The shared password is already a staffing problem
On a small team, the same short password often lives in a group chat, a paper scrap near the register, and the owner's head. It feels efficient. Nobody wants to be the person who locked a coworker out of the supplier portal on a Saturday morning.
The trouble is not that your people are careless. The trouble is that a shared secret is also a shared leak. A former weekend hire, a contractor who finished last winter's remodel, or a phone left on the counter can still open the same door. You may not notice until an invoice is missing, a domain expires, or a customer gets a strange email that looks like it came from you.
If everyone uses one login, you cannot take access back from one person without interrupting everyone else. That is a staffing problem wearing a technology costume.
The accounts that can stop a shop from opening
Make a short list of the logins that would close the doors for a day. For many shops that is the business inbox, the payment processor, the point-of-sale dashboard, the domain registrar, and the accountant's portal. A stolen or lost inbox is especially costly, because password-reset mail for the rest of the stack lands there. Treat protect email first as a business rule, not a personal hobby.
Then add the quiet accounts: payroll, the social page that answers customer messages, shipping, and the cloud folder with contracts. These do not feel like information technology. They are still keys to money, reputation, and time.
Write one owner's name beside each account. If you cannot name an owner, the login is already drifting. Drift is how a shop keeps paying for a tool nobody can get into, or worse, a tool the wrong person can still open.
- Business email and the phone number used for password resets
- Card reader, invoicing, and payroll dashboards
- Domain, website host, and the social inbox customers actually use
One person leaves, and the login stays behind
People leave even happy teams. They take new jobs, move towns, or stop answering texts. If they still know the password to the Instagram page or the wholesale site, your access policy is a hope.
The simple habit is this: each person who needs a tool gets their own login when the service allows it. When a service forces a single shared account, store that password in a manager, change it when staff change, and keep a private note with the support number and account ID. Do not text the new password. Do not leave it sitting in last year's group thread.
That habit only works if unique passwords are easy. A dedicated what a password manager is makes the change small enough that you will actually do it on a busy Tuesday, not after a painful lockout.
Give people their own keys, even on a tiny team
A password manager is not a corporate luxury. It is a way for three people to stop recycling Shop2021! with an extra exclamation point. You remember one main password. The app holds a different long secret for the registrar, the inbox, and the card reader. Nobody on a two-person crew can memorize those on purpose. That is the point. Memory is the wrong tool.
Stax Pass encrypts each saved record on the device before anything syncs, using XChaCha20-Poly1305 (the lock on each saved record). Support cannot see those passwords or invent a spare key. The owner of the vault holds the password and the recovery phrase. That is an honest limit, and it is also why a shared master password for the whole shop is a bad idea.
If four of you need your own vaults, a family plan is $0.99 a month or $9.99 a year. Family Plus is $1.99 a month or $19.98 a year for up to eight people. Each person still signs in separately. Pricing is per plan, not one household password passed around the back office.
A one-page ownership list beats a drawer of sticky notes
You do not need a policy binder. You need a list you can finish in twenty minutes: account, purpose, owner, and where recovery lives. Keep that list as private notes next to the logins, not in a shared spreadsheet that anyone can copy or email to the wrong address.
When you hire, add the person to the tools they need that week. When they leave, change those passwords the same week you collect the keys to the shop. If a vendor only offers one user, change that shared password on the exit day and store the new one in the owner's manager.
Start with the inbox, then payments, then the domain. Those three cover most of the damage a small business actually feels. The rest can join as you use them. A toolkit is something you reach for during ordinary work, not a project you postpone until January.
Is this worth paying for?
A stolen business inbox, a domain that quietly expires, or a weekend spent on hold with a payment processor costs more than a year of a family password manager. Stax Pass includes a 45-day free trial with no credit card, so you can move the dangerous accounts first and see if the habit fits the way the shop already works.
Take this with you
- Name an owner for every account that could stop work for a day.
- Give each person their own login when the tool allows it, and change shared passwords when staff change.
- Save business email first, then payments, then the domain.
Common questions
We only have three people. Is a password manager overkill?
Three people still have an inbox, a way to get paid, and a website. Those are enough to protect. A manager is smaller than the mess of one shared password after someone leaves.
Should the whole shop use one Stax Pass account?
No. Each person should have their own login. A family plan is priced for several people, but it is not one shared vault password.
What if a vendor only allows one user?
Store that shared login in the owner's manager, keep a private note about who may use it, and change the password the week someone leaves.