Choosing a Password Manager: A Practical Checklist
Feature lists all look the same. Use this checklist to compare vaults on recovery, sharing, MFA, and admin controls that small teams actually need.
Part of the Business Cybersecurity Basics series. Start here: Cybersecurity checklist for small businesses.
Every password manager claims military-grade encryption on the homepage. Your decision will turn on boring details: who can reset access when someone leaves, how sharing works, and whether the browser extension will annoy people into quitting.
Must-haves
- Strong master password or passphrase support - generate candidates with Passphrase Generator or Password Generator.
- MFA on the vault itself.
- Apps for the OSes your team actually uses.
- Secure sharing for company logins (not emailing passwords).
- Export that you control - avoid lock-in without an exit.
Team admin questions
- Can owners revoke a user in under five minutes?
- Are there audit logs for shared vault access?
- Is there a documented account recovery path that isn’t “tweet support”?
- Can you separate personal and work vaults cleanly?
Usability - the quiet requirement
If autofill fails constantly, people revert to reused passwords. Trial the extension on your real sites: banking quirks, SSO flows, mobile Safari. A prettier UI loses to a tool the team will live in.
Threat assumptions
Cloud-synced vaults are convenient; some regulated teams want self-hosted. Know which you are before demos dazzle you. Neither choice removes the need for device hygiene and phishing awareness covered in MFA and password hygiene.
Migration plan
- Pick a pilot group.
- Import, clean duplicates, delete junk.
- Rotate shared credentials as you touch them.
- Turn on MFA everywhere you store a login.
- Schedule a 30-day check: who’s not using it and why?
Spot-check new passwords with Password Strength during training so people see what “good” looks like.
Trial scorecard (copy into a spreadsheet)
- Setup time for a new teammate (minutes).
- Autofill success on five critical sites.
- Mobile sign-in reliability.
- Sharing a credential with least privilege.
- Admin offboarding steps counted.
- Export completeness.
- Support response quality during trial.
Weight the rows for your risks. A design studio cares about sharing mockups logins; a clinic cares about audit logs and retention.
Budget honesty
Paid seats are cheaper than one breached inbox. Still, don’t buy enterprise SKUs you won’t administer. Choose mid-tier features you’ll turn on in the first month. Unused SSO integrations aren’t security.
Family versus work vaults
Encourage personal vaults for personal life - separately. Mixing forever-personal logins into company vaults creates offboarding messes and ownership fights. Clear policy beats polite confusion.
Field notes from teams who shipped this
The pattern that keeps showing up: write the constraint first, then the steps, then the failure modes. Teams that only publish happy-path screenshots create tickets. Teams that document the ugly path create trust.
Schedule a short review ninety days after publishing. Check whether product UI names still match, whether linked tools still exist, and whether support still hears the same questions. Update the page or merge it. Standing still is how useful posts become interchangeable again.
If you adapt this article for internal wikis, keep the examples tied to your stack names. The moment you generalize back to “best practices for organizations,” you’ve started erasing the specificity that made the piece worth saving.
Browser extension threats
Autofill phishing pages that look like your bank are a known risk class. Prefer managers that match origins strictly and teach users to spot near-miss domains. Some teams disable autofill on high-risk categories and use copy buttons instead.
Keep extensions updated. Pin versions in managed browsers when you can. A password manager extension with a stale XSS is an irony you don’t want in the postmortem.
Review admin settings for vault export permissions. Not every teammate needs one-click export of the company shared folder.
Finally, document emergency access: who can recover the company vault if the primary owner’s device falls into a river. Romantic, but it happens.
Exit drill
Before you fully commit, export from the trial vault and import into a competitor or a local backup to prove the exit path. Vendors rarely advertise friction; you should discover it on purpose.
Schedule an annual export even when happy - backups of vaults belong in your continuity plan beside database dumps.
Compliance questions to ask vendors
- Where are vaults stored, and is there regional choice?
- What’s the history of security disclosures and response times?
- Can we SSO with our IdP and enforce MFA at the IdP?
- How is customer data separated in multi-tenant cloud?
- What admin roles exist beyond “everyone is owner”?
Write answers into your vendor file. Future you will not remember the sales call.
If a vendor can’t answer plainly, treat that as data - not as mystery prestige.
Rollout communications that don’t flop
Announce the why in plain language: fewer shared passwords, faster offboarding, less “reply-all with the login.” Give a two-week parallel period where the old spreadsheet still exists but is marked deprecated. Then delete the spreadsheet with ceremony so everyone notices.
Offer office hours for the first Fridays. Most resistance is fear of getting locked out, not love of sticky notes. Sit with people while they enroll MFA on the vault - that single gesture raises adoption more than another email.
FAQ
Are free tiers okay?
For solo use, often yes. For teams, pay for admin controls and sharing that won’t collapse on a personal plan.
What about built-in browser managers?
Better than nothing for individuals. Teams usually outgrow them when sharing and offboarding appear.