
Is it safe to put all passwords in one place?
A good password manager encrypts the vault so that only your people can decrypt it, and it is protected by a master password plus two-factor. That is far safer than a spreadsheet, and safer than reused passwords spread across services.
Can we use the browser's built-in password saving?
For personal use it is better than nothing. For a company it lacks shared vaults, role-based access, admin recovery and audit logs, which are exactly what you need when people join and leave.
What about passkeys?
Passkeys replace passwords with a cryptographic key and resist phishing well. Many business password managers can store and share passkeys, so adopting them fits into the same setup.
Does NIS2 require a password manager?
NIS2 and the Swedish cybersecurity act require covered organisations to manage access and authentication properly, without naming a specific tool. Most small companies are not directly covered, but customers may ask about it.
Check your company's access setup
Tell us how passwords and admin accounts are handled today. In 15 minutes we will list the most urgent fixes.
Book a free 15-minute call