What a password manager does
A password manager stores logins in an encrypted vault, generates strong unique passwords and fills them in for you. Business plans add shared vaults, so teams can share access without sending passwords in chat, and an admin console to manage who has access to what. 1Password, Bitwarden and LastPass are widely used options.
Why companies need one
- Shared logins end up in spreadsheets, chat messages and sticky notes.
- People reuse the same password across tools.
- When someone leaves, nobody knows which shared passwords they knew.
- Customers and auditors ask how you manage credentials.
Before rollout
- Decide the vault structure: usually one per team plus a few restricted ones for finance and admin.
- Decide who the administrators are. Have at least two.
- Set the account recovery process before anyone is locked out.
- Require multi-factor authentication on the password manager itself.
- Connect it to your identity provider if you have one.
Rollout steps
- Start with a pilot group and fix what confuses them.
- Invite everyone, with a deadline and a short how-to.
- Have each team move its shared logins into the right vault.
- Change shared passwords as they are moved, since the old ones were likely exposed.
- Delete the old spreadsheets and pinned messages.
Keeping it working
- Add the password manager to onboarding, so new hires are set up on day one.
- On offboarding, remove the account and rotate the shared passwords that person could see.
- Review vault access on a schedule.
Why rollouts stall
The software takes an afternoon to configure. Getting every person to install it, move their logins and stop using the old way takes weeks of follow-up, and that follow-up is the actual project.
We set up password management and see the rollout through until everyone is using it. See systems selection and setup.
