Fit map · evidence partial
A six-step path from shared passwords to revocable team access
This is a control sequence for evaluating an approach. It is not a recommendation for a named product or a ranking of any vault.
1. Bound one account group
Pick the smallest set of shared accounts where loss of access is painful but recovery is cheap, such as marketing and supplier logins. Leave banking and hosting out until the sequence has been exercised once.
- partial
Population statistics do not establish a safe local scope for one business, so scope is a documented judgement rather than an inferred threshold.
UK-DSIT-CSBS-20252026 · Cyber Security Breaches Survey 2025 to 2026 · external-uk-dsit-csbs-20252026
2. Record what exists
For each account write down who can reach it, how the secret is found today, whether the provider supports per-person logins, and whether passkeys are offered. Where a field cannot be answered, that is the work rather than a gap in the page.
- validated
The guidance treats usability and actual usage patterns as prerequisites for choosing a product, which requires knowing the current pattern first.
NCSC-PASSWORD-MANAGER-BUYERS-GUIDE · Password manager buyers guide · external-ncsc-password-manager-buyers-guide
3. Separate the person from the secret
Give each member an individual identity before any secret is shared with them. A vault that models organisation-owned items shared to named members supports revocation; a list of credentials shared as one secret does not.
- partial
Vendor documentation describes organisations as relating named users to shared vault items managed from an administrator console, which is the documented shape of this capability.
BW-ORGANIZATIONS-DOCS · Get to know your organization · external-bitwarden-organizations-docs
4. Retire the password where you can
Migrate any account that already supports passkeys before moving its secret into a vault. A stored password you no longer need is a smaller exposure than a well-encrypted one.
- validated
The technical authority states that passkeys are at least as secure as traditional credentials and should be the default where available, a position newer than the 2018 password-administration collection.
NCSC-PASSKEYS-2026 · Leave passwords in the past - passkeys are the future · external-ncsc-passkeys-2026; NCSC-PASSWORD-ADMIN-COLLECTION · Password administration for system owners · external-ncsc-password-administration-collection
5. Prove recovery without a hero
Test break-glass access while the usual holder is unavailable. Record who approved it, what was reached, and how access returned to normal. An untested recovery route is a rumour about resilience.
- partial
The survey records that restricted administrator rights are common while staff training remains low across businesses, which makes a written recovery route more reliable than remembered procedure.
UK-DSIT-CSBS-20252026 · Cyber Security Breaches Survey 2025 to 2026 · external-uk-dsit-csbs-20252026
6. Review use, not purchase
After one month check whether members actually reach the vault or have returned to a copy elsewhere. If usage has decayed, the control failed even though the purchase succeeded.
- validated
The authority recommends periodic review of how the product is used after implementation because benefit and cost are wasted if workarounds persist.
NCSC-PASSWORD-MANAGER-BUYERS-GUIDE · Password manager buyers guide · external-ncsc-password-manager-buyers-guide
7. Expand, hold, or stop
Expand to the next account group only when revocation, recovery, and review have each been exercised once. Hold where a provider cannot support per-person access. Stop where naming an owner is impossible, because no tool supplies accountability.
- partial
Selection criteria are stated as conditional on how an organisation intends to use the product, so a hold or stop outcome is a compliant reading rather than a failure.
NCSC-PASSWORD-MANAGER-BUYERS-GUIDE · Password manager buyers guide · external-ncsc-password-manager-buyers-guide; D07 · 18.3 Hard exclusions · D07-S-c87bcf7ab169 - insufficient
These six steps rest on United Kingdom authority and vendor documentation. They carry no South African legal, regulatory, or breach-notification conclusion, and no local equivalent was acquired in this pass.
NCSC-PASSWORD-MANAGER-BUYERS-GUIDE · Password manager buyers guide · external-ncsc-password-manager-buyers-guide; D08 · 11. Source Hierarchy · D08-S-e4b63d794258