Insights & News
How to Share Passwords Securely With Staff
- August 27, 2026
The safe way to share a password with staff is through a business password manager with shared vaults, where the credential is granted to a role rather than sent to a person. Anything that involves typing a password into an email, a chat message, a spreadsheet or a sticky note creates a copy you can never retrieve or revoke. That distinction matters more than password strength: a long random password pasted into a group chat is less safe than a mediocre one held in a vault, because the chat message will still be there, searchable, after the person leaves.
Key facts
- Shared vaults in a business password manager are the correct mechanism. Access is granted per vault and can be removed centrally without changing the password for everyone else.
- Email and chat are the worst options, because the credential is copied into a system that retains it, indexes it, syncs it to phones, and keeps it in backups long after the person has gone.
- Shared spreadsheets fail on audit as well as security: there is no record of who read what, and removing one person's access to one credential is impossible.
- Where a system supports individual accounts, share access rather than a password. A shared login should be the exception, used only where the vendor gives you no alternative.
- Anything sent outside a vault should be treated as compromised and rotated, not just deleted from the chat thread.
- Australian privacy obligations sit behind this. If a shared credential exposes personal information, how that credential was handled becomes part of the incident.
Why is emailing a password so much worse than it feels?
Because a message is not a delivery, it is a permanent copy. Send a password by email and it exists in your sent items, the recipient's inbox, both mail servers, any archive or journaling system, every phone and laptop that has synced the mailbox, and every backup taken since. You cannot recall it, you cannot see who has read it, and you cannot tell whether it was forwarded. The same is true of chat, with the added problem that most chat platforms have excellent search, so a compromised account can find every credential ever shared by typing the word password.
This is also the mechanism behind a lot of business email compromise. An attacker who gets into one mailbox does not just read the current messages. They search the history for credentials, invoices and banking details, and a mailbox that has been used to pass around logins for several years hands them the keys to everything at once. The exposure is not the moment of sending, it is the years of retention afterwards.
What does correct password sharing look like?
Credentials sit in vaults organised by function, not by person. A finance vault holds the accounting, banking and payroll logins. An operations vault holds the systems that team runs. A marketing vault holds the social and advertising accounts. People are granted access to the vaults their role requires, so a new starter in finance gets working access on day one without anyone reading a password out to them, and a departing staff member loses access to everything in one action.
Permissions should distinguish between using a credential and managing it. Most staff need to sign in; far fewer need the ability to change a password or share it onward. That separation is what stops a shared vault quietly becoming a shared free-for-all. It also means nobody, including the owner, needs to hold a master list, because oversight comes from the reporting rather than from someone knowing every password.
Where a system supports individual user accounts, use them. A shared login is a compromise you accept when a vendor forces it on you, not a convenience to reach for, because it destroys accountability: if four people use the same account, the audit log cannot tell you who did something.
How do you share a credential with someone outside the business?
Contractors, bookkeepers and external agencies are where most businesses fall back into bad habits, because adding an outsider to the internal system feels like too much work. Business password managers handle this with guest access, letting an external party reach one specific vault without a full licence and without seeing anything else. That is almost always the right answer for an ongoing relationship such as an external accountant.
For a genuine one-off, most password managers can generate a link that expires after a set time or a single view. It is not perfect, since the recipient can still copy what they see, but it is far better than email because the credential is not permanently retained in a messaging system. Use it as the exception, and rotate the credential afterwards if it protects anything material.
What should you do about the passwords already sent by email?
Treat them as exposed and rotate them, rather than trying to delete the history. Deleting the sent message does not remove the copies in backups, archives or synced devices, so the only way to close the exposure is to change the credential and put the new one in a vault. In practice this is a project rather than an afternoon: identify the accounts that have been shared informally, prioritise anything touching money, customer data or administrative access, and work through them.
The other half of the job is stopping the behaviour returning. That is mostly friction: if the vault is easy and the browser extension is installed on every machine, people use it, and if it is not, they go back to chat. This is why we treat adoption as part of the deployment rather than an afterthought. See our password management page for how the whole thing fits together, and security awareness training for the behaviour side.
Frequently asked questions
Is it safe to share passwords over Microsoft Teams or Slack?
No, and it is one of the more common mistakes we find. Chat platforms retain messages, sync them to every device, include them in backups and index them for search, which means a single compromised account can retrieve every credential ever shared in the workspace. Deleting the message afterwards does not remove it from backups or from devices that already synced it. If a password has been shared in chat, rotate it rather than delete the message.
What about sending the password by text and the username by email?
Splitting a credential across two channels is better than putting both in one, and it was reasonable advice before password managers were common. It still leaves a permanent copy of each half in a system you do not control, and it gives you no ability to revoke access or see who used it. Use it only when you have no vault available, and rotate the credential once the recipient has stored it properly.
Can we just use one shared login for everything to keep it simple?
It is simple right up to the first problem. A single shared login means the audit log cannot tell you who did what, you cannot remove one person's access without disrupting everyone, multi-factor authentication becomes awkward because the second factor has to be shared too, and one departure forces a change that affects the whole team. Individual accounts with vault-based sharing take slightly more setup and remove all of those problems.
How do we stop staff writing passwords down?
By removing the reason. People write passwords down when they are expected to remember something they cannot, which is the predictable result of complexity rules and forced rotation without a password manager. Once credentials are generated and filled by a vault, there is nothing to remember and the notes stop appearing. If people are still writing things down after a rollout, it usually points to a system that was missed or a workflow the vault does not cover well.
If passwords in your business are currently moving around by email, chat or spreadsheet, we can set up proper vault-based sharing, work through rotating what has already been exposed, and get staff using it. Request a callback and we will scope it with you.
About the author
Brett Muscio is the Director of 4iT Support Pty Ltd, a managed services provider based in Castle Hill, NSW. He works with SME clients across Sydney, Melbourne, and Brisbane on cybersecurity, including password management, multi-factor authentication, identity and access management, and Microsoft 365 hardening, with on-site support across the Sydney metro area and remote delivery nationally. Connect on LinkedIn.
Recent Posts
-
Choosing a Password Manager for Small Business -
Passkeys vs Passwords: What Businesses Need to Know -
Password Policy for Australian Small Business -
How to Share Passwords Securely With Staff -
What Is Veeam, and Why 4iT Uses It for Backup -
Sophos Intercept X and MDR: Endpoint Protection That Fights Back -
Sophos Firewall for Business: What It Does and Why It Matters -
Microsoft 365 Backup: Why Your Data Is Not as Safe as You Think -
What Is a Cyber Security Audit? A Guide for Australian SMEs -
Vulnerability Scanning for Australian SMEs: What You Need to Know







