Shared password management for IT teams: getting passwords out of Excel and WhatsApp
Shared password management for IT teams in Indian companies: safes, reveal with a reason, check-out, break-glass, audit logs and what to rotate on an exit.
Last checked 5 min read
Ask any IT head in a mid-sized Indian company where the firewall password is, and the honest answer is often "in an Excel file on the shared drive", or "the network guy knows". Shared accounts are unavoidable: routers, CCTV recorders, domain admin, cloud consoles, the EPFO and ESIC employer logins, the GST portal. Shared password management for IT teams is about keeping those shared, but never loose.
Why the spreadsheet stops working
A spreadsheet of passwords has three problems that show up at the worst moment:
- No record of who looked. When something goes wrong, nobody can say who opened the firewall password last week.
- No clean exit. When the network admin leaves, you cannot tell which of 140 passwords he actually used, so either you change all of them or none.
- Copies everywhere. The file gets emailed, downloaded and pasted into WhatsApp. Each copy is a leak waiting to happen.
There is a compliance angle too. CERT-In's directions of April 2022 ask organisations to keep logs of their ICT systems for 180 days within India and to report specified cyber incidents within six hours. The DPDP Act asks for reasonable security safeguards for personal data, and many shared logins, HRMS admin, payroll and the statutory portals, open exactly that data.
Shared password management for IT teams: the building blocks
A good setup has a handful of parts. You can build some of them with process alone, but a proper tool makes them stick.
Safes, not one big list. Group credentials by team or system: Network, Servers, CCTV and access control, Statutory portals, Vendor portals. Give each safe its own members.
Access by role, with levels. Not everyone who needs to use a password needs to edit or share it. Four levels work well: view metadata, use or reveal, edit, and manage members.
Reveal with a reason. Every time someone reveals a password, they type why, or a ticket number. It takes five seconds and changes behaviour more than any policy document.
Approval for the sensitive ones. For domain admin or the firewall, require a manager's approval for time-limited access, say two hours.
Check-out and check-in. For the most privileged accounts, a person checks the password out, uses it, checks it back in, and the password is changed afterwards. Nobody keeps a working copy.
Break glass access. At 2 a.m. the plant's network is down and the approver is unreachable. Break-glass lets the on-call engineer open the credential anyway, with a loud trail: the event is logged and managers are told immediately.
A privileged access audit log. Who opened what, when, from where, with what reason. Keep versions too, so an old password can be recovered if a change goes wrong.
Password sharing policy: one page is enough
Write it down, keep it short, and make it the thing people actually follow:
- Shared credentials live only in the password manager. Not in Excel, email, chat or notebooks.
- Every reveal has a reason or a ticket number.
- Domain admin, firewall and cloud root need approval and are changed after use.
- Break-glass is for emergencies only, and every use is reviewed within a working day.
- Passwords are checked for strength, reuse and age every quarter.
- Access is removed the day someone leaves or changes role, and the credentials they used are changed.
- Multi-factor sign-in is required for the password manager itself.
Rotate passwords when an employee leaves
This is where most companies fail. A worked example:
A 250-person company in Ahmedabad has a three-person IT team and about 140 shared credentials. The network admin resigns, with a last day of 15 November.
- Same day as the exit: his access to every safe is removed, along with his VPN and email.
- Within a day: the IT head looks at what he revealed in the last 90 days. It is 23 credentials: the firewall, two switches, the Wi-Fi controller, the CCTV recorder, the cloud console and the EPFO employer login, among others.
- Within a week: those 23 are changed, highest risk first. The other 117 go into the normal quarterly review.
Without a reveal history, the honest choice would have been to change all 140, which in practice means changing none.
Linking this to the HR exit process helps. When HR marks an exit, IT gets the list automatically instead of hearing about it at the farewell lunch. The same exit checklist should catch company laptops and phones that have not come back; see asset physical verification.
Ask your vendor how encryption works
Password managers differ in who holds the keys. Some encrypt on your device with a key the vendor never sees. Others encrypt on the server with a key held for your company. Both can be secure, with different trade-offs: server-side keys make features like approvals, break-glass and leaver checks easier, while device-side keys reduce what a breach of the vendor could expose.
Ask any vendor to explain its model plainly, and do not accept vague marketing words in place of an answer.
A quick self-check
- Can you list every shared credential, by safe?
- Can you tell who revealed the firewall password last month, and why?
- Can you produce, within an hour, the list of passwords a leaver used?
- Is break-glass possible, and is every use reviewed?
- Is MFA on for the password tool itself?
If two or more answers are no, start with the inventory this week. Employee data handled through these accounts has its own rules; see the DPDP Act for HR, and for the front desk, visitor management and DPDP.
Vatsin Password Manager gives IT teams shared safes with four permission levels, reveal with a reason, approval for timed access, check-out and check-in, break-glass, a full audit log with versions, and leaver checks linked to HR. Passwords are encrypted with a key for your company only, held on our servers, and we will walk your team through exactly how that works.