Physical Address
304 North Cardinal St.
Dorchester Center, MA 02124
Physical Address
304 North Cardinal St.
Dorchester Center, MA 02124

For years, our agency handled credentials in a way that probably sounds familiar to plenty of small businesses: a shared spreadsheet, a few sticky notes, scattered saved passwords, and a generous amount of trust. That approach seemed manageable until a former contractor still had access to an ad account and a phishing email made me take a closer look at how we handled credentials.
Client dashboards, advertising accounts, hosting panels, domain registrars, and other business systems were being treated far too casually. I eventually realized that we needed a proper system, not another temporary workaround. Here’s how I rebuilt our credential management with password manager apps, what changed afterward, and what I learned during the process.
An agency can accumulate an enormous number of logins because it manages systems belonging to both the business and its clients. Our list included Google Ad Manager accounts, hosting control panels, WordPress sites, domain registrars, payment gateways, and social media accounts. At one point, our small team was regularly using more than 140 separate credentials.
The problem became obvious when a former contractor still had one of our ad-account logins sitting in an old email conversation months after their contract ended. There was no malicious activity, but the situation exposed a bigger issue: we had no reliable idea where all our credentials had ended up.
Old emails, shared documents, chat histories, personal notes apps, browser autofill, and even devices that had already been sold could potentially contain access information. For an agency, that isn’t merely an internal security problem. A compromised credential can potentially expose the accounts and systems belonging to multiple clients.
Rather than choosing a tool based solely on popularity, I first listed the capabilities that mattered for an agency:
I used those criteria to test several password managers over a period of a few months, including individual trials and team-wide pilots.
1Password was the first major contender and quickly became popular with the team. Its interface is straightforward enough for non-technical employees to understand without extensive training, while its browser extension handled autofill reliably, including more complicated login forms.
For our agency, the shared vault system was particularly useful. We created separate vaults for individual clients and additional internal vaults covering areas such as finance, marketing tools, and infrastructure. Employees could then be given access only to the areas relevant to their responsibilities.
That setup also worked well with freelancers. Someone brought in for a single project could receive access to one client vault and have that access removed when the project ended without affecting the rest of the system.
1Password’s Watchtower feature was another useful discovery. It identifies weak or reused passwords and alerts users to credentials associated with known breaches. Our initial scan uncovered more password reuse than I expected, which made the value of the audit immediately obvious.
The biggest drawback for us was price. Costs increase as the team grows, and it isn’t the cheapest option available. For our agency, however, the additional expense made sense.
Bitwarden stood out because of its open-source approach and relatively low cost. Its free version is useful, while the business plans cost considerably less than some competing services. That makes it a practical starting point for smaller agencies that are beginning to formalize their credential security.
Its organization system provides shared collections that can be assigned to particular users or groups. The interface isn’t quite as polished as 1Password, and self-hosting requires more technical knowledge. Teams that don’t want to maintain their own infrastructure can simply use the hosted version.
For us, Bitwarden’s limitations appeared in areas such as detailed permissions and the depth of audit information available compared with 1Password’s business offering. That difference mattered for an agency handling sensitive client infrastructure, so we didn’t make it our primary solution. Still, its combination of features and price makes it a strong alternative for budget-conscious teams.
Dashlane initially caught our attention because of its dark web monitoring. Instead of requiring someone to manually check for compromised credentials, the service monitors for credentials appearing in breach-related data and provides alerts.
Its business plan also includes a VPN, which was useful for employees occasionally accessing client systems from unfamiliar or public networks. The interface is polished, and the mobile experience was smooth.
We ultimately chose not to make Dashlane our main password manager because its team-management approach didn’t feel quite as suited to our need for detailed, client-by-client separation. That doesn’t make it unsuitable for agencies; teams that place greater importance on dark web monitoring and VPN functionality may have different priorities.
Keeper takes a more security-focused, enterprise-style approach. Its compliance certifications can be particularly relevant for agencies serving regulated clients in areas such as finance or healthcare. It also provides extensive role-based access controls for teams that need highly specific permission levels.
The downside for our agency was complexity. Configuring Keeper properly requires more time, and its interface feels more oriented toward larger organizations than smaller teams that simply need quick access to credentials.
For an agency with dedicated IT resources, that additional control may be useful. At our size, we found the setup more involved than necessary.
NordPass, developed by the team behind NordVPN, also made our shortlist. It uses the XChaCha20 encryption algorithm and integrates naturally with other Nord products. Its business functionality has less depth than some longer-established competitors, but the service is developing and its pricing remains competitive.
We ultimately selected 1Password as our primary password vault. We also maintained a documented Bitwarden setup as a backup and allowed a couple of team members to use it for personal purposes alongside the agency system.
Three factors drove the decision. First, organizing vaults around individual clients matched the way our agency already worked. Second, the audit trail gave us a concrete way to address client questions about credential security. Third, the team actually liked using it.
That last point turned out to matter. A security tool doesn’t accomplish much if employees abandon it and return to spreadsheets, browser storage, or messages because those options feel easier.
I had no intention of manually entering more than 140 logins. Most password managers provide import features for browser-stored credentials or CSV files exported from another manager, which significantly reduced the workload.
We also used the migration as an opportunity to clean up our entire credential system:
That cleanup may have produced a larger security improvement than simply installing a password manager. The software gave us the framework, but the real benefit came from reviewing every account and access permission.
The first improvement was surprisingly simple: people stopped asking one another where particular passwords were stored. Team members also stopped sending client credentials through Slack simply because it was convenient.
New-hire onboarding became much faster. Instead of spending part of a day tracking down individual logins, we could assign the appropriate vault access in about fifteen minutes. Offboarding became similarly straightforward because access could be revoked centrally rather than relying on someone to remember every account that needed changing.
Client conversations improved as well. Instead of vaguely saying that we were careful with credentials, we could explain that access was managed through an encrypted, permission-controlled vault with an audit trail. For clients concerned about who can access their systems, that specificity was valuable.
If your agency still manages passwords through spreadsheets, emails, notes, or scattered browser storage, you don’t necessarily need to find one universally “correct” password manager. The established options can all provide meaningful security improvements.
The more important step is completing the migration, reviewing permissions while you do it, and selecting a platform your team will consistently use. A password manager only helps when it becomes part of the normal workflow. Once using it becomes automatic rather than optional, credential security stops feeling like another project and becomes part of the agency’s everyday routine.
Moving our agency’s 140+ credentials into a structured password-management system eliminated a large amount of unnecessary risk and friction. The biggest gains came from centralized access, faster onboarding and offboarding, unique passwords, and finally knowing who could reach which client accounts. The software mattered, but the security audit we completed during the migration mattered just as much.