Your contractor’s last day was Friday. On Monday morning you open the shared spreadsheet called “logins FINAL v3” and count: the company bank portal, the domain registrar, the Instagram account, the hosting panel, the payroll tool. Thirty-one rows. She could read every one of them. You have no idea whether she copied them, and you know you are not going to change thirty-one passwords before lunch.
That sinking feeling is the whole case for a team password manager. Not stronger passwords. Control over who knows them.
The short version: setting up a team password manager the right way means designing access before you import anything. Name an owner and a backup admin, sort shared logins into vaults or folders by job (finance, marketing, infrastructure), give each person only what their role needs, enforce multi-factor authentication, then migrate in small waves and delete the spreadsheet. Plan offboarding on day one, because that is where the real risk lives. NordPass Business is a solid fit for small teams that want a polished, easy tool with an admin panel, shared folders, an activity log and data incident monitoring. As of October 2026, its Teams plan is sold as a 10-user pack and its Business and Enterprise plans need at least 5 users. Teams that want open source or self-hosting should look at Bitwarden instead, and very small teams should price the seat minimums carefully.
Get the free "Secure Your Accounts in 30 Minutes" checklist by email. You will also get four short follow-up emails over about two weeks (passwords, two-factor, optional tools, a recap). One of them includes affiliate recommendations: if you buy through our links we may earn a commission at no extra cost to you. Unsubscribe in one click, any time.
By subscribing you agree to receive this checklist and a short email series from The Unhacked (Dr. AshR), including affiliate recommendations, at the address you enter. See our Privacy Policy.
Why small teams need a team password manager: the spreadsheet problem
Every small business ends up with the same accidental system. Logins live in a spreadsheet, a pinned chat message, a sticky note under the monitor, and the founder’s memory. It works until someone leaves, a laptop is stolen, or a impersonation scam email lands on the one person who has everything.
The real problem isn’t weak passwords. The real problem is that nobody can answer the question “who has access to what, right now?” A spreadsheet cannot tell you who opened row 14. A group chat cannot take access back. Every person who has ever seen a shared login keeps it in their head, their browser and their screenshots, indefinitely.
A team password manager fixes this by changing the unit of control. Instead of sharing the secret, you share access to a vault entry, and access can be granted, logged and revoked.
How shared business logins get stolen: the reuse machine
It helps to see what you are defending against, because it is rarely a hooded genius. It is a machine.
When any website suffers a data incident, the leaked email-and-password pairs end up in lists that circulate among attackers. Automated tools then try those pairs against other login pages: banks, email providers, hosting panels, social accounts. This is called credential stuffing, and it works silently, at scale, without anyone targeting you personally. If one of your team reused the “logins FINAL v3” password for a forum that leaked years ago, the machine will find that overlap before you do.
The second route is impersonation scam. A convincing “your domain is about to expire” email only needs to fool the one person who has the registrar password. In a spreadsheet system, that is often everyone.
You are not careless for living with a spreadsheet. You are up against automated systems built to misuse exactly that habit. The fix is structural: unique generated passwords per account, MFA everywhere, and fewer people holding the keys that matter.
How to set up a team password manager: a 6-step rollout plan
This sequence works for any serious business tool, NordPass included. Budget one focused afternoon for steps 1 to 3, then a week or two for the migration.
- Name an owner and a backup admin. Two people, never one. If your only admin is on a plane when something breaks, you are locked out of your own business.
- Inventory every shared login. Go through the spreadsheet, the chat history and your browser’s saved passwords. Mark each as personal (one user) or shared (several users).
- Design your structure before importing. Create folders or groups by function: Finance, Marketing and Social, Infrastructure (domain, hosting, DNS), Clients, Admin. Keep the bank and the domain registrar in the tightest folder.
- Enforce multi-factor authentication for every member before they get access to anything shared.
- Migrate in waves. Start with the admins, then one team at a time. Import, check that autofill works, and change any password that was ever in the spreadsheet.
- Delete the spreadsheet. Not archive. Delete, empty the trash, and tell everyone it is gone. A system with a backdoor spreadsheet is not a system.
The rule of thumb for step 3: if a folder would hurt to leak, fewer than three people should have it.
Shared vaults and access levels: least privilege without friction
Least privilege sounds bureaucratic. In a five-person team it is simply this: the social media freelancer does not need the payroll login.
A few practical patterns:
- Share by folder or group, not by individual item. When someone joins marketing, they get the marketing folder in one click instead of fourteen separate shares.
- Separate “use” from “see” where the tool allows it, so a contractor can log in without ever reading the raw password.
- Keep a short “break glass” folder (domain registrar, hosting root, bank) limited to the owner and backup admin.
- Review access every quarter. Ten minutes, once a season, to remove people from folders they no longer need.
Offboarding with a password manager: the 30-minute checklist
Here’s the thing most setup guides skip. A team password manager is an offboarding tool first and a security tool second. The day someone leaves is the day the whole investment pays for itself, so write the checklist now:
- Remove the person from the organisation in the admin panel.
