
Account Security
Part of Small business account security
Using a business password manager
Choose and roll out a business password manager using real account needs, controlled sharing, vault protection and a clear process for staff changes.
A business password manager can help staff use a different strong password for each account. It also lets the business control access to necessary shared credentials. Choose one to suit the team's actual accounts and devices. Protect its sign-in, then move credentials into it in a controlled order.
Identify what belongs in the manager
List accounts that still use passwords. Separate each person's own logins from credentials several people know. Use individual service accounts where available. A shared password in a vault does not make actions under that account attributable to one person.
Record which devices and browsers staff use, who will administer the vault, and which people need each shared item. Include external providers only for work that requires their access. Check a service's terms before storing or sharing its login.
Check applicable account terms; do not assume every login can be moved.
Pros and cons of using shared passwords vs. a business password manager
- Shared passwordsPro: Simple to set up initially. Con: No accountability, high risk of exposure, hard to rotate or revoke access.
- Business password managerPro: Enables strong, unique passwords, audit trails, controlled sharing, and MFA. Con: Requires training and ongoing management.
Check the product and plan
Ask suppliers to show how these functions work on the plan under consideration:
| Need | Question to settle |
|---|---|
| Vault protection | Which MFA methods are available for the vault? |
| Team access | Can a shared item be limited to named people or groups? |
| Staff changes | How is vault access removed, and which shared passwords must still be changed? |
| Devices | Do the apps and browser extensions work on the team’s devices? |
| Recovery and export | What happens if the master sign-in is lost, and how can an authorised owner export credentials? |
| Maintenance | How are updates delivered, and what security and privacy information does the supplier provide? |
Check a manager's reputation, security and privacy features, updates, encryption, MFA and device support. Features and recovery options vary by product and plan. A forgotten master passphrase may leave stored credentials inaccessible. Establish the actual recovery route before rollout.
Key features to compare in business password managers
- Vault protectionSupport for biometrics, hardware tokens, or authenticator apps as MFA methods.
- Team access controlAbility to restrict shared items to specific users or groups, not just all team members.
- Staff change managementClear process to revoke access and reset shared passwords when employees leave.
- Device and browser supportNative apps and extensions for Windows, macOS, iOS, Android, and major browsers used in Australian businesses.
- Recovery and exportSupported recovery paths such as backup codes or admin-assisted recovery; secure export options for compliance.
Protect the vault and move accounts
Give workers named access where the product supports team accounts. Assign administrators only the permissions they need. Use a strong, unique master passphrase and MFA if available. Set devices to lock after inactivity, and avoid opening the vault on shared or public computers.
Start with an important account whose owner can confirm the change. Save its login in the manager, generate a new unique password, change the password in the service itself and check a fresh sign-in. Enable MFA for that service if available. Saving a new password in the vault does not change the old one at the service.
Organise shared items by who needs them. Decide who handles their MFA prompts and who changes their passwords when access ends. A worker may have seen or copied a revealed password, so removing their vault access alone may not secure that service. Replace shared logins with named service accounts when possible.
Tell staff how to request access and report a lost device. Review vault permissions after role changes. Check whether business credentials remain in a personal vault the business cannot administer. The manager does not replace MFA or permissions on the services it holds.



