Sharing passwords at the office: what's acceptable and what's not
Sharing passwords at the office is sometimes unavoidable. Here's how to do it without unpleasant surprises — and which passwords you should never share under any circumstances.
Sharing passwords — it happens in every office. The permanent staff member knows the password to the shared mailbox, the bookkeeper has the bank login memorised, and the guest Wi-Fi password is on a yellow sticky note at the reception desk. Convenient, until someone leaves or something goes wrong.
The reality is messy: stopping password sharing altogether is unrealistic for most small offices. But you can organise it more securely — without needing an IT department. In this post we explain which passwords you should never share, which ones are acceptable (under the right conditions), and how to handle it practically.
Three types of passwords in the office
Before we talk about sharing, it helps to make a distinction. In a typical office there are roughly three types of passwords:
- Personal logins — your own email, your own Microsoft or Google account, your own login for the accounting software.
- Shared accounts — a general email address such as info@, a customer portal that only allows one login per company, or a social media account.
- Device and network passwords — guest Wi-Fi, the router, the printer, the NAS.
Each category calls for a different approach.
Personal logins: never share. Full stop.
Your personal work account is yours. If a colleague temporarily needs access to your email or files — for example when you're on holiday — arrange it through the proper channels: enable mail forwarding, create a shared folder, or add someone as a delegate in your calendar.
Why does this matter? If someone logs in with your password and something goes wrong (an incorrect payment, a leaked document, an angry client), the system will show that you did it. There's no explaining that away afterwards. Besides: the moment two people know a password, you can be sure it will eventually reach a third.
Also important: enable two-step verification on all personal accounts. This makes sharing awkward in the first place (because the code arrives on one phone) and protects against most phishing attempts.
Shared accounts: fine, but not via WhatsApp
Some accounts are simply communal — info@, the wholesale supplier account, the webshop admin. Sharing is unavoidable there. Just do it properly:
- Use a password manager with a team feature. Think Bitwarden, 1Password, or Keeper. Everyone with access can use the password without ever seeing it. Someone leaves? One click and their access is gone.
- Never share via email, WhatsApp, or a Post-it. These stick around forever. A screenshot of a chat message containing a password can still be sitting in someone's photo backup five years later.
- Keep track of who has access. A simple list in your password manager or a spreadsheet is enough. Without that list, within a year you'll have no idea who can get into what.
- Change the password whenever someone leaves. This includes interns and temp workers. Even if you think "they won't do anything" — you don't know whether their phone gets sold later on.
Device and network passwords: less drama, more discipline
Putting the guest Wi-Fi on a sign in the waiting area is perfectly fine — that's exactly what it's there for. But the password for your business Wi-Fi network, which your computers, printer, and NAS are all connected to, is a different matter. That one should not be on the same sign.
Practical tips:
- Set up a separate guest network. Most modern routers support this. Visitors connect to that; your devices stay on the business network.
- Change the default password on your router. The "admin/admin" login is still one of the most common causes of trouble.
- The printer, NAS, or camera in the office? These all have an administrator password too. Change it during installation and store it in your password manager — not on a sticker on the device itself.
What about passwords that are already floating around?
Let's be honest: there are probably passwords sitting in old emails, WhatsApp conversations, and Word documents right now. Don't try to overhaul everything in one weekend — start small:
- Make a list of your five most important shared accounts (think: bank, accounting, general email, hosting provider, main social media account).
- Change the password for each one and immediately store the new password in a password manager.
- Delete the old messages containing the password (in your email, chat, and notes).
- Enable two-step verification wherever possible.
That's a single morning's work and it eliminates the biggest risk straight away. The rest can wait.
Warning signs that things are getting out of hand
Recognise one or more of these? Then it's really time for a clean-up:
- You no longer know exactly who has the password to info@.
- Passwords are stored in a shared Word or Excel file in the cloud.
- Former employees or old interns could theoretically still access something.
- You're using the same password for multiple business accounts.
- You have no idea which services you even have an account with.
Get started yourself
Password management doesn't have to be a big project. Start with the shared accounts and work outward from there. If you get stuck, or want to make sure no former employee can still access your files, our access check gives you an instant overview of who has access to what. And for enabling two-step verification on your most important accounts, take a look at our 2FA implementation service.
Volledige gids: Access Management for SMBs: The Complete Guide (2026)
Dit artikel is onderdeel van onze uitgebreide Toegangsbeheer-gids. Lees de pillar voor het complete plaatje.
Lees de pillar →