Skip to main content
MAG&Cie
Back to tutorials
FreeBeginnerAdmin & Compliance

Password Vault for Business: The SMB & Small-Business Guide

The real risk isn't a hacker stealing your passwords. It's that a critical account — bank, domain, hosting — is held by a single person. The day they leave, no one can log in. SMB guide to turn this single point of failure into a process.

August 18, 202625 min

What you'll learn

  • Identify single-point-of-failure access accounts in your business
  • Answer the three diagnostic questions in under 15 minutes
  • Build a working critical-access inventory (five-column table)
  • Decide between a shared vault and individual vaults
  • Set objective criteria to choose a tool without being driven by price alone
  • Prepare a departure (partner, employee, contractor) before it happens

Prerequisites

  • Run or manage a small business without a dedicated IT department
  • Have at least one critical account (online bank, hosting, domain registrar, invoicing tool) and know who holds its password today
  • Have a professional email address to receive the vault invitation
On this page11

The real risk of your business passwords isn't a hacker stealing them. It's that a critical account — the business bank, the domain registrar, the hosting console, the invoicing admin — is held by a single person. The day that person leaves, gets sick, or loses their phone, no one can log in. It's a business continuity problem, not a spectacular cybersecurity one, and it affects every small business without a dedicated IT department.

The real problem: single point of failure

A single point of failure is an access account whose unavailability halts all or part of the business. No attack is needed for it to fall. A lost phone, a hacked mailbox, a sudden departure, a dispute with a former partner are all it takes.

Four concrete examples, all seen in real small businesses:

  • The domain registrar. The domain auto-renews on the personal credit card of one person whose mailbox is no longer read. The renewal fails. The domain expires. The site goes down, email stops flowing, the brand becomes claimable by anyone.
  • The hosting console. The partner who installed the site five years ago is gone. They set up the account under their personal name. No one else can change DNS or migrate.
  • The invoicing admin account. The long-time bookkeeper manages access alone. She goes on extended leave. No user can be added, no template edited, no URSSAF export resumed.
  • The SaaS vendor billing account. The monthly charge for a business tool fails. The vendor cuts access. Operations stop while you hunt for who, in the company, had the card on file.

None of these incidents make headlines. Each of them costs several days of productive activity.

The three diagnostic questions

Answer these three questions now, before reading further. They take fifteen minutes. If you can't answer, that's already a signal.

  1. How many critical accounts are held by a single person? Count the accounts whose unavailability would halt the business. Count only those held by a single person. That's your active single-point-of-failure count.

  2. How many accounts share one password, never changed, known to several people? The CRM admin with a password pasted in a team chat. The generic mailbox whose password is the company name followed by a year. Count them. That's your ungoverned secrets count.

  3. Who in the company can produce, in five minutes, the full list of critical accounts? If it's one person only — often the owner, or the historical IT contact — the inventory doesn't exist. It lives in someone's head.

Those three numbers are enough to decide whether the topic is urgent or not.

What to centralize: the critical-access inventory

Before choosing a tool, build the inventory. It's the one step that cannot be delegated — you're the only person who knows what's strategic to your business. Use a five-column table, no more.

DomainAccount namePrimary holderBackup holderImpact if lost 48h
Domain & DNSRegistrar (e.g. OVH, Gandi, Cloudflare)OwnerPartnerWebsite down, email cut
HostingCloud console / hosting providerTechnical contractorOwnerCannot deploy or restore
Primary emailAdmin console (Google Workspace, Microsoft 365)OwnerHR leadInvoices and official mail no longer received
Business bankBusiness accountOwnerSecond signatoryPayroll, direct debits, incoming transfers stopped
Accounting / invoicingInvoicing tool, bank, URSSAFBookkeeperOwnerInvoice issuance and filings frozen
Business toolsERP, CRM, planning, POSOperations leadOwnerDaily production slowed or stopped
Technical accountsAPI keys, service accounts, certificatesTechnical contractorOwnerThird-party integrations cut silently

The table lives in a shared file on the company drive. It lists categories, not passwords. It's updated as soon as a critical account is created or removed. It's the basis for any future tool migration, business handover, or due diligence.

Governing access: shared vault, individual vaults, folders

A business password vault is not a pile of passwords. It's a folder hierarchy with explicit access rules.

Shared vault vs individual vaults

  • The shared vault holds access that must survive one person leaving: ERP admin account, business bank, hosting console, SaaS vendor accounts. These secrets belong to the business, not to a person.
  • The individual vaults hold professional-personal access: the person's own email, accounts created under their name, personal passwords used at work (e.g. a SaaS account tied to their address). These leave with the person — inside a clear legal frame, written in the IT charter.

