Password management and access control for small businesses.

Every browser asks the same question dozens of times a week: "Save this password?" Most people click yes without thinking about it. And for personal use, that works fine.

But in a business, that habit quietly creates a problem nobody notices until something goes wrong.

The real problem is not the method. It is the lack of a system.

Most small businesses do not have a single bad habit when it comes to passwords. They have several running at the same time. Some credentials are saved in Chrome. Others are in a shared spreadsheet. A few are on sticky notes. Some get texted between coworkers. And there is almost always one person in the office who "knows all the logins."

None of these methods are unusual. But together, they create a situation where the business cannot answer three basic questions: Who has access to what? How do we revoke access when someone leaves? And how do we recover access if someone is unavailable?

The personal account trap. When an employee saves a password in Chrome or Safari, that credential syncs to their personal Google or Apple account. The business does not own that account. When someone leaves, whatever they saved goes with them, and the business has no way to know what credentials walked out the door.

The shared login problem. Teams routinely share a single login for the CRM, the social media account, the vendor portal, or the accounting software. When someone leaves, nobody changes the password because nobody remembers which accounts are shared. This is the most common access control gap in small businesses, and it usually stays invisible until it causes a problem.

The "one person who knows everything" risk. Many offices have someone who holds all the institutional knowledge about logins and accounts. That works until they are on vacation, out sick, or no longer with the company. Without a system, there is no fallback.

A purpose-built password manager solves all three of these problems. It gives the business a single, secure place where every credential is stored, shared, and controlled.

What to look for in a password manager

Not every password manager is built for business use. When evaluating options, there are three things that matter most.

Governance: who has access to what. The tool should let an owner or office manager manage access, enforce policies, and see who has credentials for which accounts, all without seeing the actual passwords. It should support sharing individual credentials with specific people, revoking access for routine changes, and making it easy to rotate shared passwords when someone leaves the company. And it should keep a quiet log of who accessed what, and when. That log runs in the background day to day, but it becomes important when someone departs, when something needs to be investigated, or when a cyber insurance carrier asks about your access controls.

Security architecture: is the provider trustworthy. The most important technical question is whether the password manager uses what is called zero-knowledge encryption. In plain terms, this means the provider never has access to your data. Even if their own systems are compromised, your vault stays encrypted with a key that only you hold. If the provider can access your data, or if independent researchers have shown that the encryption can be bypassed, that is disqualifying. A good password manager should also alert you when a saved credential shows up in a known data breach, so you can act before it becomes an incident.

Usability and continuity: will people actually use it. The tool needs to work on every platform the team uses: Mac, Windows, phones, and all major browsers. If it does not, people will route around it and go back to Chrome or paper. It also needs an emergency access path. If the person who holds the master password is unavailable, the business needs a way to recover without depending on that one individual. And it should make changing passwords simple, because the harder rotation is, the less often it happens. Ultimately, the best password manager is the one the team actually adopts. If it is slow, confusing, or clunky, people stop using it. Ease of use is not a bonus. It is a requirement.

The options

1Password is the solution GranIT deploys and manages for clients. It meets all three of the criteria above while being the most approachable option for non-technical teams. The apps are polished across every platform, the vault-sharing model fits small team structures naturally, it includes built-in breach monitoring, and the business tier has mature admin controls. For most small businesses, it is the simplest path from "no system" to "working system."

Bitwarden is an open-source, zero-knowledge alternative with a strong feature set at a lower price point. It offers a self-hosted option for businesses that want full infrastructure control, though for most small businesses the cloud-hosted business tier is the practical choice. The interface is functional but less polished, which can increase adoption friction for teams that are not particularly technical.

Keeper has a zero-knowledge architecture with a strong focus on compliance and governance. It is worth evaluating for firms with regulatory requirements, audit expectations, or cyber insurance obligations that demand documented access controls.

Other consumer-focused tools exist, including Dashlane, NordPass, and Proton Pass, but they currently lack the mature business-tier admin controls, team governance, and low-friction onboarding that a business environment requires.

A note on LastPass. LastPass has a documented pattern of security incidents spanning over a decade, with eight incidents recorded since 2011. In 2025, independent researchers at ETH Zurich identified vulnerabilities that called into question the company's zero-knowledge encryption claims. The most severe incidents occurred in 2022, when encrypted vault backups for every user were stolen. Federal investigators have linked those stolen vaults to an estimated $150 million in cryptocurrency theft. The company settled a class action lawsuit for $24.5 million in late 2025, and the UK Information Commissioner's Office fined them £1.2 million for failing to protect user data. Another data exposure occurred in 2026 through a supply chain attack on a third-party vendor. For any business relying on a password manager to protect client and financial data, a provider with this history is not a responsible choice.

Getting started

Any of the credible options above is a significant improvement over no system at all. A password manager is one of the highest-impact, lowest-cost security improvements a small business can make. Most tools cost less per month than a single lunch, and setup is measured in hours, not weeks.

If your business does not have a system today, the first step is simple: pick one, and start by getting the owner's credentials into it. The rest of the team can follow from there.

Next
Next

The Technology Conversation Every New Business Should Have (and Almost Nobody Does)