Password sharing policy template for organizations
A password sharing policy is a short, clear document that tells staff how credentials are to be shared — what is allowed, what is prohibited, and what happens if the policy is violated. Most organizations do not have one. This template gives you a starting point.
Adapt this template to your organization's specific context, legal environment, and existing policies. Have it reviewed by legal counsel if your sector has specific regulatory requirements.
[ORGANIZATION NAME] Password Sharing Policy
Version: 1.0 Effective date: [DATE] Policy owner: [IT Manager / CISO / Security Lead] Review cycle: Annual
1. Purpose
This policy establishes requirements for how passwords and access credentials are shared within [Organization Name] and with external parties. Its purpose is to protect organizational systems and data from unauthorized access caused by insecure credential handling.
2. Scope
This policy applies to:
- All employees of [Organization Name]
- Contractors, freelancers, and temporary staff with access to organizational systems
- Third-party vendors and partners who receive credentials from [Organization Name]
This policy covers all types of access credentials, including but not limited to: system passwords, application logins, API keys, SSH keys, database credentials, and service account credentials.
3. Approved credential sharing methods
Credentials must be shared using one of the following approved methods:
a) Designated credential-sharing tool: [Organization Name] uses [PassTransfer / other approved tool] for all credential delivery. This tool provides encrypted, one-time-access links that expire after a defined period.
b) In-person verbal communication: For highly sensitive credentials, in-person verbal delivery with immediate storage in a password manager is acceptable.
c) Team password manager: For credentials shared across a team on an ongoing basis, the team password manager ([1Password / Bitwarden / other]) is the approved storage and sharing mechanism.
4. Prohibited credential sharing methods
The following methods are strictly prohibited for sharing credentials:
- Email (whether in the message body or as an attachment)
- SMS or instant messaging applications (Slack, Teams, WhatsApp, etc.)
- Shared documents (Google Docs, Word files, spreadsheets, PDFs)
- Printed documents left in accessible locations
- Voice calls where the credential is recorded or logged
- Any method that creates a persistent, unencrypted copy of the credential
5. Expiry requirements
Credential links shared via the approved tool must use the following maximum expiry times:
| Recipient type | Maximum expiry |
|---|---|
| Internal employee | 72 hours |
| External contractor | 24 hours |
| Client | 48 hours |
| Highly privileged credentials (admin, root) | 4 hours |
If a link expires before the recipient retrieves it, a new link must be generated. The credential must not be sent via a prohibited method as a fallback.
6. Credential rotation requirements
Credentials must be rotated in the following circumstances:
- Staff departure: All credentials accessible to a departing employee must be rotated within 24 hours of their last working day
- External access termination: Credentials shared with a contractor, vendor, or client must be rotated when their access is no longer needed
- Suspected compromise: Any credential believed to have been accessed by an unauthorized party must be rotated immediately
- Routine rotation: High-privilege credentials (admin accounts, production system access) must be rotated at least every 90 days
7. Responsibilities
All staff are responsible for:
- Using only approved methods for sharing credentials
- Storing received credentials in the approved password manager immediately upon receipt
- Reporting suspected credential compromise to [IT/Security contact] immediately
IT / Security team is responsible for:
- Maintaining and providing access to approved credential-sharing tools
- Conducting periodic audits of credential handling practices
- Responding to reported credential compromise incidents
- Maintaining this policy and providing staff training
8. Enforcement
Violations of this policy may result in disciplinary action in accordance with [Organization Name]'s disciplinary procedures. Serious or repeated violations, or violations that result in data compromise, may result in termination of employment or contract.
9. Exceptions
Exceptions to this policy must be approved in writing by [IT Manager / CISO]. Exceptions are time-limited and must include documented justification and compensating controls.
10. Policy review
This policy will be reviewed annually by [Policy Owner] or following any significant security incident related to credential handling.
Implementing this policy
Once you have adapted and approved this template:
- Distribute it to all staff with a read-and-acknowledge step
- Include it in your new employee and contractor onboarding process
- Reference it in your general IT security policy
- Add the approved tools (PassTransfer, password manager) to your IT provisioning process so new staff have access from day one
- Set a calendar reminder for the annual review
A policy without adoption is decorative. The goal is to make secure credential sharing the default behavior — and a clear, accessible policy is the foundation for that.