Both coexist in the same tool, in separate spaces. An employee should not see, in their individual vault, shared secrets that don't concern them.

Folders, by scope

In the shared vault, structure by business scope, not by tool:

  • Finance & Leadership: bank, accounting, invoicing, URSSAF, taxes.
  • Infrastructure & IT: domain, DNS, hosting, backups, service accounts.
  • Business tools: ERP, CRM, planning, e-commerce platform, POS.
  • Communication & Marketing: social platforms, email marketing, analytics.
  • HR: HRIS, employee vault, health insurance, training.

Every folder has a list of users who can read, a shorter list who can write, and two administrators who manage invitations.

The two administrators of the vault itself

The vault needs at least two administrators:

  • On two distinct email addresses owned by the business;
  • With two-factor authentication enabled on different devices;
  • With a documented emergency recovery kit stored offline (sealed printout, physical safe, notary or trusted deposit).

A single administrator is the single point of failure moved up, not solved.

Choosing a tool: decision criteria

Four categories of tools exist. Each has a use case. Don't hunt for the "best" tool; find the category that fits your team and technical appetite.

  • Local vaults, encrypted file. An encrypted file shared through a drive or a private repo. Simple, free, no account required. Good for a solo owner or a technical duo. Poor for granular sharing above two people.
  • Consumer cloud vaults used at work. Family and small-team plans of well-known market editors. Good feature-to-price ratio for three to ten users, with per-folder sharing. No SSO, limited audit logging.
  • Business cloud vaults. "Business" or "Teams" plans from the same editors. Add SSO (login via Google Workspace / Microsoft 365), automated provisioning, detailed logging, organization policies. Suitable from ten to fifteen users on, or earlier if you face traceability requirements (public procurement, sensitive subcontracting).
  • Self-hosted vaults. Open-source solutions deployed on your own server. Low direct cost, high indirect cost (maintenance, backups, security updates). For businesses with a dedicated technical lead, either in-house or under contractor SLA.

Five criteria to arbitrate, in decreasing order of importance

  1. Data hosting location. European Union or outside. EU hosting simplifies GDPR compliance evidence and removes the need to document international transfer impact assessments. Check the contract, not just the marketing page.
  2. Documented recovery procedure. What happens if the sole administrator loses their master password and phone? Does the editor publish a clear procedure? Does it rely on an offline emergency kit, or on the second administrator? Reject any tool whose recovery procedure isn't written explicitly.
  3. Sharing granularity. Can you share a folder, a subfolder, a single secret? Can you distinguish "read", "use without seeing", "edit"? These matter the day an intern needs a temporary access.
  4. Export and reversibility. Can you export the full vault in a documented format (encrypted CSV, JSON), any time, without extra cost? If not, you're locked in.
  5. Real cost per user. Compare the plan that actually includes the features you need, not the entry-level one. Add the cost of invited users (external accountant, technical contractor, lawyer) you didn't count at first.

The offboarding procedure

A departure is prepared before it happens. Whether it's an employee, a partner, a contractor or an intern, the procedure is the same. It kicks in the moment the exit date is known.

  • D-30 (as soon as the departure is announced). Extract from the vault the list of folders and secrets accessible to the leaving person. For every critical access, identify a named successor. Document the third-party integrations where their personal email address appears as a recovery contact.
  • D-15. Rotate passwords on critical access the person no longer needs in the last two weeks. Hand over shared folders to their named successor. Revoke write access, keep read where useful, until the last day.
  • D-7. Go account by account through the accounts created under their personal name but used by the business. Migrate to a named business account of the successor or to a generic business account. Log the migration in the inventory.
  • D-1. Final rotation of remaining critical passwords. Full removal of vault rights. SSO deactivation (Google Workspace, Microsoft 365). Retrieve devices issued by the business.
  • D+1. Audit residual access: is the person still listed as recovery on external accounts (bank, SaaS platforms)? Are bank notifications still hitting their phone? Are their remaining 2FA tokens revoked server-side?

The number of days can be compressed for a conflictual or sudden departure. The list of gestures cannot. Every skipped gesture becomes an exploitable residual trace or a future blocker.

Final checklist

  • Three diagnostic questions answered with precise numbers.
  • Five-column critical-access inventory in a shared file, kept up to date.
  • Business vault in place, with two independent administrators and an offline emergency recovery kit.
  • Clear separation shared vault / individual vaults, documented in the IT charter.
  • Folders structured by business scope, with correct rights for read, use, edit.
  • Tool chosen on five written criteria, EU hosting verified, recovery procedure read.
  • Offboarding procedure printed, known to leadership, applicable in thirty days.
  • Next audit scheduled in six months, in a calendar reminder.