Give Access, Keep Control: Shared Vaults for Small Teams and Businesses
Every small team shares logins, the analytics account, the domain registrar, the shared inbox, plus contracts and licenses. Usually over chat and a spreadsheet. Here is how to give the right people access, end-to-end encrypted, and take it back the day someone moves on.
A founder's password problem is not the same as a big company's. You do not have an IT department or an SSO budget; you have five people, forty shared logins, and a growing pile of contracts. So the credentials end up in a pinned chat message, a shared note, or a spreadsheet named passwords_final_v2. It works until someone leaves, and then no one is quite sure what they still had access to.
A shared vault is the small-team answer: real end-to-end encryption, no admin console to run, and the one thing a spreadsheet can never give you, the ability to actually take access away.
Key takeaways
- Put shared company logins, contracts, and licenses in a shared vault instead of chat and spreadsheets.
- Each teammate opens it on their own device with their own biometrics; everything is end-to-end encrypted.
- No admin console, no per-seat account, no server. It is peer-to-peer sharing between people's own apps.
- Offboarding is a single action: remove the person, which rotates the key so they lose access to anything written afterward.
The real risk is offboarding, not onboarding
Giving someone a password is easy. The dangerous part is the day they leave, when a shared spreadsheet means their access simply continues, and "we should change those passwords" becomes a task nobody owns. Most credential leaks at small companies are not dramatic hacks; they are old access that was never cleaned up.
The question is not "can I share this login?" Anyone can. It is "can I be sure this person cannot use it next month?"
A shared vault is built around that question. Because removing a member rotates the vault's encryption key and re-seals it only to the people who remain, offboarding is real: the former teammate cannot read records written after they are out, even if they held onto a device. It is the difference between crossing a name off a list and changing the lock.
Set up a business vault
- Create a separate vault for the business, so it never mixes with your personal logins. Open Manage Vaults and choose Create Shared Vault.
- Add the shared credentials, or pull existing ones over with Move or Copy Items. Give each a strong, unique, generated password so the whole team benefits.
- Tap Create & Invite and send invitations to your teammates through the share sheet.
- Manage the roster from the members list: see who can open the vault, and remove anyone when the time comes. Only the owner can invite or remove people.
Keep the business and personal apart
You do not want your personal banking login in the same place your contractor can reach. With multiple vaults you share only the business vault; your personal vault stays invisible to the team, and anything especially sensitive can live in a sensitive vault that cannot be shared at all. One app, clean boundaries.
| Spreadsheet or chat | Shared vault |
|---|---|
| Plaintext credentials, copied everywhere | End-to-end encrypted; cloud sees only ciphertext |
| Everyone sees everything, forever | Owner-controlled membership, revocable |
| Offboarding means "change all the passwords, somehow" | Remove the person; the key rotates automatically |
| No record of who could open what | A clear members list on the vault |
If your bigger concern is getting company documents out of email in the first place, pair this with getting your licenses, contracts, and logins off email.
Share the company logins. Own the off-switch.
Give your team a shared, end-to-end encrypted vault, and take access back the day someone leaves, no admin console required. On iPhone, iPad, and Mac.
Explore Kinship Vault