- Transfer any items they owned that the business still needs.
- Review the activity log for anything they accessed in their final weeks.
- Rotate the passwords they could read in high-risk folders, starting with money and domain access.
- Revoke their sessions on any connected apps that use single sign-on.
- Note the date and what you changed, so you have a record if questions come up later.
On Monday morning, with that contractor gone, this is the difference between a two-hour checklist and a week of dread.
NordPass Business review: features, plans and limits as of October 2026
NordPass is made by Nord Security, the company behind NordVPN. Here is what its business pages stated when we checked in October 2026.
Security model. NordPass says it uses XChaCha20 encryption and a zero-knowledge architecture, meaning only the vault owner can access stored items, not NordPass. Its business page lists ISO 27001 and SOC 2 Type 2 certification and references a Cure53 security audit. These are vendor claims backed by named third parties, which is the right kind of evidence, and you can request the reports.
Plans. According to the NordPass business plans page, there are three business tiers, with 1-month, 1-year and 2-year billing on business plans:
- Teams (for small teams): sold as a 10-user pack only. Includes password generation, password sharing, offline access, user activity monitoring, security settings applied to all users, MFA, and single sign-on with Google Workspace.
- Business (for companies, 5 users minimum): everything in Teams, plus group-based sharing, sharing by folder, password strength monitoring, data incident monitoring, and a Vanta integration for compliance evidence.
- Enterprise (5 users minimum): everything in Business, plus centralised tracking of shared credentials, single sign-on with Microsoft Entra ID, Microsoft ADFS and Okta, automatic user access management through Entra ID and Okta, and integrations with Microsoft Sentinel and Splunk.
The page also describes an Activity Log, a Data incident Scanner that alerts you when company email addresses or domains appear in known data incidents, import from browsers, CSV files or other password managers, round-the-clock live chat support, and a 14-day free Business trial.
Price. Per-seat prices loaded dynamically on the pricing page and were being discounted with a seasonal promo code when we checked, so we are not quoting a figure that may already be stale. Check the current NordPass Business plans and compare the per-seat price over the full term, not the first-year rate.
Is NordPass Business right for your team? Who should pick something else
NordPass Business is a strong choice when:
- You have 5 to roughly 50 people and want a tool non-technical staff will actually use.
- You want shared folders, an activity log and data incident monitoring without running your own server.
- You already use Google Workspace, so the Teams plan’s SSO fits.
Pick something else when:
- You are two or three people. The Teams plan is a 10-user pack, so you pay for seats you do not use. A family or individual plan elsewhere may be enough for now.
- You want open source or self-hosting. NordPass is sold as a hosted cloud service, and we found no self-hosting option on its business plan pages. Bitwarden says its source code is public on GitHub and the whole stack can be self-hosted with Docker; our Bitwarden review covers that path.
- You need Entra ID or Okta single sign-on and automatic provisioning. On NordPass that is Enterprise-tier territory, so price it at that level from the start.
- You are still deciding between the big names. Our side-by-side of NordPass vs Bitwarden vs Proton Pass is the faster way to choose.
Frequently asked questions
What is the minimum number of users for NordPass Business?
As of October 2026, the Teams plan is sold as a 10-user pack, and the Business and Enterprise plans each require at least 5 users. Check the live pricing page before you buy, as plan rules can change.
Can NordPass see our company passwords?
NordPass states that it uses a zero-knowledge architecture with XChaCha20 encryption, so only vault owners can decrypt stored items. That is a vendor claim; its business page lists ISO 27001, SOC 2 Type 2 and a Cure53 audit as supporting evidence.
Is there a free trial of NordPass Business?
Yes. In October 2026 NordPass offered a 14-day free Business trial. Use it to run the rollout plan above with two or three people before committing the whole team.
What happens to shared passwords when an employee leaves?
You remove them from the organisation in the admin panel, which revokes their access to shared items. Then rotate any high-risk passwords they could read, because access to a vault entry today does not erase what someone saw yesterday.
Your first step: one owner, one folder, one afternoon
You do not need to migrate the whole company this week. Name your backup admin today. Then create a single folder for the five logins that would hurt most to lose: bank, domain, hosting, email admin, payroll. Move those first, change their passwords, and make sure two people can reach them.
If NordPass fits your team’s size and tools, start the NordPass Business trial and run that first folder through it. For background on the personal product, see our NordPass review.
The next time someone leaves, you will not be counting rows in a spreadsheet. You will be the owner who opens one panel, takes access back, and gets on with the day, fully in control of the keys to your own business.
The Signal - free dispatch
One practical email that makes your digital life calmer. Checklists, tool cautions, plain-English decisions. No noise.
Free. No spam. Unsubscribe any time.
Join the Inner Circle
Weekly dispatches. No algorithms. No surveillance. Just sovereign intelligence.
Zero spam · Fully private · Sovereign by design.