Shared admin passwords in a spreadsheet, a Teams chat, or one person’s browser are how credentials outlive employment. A team vault in a real password manager is the fix — if you set collections, permissions, and rotation rules on purpose. Bitwarden’s Organizations documentation is one concrete product example: the organization, rather than an individual user, owns shared items and administrators manage access centrally.
1. Pick a vault product and a ownership model
Use a business password manager (1Password, Bitwarden, Keeper, etc.) with:
- Individual logins + MFA for every technician
- Shared collections / vaults for client or internal systems
- An org owner that is not a single personal email you will lose
Personal free vaults are not an ops strategy.
2. Structure collections by blast radius
Examples:
Internal — Network & FirewallInternal — Microsoft 365 break-glass references(metadata / location notes; store actual break-glass offline if that is your policy)Client A — ServersClient A — SaaS admin
Do not put every secret in one mega-folder everyone can see. Least privilege applies to passwords too. In Bitwarden, for example, collection access is the combination of member roles, collection settings, and per-user or group permissions. Check the equivalent controls in the product you select.
3. Migrate deliberately
- Inventory shared secrets from spreadsheets, browsers, and sticky notes
- Create or import entries with clear names (
FW-Edge01-admin, notcisco) - Grant collection access only to people who need it this week
- Rotate anything that lived in the old spreadsheet after import
- Delete or archive the spreadsheet so it cannot become current again
Rotation after migration is the step teams skip. Do not skip it.
4. Set operating rules
- No pasting vault passwords into tickets or chat
- Emergency access / break-glass for the vault itself documented
- Offboarding removes vault access the same day as Entra / email. Confirm what removal does in your product; Bitwarden documents that a removed member loses organization permissions and shared-item access, while their separate personal vault can remain.
- Periodic access review of who can open high-impact collections
5. Prove a restore of vault access
Confirm what happens if the vault admin leaves or MFA is lost. Do not leave ownership with one person: Bitwarden’s role guidance explicitly recommends assigning an additional owner to prevent subscription and administration disruption. If the answer is “we are locked out of every client firewall,” fix that before you celebrate.
Bottom line
Shared admin secrets belong in a business password manager with scoped collections, MFA on every tech, rotation after migration, and same-day access removal — not in a spreadsheet that outlives the employment roster.

