What a password manager changes
A password manager stores credentials in an encrypted vault and helps create a different strong password for every service. The important improvement is not convenience alone: one stolen website password no longer unlocks email, banking, accounting software and social media.
The vault still needs protection. Use a long, unique master password or passkey, enable multi-factor authentication, secure the recovery methods and keep the device itself updated.
Choose for the business, not just one user
- Ownership: the organisation should control the subscription and administrator access.
- Sharing: passwords should be shared through named vault access, not messages or spreadsheets.
- Offboarding: access must be removable when a person changes role or leaves.
- Recovery: document who can recover the organisation if the main administrator is unavailable.
- Auditability: business plans may provide activity records, policy controls and security reports.
- Export: understand how an authorised administrator can retrieve the organisation's data if the service changes.
A safe rollout sequence
- Create the organisation account using a business-controlled address.
- Secure administrator and recovery access before importing credentials.
- Move the most important accounts first: email, domain, banking, accounting, cloud storage and social media.
- Replace reused passwords rather than simply importing them unchanged.
- Invite each user by name and grant only the collections needed for their role.
- Record an offboarding and emergency-recovery procedure.
Password manager, MFA and passkeys work together
A password manager does not replace multi-factor authentication. Enable MFA on email, domain administration, finance, cloud storage and the password manager itself. Where a service supports passkeys, they can reduce reliance on phishable passwords, but the business must still plan device loss and account recovery.
Common mistakes
- Keeping the master password in the same unlocked notes app as the vault recovery code
- Using one shared login for every employee
- Giving every user permanent access to every credential
- Leaving former staff accounts active
- Assuming browser sync is a complete business recovery plan
Authoritative guidance
See the NCSC small organisations guide and its current advice on securing accounts, email and devices. Product features change, so confirm security, recovery and export capabilities in the provider's current documentation before adoption.
Need help applying this to your business?
Vengera can assess the current setup, explain the priorities and scope any practical improvements.