Shared Accounts: How to Control Access Without Sharing Passwords Informally
Shared accounts often exist because several people need the same system. The risk comes from how access is granted, tracked and removed. Emailing one password to an entire team isn't an access-control strategy, a shared vault folder with defined permissions is.
Use Individual Accounts Whenever the System Allows It
Individual accounts make it easier to apply least privilege, MFA and logging. When a shared or service account is unavoidable, assign an owner, store the credential in a managed vault, control who can use it, and rotate access when people or vendors change.
Named owner
Every shared or service account needs a responsible business and technical owner.
Vaulted access
Keep credentials in the approved business password manager.
Lifecycle control
Review, rotate and remove access as roles and vendors change.
How to Create a Shared Folder in Keeper
Instead of emailing a password to a team, create a shared folder in Keeper and add only the people who need it.
Create the record first
Add the account as a Login record in your own vault, with a long, unique password generated by Keeper rather than one you invented.
Create a shared folder
In the Keeper Vault, select Create New, then Shared Folder, and give it a clear name that identifies the system or team it covers.
Move the record into the folder
Drag the record into the shared folder, or use the record's sharing option to add it directly.
Add users with specific permissions
Add only the people who need access, and set whether each person can view, edit, share or manage records within that folder rather than granting full control by default.
Review membership on a schedule
Check shared-folder membership periodically, not just when someone leaves, since roles and vendor relationships change over time.
What Shared Folder Permissions Actually Control
View
Can see and use the record's credentials but can't change them.
Edit
Can update the password, username or notes on existing records.
Add and remove records
Can place new records into the folder or take existing ones out.
Share and manage
Can add or remove other users and change their permissions, usually reserved for the folder owner.
Most team members only need View. Reserve Edit, Share, and Manage for the smallest group actually responsible for maintaining the account.
Rules for Shared and Service Accounts
- Create individual user accounts instead of shared accounts whenever possible.
- Document the business purpose, owner and systems affected.
- Store the password in the approved business vault, never in email, chat or a spreadsheet.
- Use a long, unique password generated by the vault.
- Enable MFA when the system supports it and manage the authenticator centrally.
- Limit access to the smallest necessary group.
- Review use through available logs and alerts.
- Rotate the credential after employee departures, vendor changes or suspected exposure.
- Don't use shared administrator accounts for ordinary work.
- Disable accounts that no longer have a valid purpose.
What Makes Shared Accounts Dangerous
No accountability
When several people use the same username, logs may show the account activity without showing which person performed it.
Access survives employment
A former employee or vendor may retain the password unless it's rotated and their vault access is removed.
MFA belongs to one person
Shared accounts sometimes depend on one employee's phone, creating both security and continuity problems.
The password spreads
Every email, spreadsheet, text message and browser copy becomes another place the company must protect.
Put Better Authentication Rules in Writing
Free Editable Download
Business Password and Authentication Policy Toolkit
Download the editable Microsoft Word toolkit and customize it for your systems, policies, MFA, passkeys, shared accounts, vendor access and offboarding.
Download the Word ToolkitQuestions Business Leaders Ask
Are shared accounts always prohibited?
No. Some systems require them, but individual accounts are preferred because they improve accountability, MFA and access control.
Where should a shared password be stored?
Use the company-approved business password manager rather than email, chat, spreadsheets or browser storage.
When should a shared password be changed?
Rotate it after access changes, employee or vendor departures, suspected exposure and according to the system's risk and policy requirements.
Who should own a service account?
Assign both a business owner and a technical owner so the purpose, permissions and lifecycle remain clear.
Continue Building a Stronger Password Program
Protect Accounts Before Stolen Credentials Become a Business Crisis
STACK Cybersecurity helps businesses assign clear ownership for shared and service accounts, move credentials into a managed vault, configure MFA and clean up access whenever vendors or employees change.
Talk With STACK Cybersecurity