Skip to content
Back to blog
best-practices

Password hygiene for teams: a practical guide

P
PassTransfer
Published June 14, 20264 min read

Password hygiene advice is abundant online. Use a password manager. Enable two-factor authentication. Use unique passwords for every service. Do not write passwords on sticky notes.

Most of this advice is aimed at individuals. But in a team context, password hygiene has additional dimensions: shared accounts, credential rotation when someone leaves, consistent practices across people with different security awareness levels, and secure processes for moving credentials between people.

This guide addresses the team dimension specifically.

The team password hygiene baseline

Before tackling the more complex questions, make sure your team has the basics covered:

Unique passwords per service. Every account should have a unique, randomly generated password. If the same password is used across multiple services, a breach at one service compromises all of them.

A team password manager. Individual password managers (1Password, Bitwarden, KeePass) are great for personal use. For team credentials, you need a shared vault with access controls: 1Password Teams, Bitwarden Organizations, Dashlane Business. These allow credentials to be shared across the team without being sent via email or chat.

Two-factor authentication everywhere possible. This is covered in more depth in another article, but the team norm should be that 2FA is non-negotiable for any account that contains sensitive data.

No shared personal accounts. If multiple team members need access to a service, use the service's multi-user or team account features — not a shared personal account. Shared personal accounts cannot be attributed in logs and cannot be revoked for one user without affecting all.

Managing shared credentials

Some services do not offer multi-user access. In these cases, shared credentials are unavoidable. The risks are:

  • No way to identify who made a specific change
  • Difficulty revoking access for one person without affecting others
  • Credentials may be stored insecurely by any team member

Mitigation steps:

  • Store shared credentials in the team password manager, not in a document or email
  • Minimize the number of people with access to any shared credential
  • Rotate shared credentials whenever someone with access leaves the team
  • Log changes where the service allows it, even if individual attribution is not possible

Credential rotation policies

Rotation — changing passwords regularly — has a nuanced relationship with security. For individual accounts, frequent rotation can lead to weaker passwords (people increment a number instead of using a genuinely new credential). For shared team credentials and service accounts, rotation is important because:

  • It limits the window of exposure if a credential has been compromised without detection
  • It is the primary mechanism for revoking access when someone leaves

When to rotate:

  • When a team member with access leaves the organization
  • After any suspected or confirmed credential compromise
  • After sharing with an external party (contractor, vendor) whose access has ended
  • Annually for high-value service accounts, even without a specific trigger

What rotation looks like in practice:

  1. Generate a new credential
  2. Update the team password manager
  3. Deliver the new credential to anyone who needs it (via one-time link, not email)
  4. Confirm the new credential works
  5. Invalidate or delete the old credential

The "someone left" problem

When a team member leaves, credential management becomes acute. The checklist:

  • [ ] Deactivate their user account on all services
  • [ ] Identify all shared credentials they had access to
  • [ ] Rotate all shared credentials
  • [ ] Deliver new credentials to remaining team members via secure links
  • [ ] Remove their access from the team password manager
  • [ ] Check for any personal accounts they may have created for work purposes (and recover access)

This process is often under-resourced and overlooked. Organizations that do not do it are frequently compromised by former employees — not maliciously, but because old credentials persisting in the former employee's password manager can be accidentally used or exposed.

Secure sharing as part of team hygiene

The final piece of team password hygiene is the delivery moment: how credentials move from one person to another.

The rule is simple: credentials should never travel via email, chat, or shared documents. Use a purpose-built tool with one-time access and automatic expiry.

This is not a complex change. It is a habit. And like most security habits, the hardest part is making it the default — the thing the team does without thinking — rather than the thing that requires a conscious decision every time.

Build it into onboarding. Build it into offboarding. Build it into the process for sharing with external parties. Mention it in your team handbook. Over time, it becomes the normal thing to do.

Share this article
P
PassTransfer

The team behind PassTransfer writes about secure sharing, compliance and practical security for teams and agencies.

Ready to get started?

Sharing securely takes 10 seconds

Paste your password, pick an expiry time and share the link. Free and without an account.

Share a password