Shared account security

Shared Accounts: How to Control Access Without Sharing Passwords Informally

Shared accounts often exist because several people need the same system. The risk comes from how access is granted, tracked and removed. Emailing one password to an entire team isn't an access-control strategy, a shared vault folder with defined permissions is.

Executive summary

Use Individual Accounts Whenever the System Allows It

Individual accounts make it easier to apply least privilege, MFA and logging. When a shared or service account is unavoidable, assign an owner, store the credential in a managed vault, control who can use it, and rotate access when people or vendors change.

Named owner

Every shared or service account needs a responsible business and technical owner.

Vaulted access

Keep credentials in the approved business password manager.

Lifecycle control

Review, rotate and remove access as roles and vendors change.

Setup steps

How to Create a Shared Folder in Keeper

Instead of emailing a password to a team, create a shared folder in Keeper and add only the people who need it.

Create the record first

Add the account as a Login record in your own vault, with a long, unique password generated by Keeper rather than one you invented.

Create a shared folder

In the Keeper Vault, select Create New, then Shared Folder, and give it a clear name that identifies the system or team it covers.

Move the record into the folder

Drag the record into the shared folder, or use the record's sharing option to add it directly.

Add users with specific permissions

Add only the people who need access, and set whether each person can view, edit, share or manage records within that folder rather than granting full control by default.

Review membership on a schedule

Check shared-folder membership periodically, not just when someone leaves, since roles and vendor relationships change over time.

Permissions

What Shared Folder Permissions Actually Control

View

Can see and use the record's credentials but can't change them.

Edit

Can update the password, username or notes on existing records.

Add and remove records

Can place new records into the folder or take existing ones out.

Share and manage

Can add or remove other users and change their permissions, usually reserved for the folder owner.

Most team members only need View. Reserve Edit, Share, and Manage for the smallest group actually responsible for maintaining the account.

Control standard

Rules for Shared and Service Accounts

  • Create individual user accounts instead of shared accounts whenever possible.
  • Document the business purpose, owner and systems affected.
  • Store the password in the approved business vault, never in email, chat or a spreadsheet.
  • Use a long, unique password generated by the vault.
  • Enable MFA when the system supports it and manage the authenticator centrally.
  • Limit access to the smallest necessary group.
  • Review use through available logs and alerts.
  • Rotate the credential after employee departures, vendor changes or suspected exposure.
  • Don't use shared administrator accounts for ordinary work.
  • Disable accounts that no longer have a valid purpose.
Common failures

What Makes Shared Accounts Dangerous

No accountability

When several people use the same username, logs may show the account activity without showing which person performed it.

Access survives employment

A former employee or vendor may retain the password unless it's rotated and their vault access is removed.

MFA belongs to one person

Shared accounts sometimes depend on one employee's phone, creating both security and continuity problems.

The password spreads

Every email, spreadsheet, text message and browser copy becomes another place the company must protect.

Free policy toolkit

Put Better Authentication Rules in Writing

Free Editable Download

Business Password and Authentication Policy Toolkit

Download the editable Microsoft Word toolkit and customize it for your systems, policies, MFA, passkeys, shared accounts, vendor access and offboarding.

Download the Word Toolkit
Frequently asked questions

Questions Business Leaders Ask

Are shared accounts always prohibited?

No. Some systems require them, but individual accounts are preferred because they improve accountability, MFA and access control.

Where should a shared password be stored?

Use the company-approved business password manager rather than email, chat, spreadsheets or browser storage.

When should a shared password be changed?

Rotate it after access changes, employee or vendor departures, suspected exposure and according to the system's risk and policy requirements.

Who should own a service account?

Assign both a business owner and a technical owner so the purpose, permissions and lifecycle remain clear.

Related resources

Continue Building a Stronger Password Program

STACK Cybersecurity

Protect Accounts Before Stolen Credentials Become a Business Crisis

STACK Cybersecurity helps businesses assign clear ownership for shared and service accounts, move credentials into a managed vault, configure MFA and clean up access whenever vendors or employees change.

Talk With STACK Cybersecurity