// Engineering Log

Password Managers: Part 1 — Why Companies Need Them

Published on 2026-09-21

// Fast route

This article belongs to the topic Security and protection.

Even in a small company there are dozens of accounts: email, cloud services, CRM system, advertising accounts, online banking client, hosting control panels and domain registrar panel. When there are many passwords, people make life easier: they invent short passwords, use the same password across different services, or record them in spreadsheets and messengers. This is how breaches most often occur.

What is the problem

  • Password reuse. Login/password databases leaked from one service are automatically checked by attackers against others. If a password is reused, compromising one site opens access to all the others.
  • Weak passwords. It’s impossible to remember dozens of long random passwords, so people choose simple and predictable ones.
  • Passwords in plain text. A spreadsheet with credentials on a shared drive or a message in a work chat is visible to everyone who has access to that drive or chat, and can remain there for years.
  • Unmanaged access. No one knows exactly which employees and contractors have the password for which service.

What is a password manager

A password manager is a program or service that stores credentials in an encrypted vault. Access to the vault requires a single master password. In common managers the data is encrypted on the user’s device, and the server receives the already-encrypted copy, so the service provider cannot read the contents of the vault. This scheme has a downside: a forgotten master password cannot be recovered unless a recovery mechanism was configured in advance.

Main features

  • Password generation. A separate long random password is created for each service.
  • Autofill. Login and password are filled in on the site or in the app automatically; you don’t need to remember or copy the password.
  • Synchronization between devices. The vault is available on desktop, phone and in the browser.
  • Two-factor authentication codes. Many managers can generate one-time codes (TOTP) for services with two-factor login.
  • Password auditing. The manager shows weak, reused, and passwords found in known leaks.
  • Secure notes. The vault can store API keys, bank card details and other secrets.

Password manager in a company

Shared access

In corporate managers entries are grouped into collections or shared folders, and access to them is granted to employees and groups. For example, a marketer gets access to advertising accounts in VKontakte and Yandex.Direct, an accountant — to the online banking client and the tax office account, a developer — to hosting control panels. Passwords are no longer sent in chats, and the administrator can see each employee’s list of accesses.

Hidden passwords

Some managers allow granting access so that an employee can sign in to a service via autofill but cannot see the password inside the manager. This feature should be used, but its limits must be understood. As Bitwarden writes, this is not a full security boundary: during autofill the password is still passed to the browser, and after insertion it can be seen in the input field on the site. Hiding the password reduces accidental disclosure, but does not protect against an employee who actively wants to obtain the password.

Employee termination

A password manager significantly simplifies revoking access: the employee is removed from the organization and immediately loses access to all shared entries. However, passwords that they saw or could obtain via autofill should be changed afterwards. The manager shows the list of such services by the collections the employee had access to, so changing passwords becomes a clear and limited task.

Activity log

In corporate plans managers keep an event log: who opened, changed or exported entries. This helps investigate incidents and verify that accesses are used as intended.

How to implement a password manager

  1. Make an inventory of the company’s accounts. Services, owners, who uses them and where the password is currently stored.
  2. Choose a solution. A cloud service is easier to launch; a self-hosted server gives more control over data but requires administration. For Russian companies it’s important to consider the payment method: it may be impossible to pay a foreign service with a Russian bank card.
  3. Design the structure. Collections by departments or projects, employee groups, rights for viewing and modification.
  4. Protect access to the manager itself. A long master password and mandatory two-factor authentication for all employees.
  5. Set up access recovery. Decide in advance what will happen if an employee forgets their master password: corporate plans often provide recovery via an administrator or access for a trusted person.
  6. Migrate passwords. Most managers import data from browsers and other managers. After import, delete the exported files: they contain passwords in plain text.
  7. Change weak and reused passwords according to the manager’s report, starting with email, bank and control panels.
  8. Establish a workflow. New credentials are created only in the manager; upon an employee’s termination — removal from the organization and changing passwords in their collections.

Common mistakes

  • Weak master password or no two-factor authentication for the manager itself: it becomes a single point of compromise.
  • No recovery plan. An employee forgets their master password — and access to the data is lost.
  • Relying on hidden passwords instead of changing passwords when an employee leaves.
  • Exporting passwords to a file that remains on disk or in email after the transfer.
  • Parallel storage of passwords in spreadsheets and chats. If the manager doesn’t become the single source of truth, it does not solve the problem.

Cloud or self-hosted

Password managers are split into cloud services, where the provider hosts the vault, and solutions that can be deployed on your own server. The cloud option does not require administration; a self-hosted server keeps the data inside the company and does not depend on the ability to pay a foreign subscription.

// Similar task

If you are dealing with something similar

This article belongs to one of the main working topics. You can keep reading on the topic, go to the homepage to understand what I do, or open the service pages directly.

Article topic

Security and protection

SSL, hardening, access control, service protection, and secure configurations.

Typical tasks behind this topic

  • Set up SSL, certificates, and secure connections
  • Restrict access and close unnecessary entry points
  • Harden server and service configuration

// Next step

If you need help with this topic, not just another article, it is better to go straight to the service page. The homepage and topic collection stay available as secondary routes.

Open services

// Contact

Need help?

Get in touch with me and I'll help solve the problem

I reply within one business day (03:00-13:00 GMT)

Или оставьте заявку здесь:

Confirm that you are not a bot.

Write and get a quick reply