Diagnostic brief · evidence partial
Should a five-person business move shared logins into a team vault?
Start with who must reach each account and what happens when they leave, before comparing any password-manager product.
Direct answer
Consider a managed team vault only as one part of an access plan. Do not adopt one until every shared account is named, an owner exists for each, and the exit of one person can be reversed without a hunt for a lost spreadsheet.
- partial
A public authority frames the choice as an organisational policy decision that depends on how people actually work, not as a product feature contest.
NCSC-PASSWORD-MANAGER-BUYERS-GUIDE · Password manager buyers guide · external-ncsc-password-manager-buyers-guide
The real decision
The decision is not which vault to buy. It is whether the business will keep proving who was allowed to reach an account, and after this change whether that proof still exists when someone leaves or loses a device.
- partial
Reported breach prevalence is measured against all businesses, so it establishes that the exposure is common rather than that a particular team is exposed.
UK-DSIT-CSBS-20252026 · Cyber Security Breaches Survey 2025 to 2026 · external-uk-dsit-csbs-20252026
Who this is for
An owner or operations lead who is also a user, holds no separate administrator role, and shares logins for banking, hosting, marketing platforms, and suppliers with four other people.
- partial
The published guidance is written for system owners setting policy and names large organisations and public sector readers, so a team without an administrator must translate rather than inherit it.
NCSC-PASSWORD-ADMIN-COLLECTION · Password administration for system owners · external-ncsc-password-administration-collection; NCSC-PASSWORD-MANAGER-BUYERS-GUIDE · Password manager buyers guide · external-ncsc-password-manager-buyers-guide
Why it matters now
Two things can be true at once: most businesses have a written rule about passwords, and far fewer enforce a second step. A rule that is not enforced is the gap the decision has to close.
- validated
In the 2025 to 2026 survey 74% of businesses reported a password policy while 47% required two-factor authentication, and two-factor use among micro businesses rose from 35% to 43%.
UK-DSIT-CSBS-20252026 · Cyber Security Breaches Survey 2025 to 2026 · external-uk-dsit-csbs-20252026
Map what is shared today
List every account more than one person can reach, the path each person uses to find its secret, and where a copy survives the change. Browser autofill, a shared document, a notes app, and a password reset email are all copies.
- validated
The authority describes password reuse and other insecure workarounds as the predictable response to password overload, which is the behaviour the spreadsheet is currently absorbing.
NCSC-PASSWORD-MANAGER-BUYERS-GUIDE · Password manager buyers guide · external-ncsc-password-manager-buyers-guide
Name an owner per account
Assign one accountable person to each account before migration. Ownership decides who may grant, change, and revoke access, and it survives the tool. Without it a vault becomes a shared spreadsheet with better typography.
- partial
Vendor documentation describes organisation-owned vaults whose items are shared to members and administered from a console, which is the capability that makes revocation possible in principle.
BW-ORGANIZATIONS-DOCS · Get to know your organization · external-bitwarden-organizations-docs
Test the controls, not the marketing
Prove four things on one low-stakes account: a member can be removed and loses access immediately, a secret can be recovered when its holder is absent, an admin can see who reached what, and the vault itself cannot be unlocked from a lost laptop alone.
- validated
The same guidance warns that a manager is a natural target because one successful attack can expose every stored password, so the master secret and the device are part of the test.
NCSC-PASSWORD-MANAGER-BUYERS-GUIDE · Password manager buyers guide · external-ncsc-password-manager-buyers-guide
Keep a person accountable
Someone must own the exception list. Where an account cannot be vaulted, or shared access cannot be revoked, that fact needs a named decision-maker and a date, not a silent workaround.
- validated
The authority recommends periodic review of how the product is actually used after implementation, precisely because benefit is lost if people stop using it.
NCSC-PASSWORD-MANAGER-BUYERS-GUIDE · Password manager buyers guide · external-ncsc-password-manager-buyers-guide
Make the trade-offs visible
Choosing speed of adoption over control concentrates risk in one master secret. Choosing per-person accounts over shared logins may require vendor support you do not yet have. Choosing a cloud-sync vault over an on-device one trades device isolation for access from several devices.
- validated
On-device managers are described as unsuitable where the same service must be reached from several devices, while cloud-sync managers add considerations for data in transit and remote account compromise.
NCSC-PASSWORD-MANAGER-BUYERS-GUIDE · Password manager buyers guide · external-ncsc-password-manager-buyers-guide
The advice is moving under the decision
A vault is a bridge, not a destination. The authority that publishes the buyers guide now states that passwords lack relative resilience and that passkeys should be the default where offered, which changes the order in which accounts should be fixed.
- validated
In April 2026 the same technical authority said it no longer recommends passwords where passkeys are available, addressing consumers and digital services rather than team ownership of shared business accounts.
NCSC-PASSKEYS-2026 · Leave passwords in the past - passkeys are the future · external-ncsc-passkeys-2026 - conflicting
The two positions are not merged here: the newer statement is about individual sign-in and the older guidance is about organisational credential policy, so the tension is disclosed rather than resolved.
NCSC-PASSKEYS-2026 · Leave passwords in the past - passkeys are the future · external-ncsc-passkeys-2026; NCSC-PASSWORD-ADMIN-COLLECTION · Password administration for system owners · external-ncsc-password-administration-collection; D08 · 11. Source Hierarchy · D08-S-e4b63d794258
How this page was built
Claims are bound to dated sources and labelled with their evidence state. Demand evidence proves the question is asked; it never proves the answer. Where a needed source was unavailable, the gap is stated instead of filled.
- validated
Community questions establish that the selection question is asked, and the governing editorial rule prevents that signal from being read as a finding about fit or outcome.
HN-TEAM-PASSWORD-MANAGER-QUESTIONS · Hacker News team password-manager questions · external-hn-team-password-manager-questions; D07 · 9.3 Demand-source rule · D07-S-a52b46a6e024 - validated
Hard exclusions still apply here: fabricated claims, undisclosed commercial bias, and a duplicated primary intent cannot be outweighed by decision value.
D07 · 18.3 Hard exclusions · D07-S-c87bcf7ab169 - insufficient
The prevalence and control-gap figures on this page are United Kingdom population statistics. They are not South African evidence, and no local law, reporting duty, or regulator position is asserted here.
UK-DSIT-CSBS-20252026 · Cyber Security Breaches Survey 2025 to 2026 · external-uk-dsit-csbs-20252026; D08 · 11. Source Hierarchy · D08-S-e4b63d794258
Conditional decision
Move to a managed team vault if the four control tests pass and every shared account has an owner. Fix passkey-capable accounts first and let the vault cover only what cannot yet be migrated. Stay with documented manual control if no owner can be named, because a vault without revocation adds a copy rather than removing one.
- partial
The authority notes that an effective single sign-on process can make a password manager unnecessary for work passwords, so the correct answer for one business may be a different control entirely.
NCSC-PASSWORD-MANAGER-BUYERS-GUIDE · Password manager buyers guide · external-ncsc-password-manager-buyers-guide