For a small business or a creator with helpers, choose a password manager that offers shared vaults you control, access you can withdraw person by person, passkey storage and a plan for emergencies. 1Password and Bitwarden both sell team plans built for that; Apple Passwords and Google Password Manager cost nothing but share only within Apple groups you invite people to or your Google family group. Whichever you pick, keep personal, owner-only and team logins in separate vaults, and change every shared password when someone leaves.
This page covers the password manager itself. Authenticator apps, recovery codes and phone-number protection are in our SIM swap protection guide, and handing platform access to a manager or agency is covered by the agency account access checklist. Prices and features below come from vendor pages read on 2 October 2026.
What a creator business needs from one
The Australian Cyber Security Centre's page on password managers is a good baseline. It suggests checking for encryption, multi-factor authentication to open the vault, syncing between devices, breach alerts and browser autofill, and it warns that password managers are attractive targets, so the master passphrase should be the strongest one you can remember. It also makes two points that matter for a business: consider a separate vault for high-value accounts, and check your bank's terms, because some providers may not cover losses if the password was stored in a password manager.
- Sharing that never requires giving anyone your master passphrase or your own login to the manager.
- Access you can withdraw from one helper without disturbing anyone else.
- Storage for passkeys as well as passwords, since more platforms now offer them.
- A documented route for a trusted person to reach essential logins if you are unavailable.
- A plan you can afford for the number of people who actually need access.
Sharing, passkeys, emergencies and price
Prices are in US dollars, billed annually and before tax, as each vendor's page showed them on 2 October 2026. 1Password labels its personal prices a current promotion, so the regular price is shown too.
| Plan | How sharing works | Emergency or recovery route | Price shown |
|---|---|---|---|
| 1Password Individual and Families | Families adds shared vaults for up to five invited members; any plan can send an expiring item link | A family organizer can recover a member's account | Individual $2.99 a month on promotion, $3.99 regular; Families $4.49 on promotion, $5.99 regular |
| 1Password Teams Starter Pack and Business | Shared vaults with role-based permissions for a small team | Team owners and administrators can recover member accounts | Starter Pack $24.95 a month for up to 10 members, extra seats $4.99 each; Business $8.99 per user a month |
| Bitwarden Free, Premium and Families | Premium shares with one other user; Families shares between six people | Emergency access to a trusted contact, on Premium and paid organisations | Free tier available; Premium $1.65 a month; Families $3.99 a month for up to six users |
| Bitwarden Teams and Enterprise | An organisation with collections, groups and event logs | Administrator account recovery, which Bitwarden suggests for staff offboarding | Teams $4 and Enterprise $6 per user a month |
| Apple Passwords | Shared groups with an owner and members, on iOS 17, macOS 14 or later | Legacy Contacts cannot reach passwords or passkeys in iCloud Keychain | Included with Apple devices |
| Google Password Manager | A copy of a password, shared only with members of your Google family group | Not covered on the help pages we read | Included with a Google Account |
All four store passkeys. 1Password treats a saved passkey like any other item, so it can be moved or shared; Bitwarden saves and autofills passkeys under its end-to-end encryption; and Google Password Manager and Apple Passwords sync them across signed-in devices. The emergency column matters more than it looks. Apple's Legacy Contact page lists iCloud Keychain passwords and passkeys among the data a Legacy Contact cannot access, so a creator relying only on Apple Passwords needs another way to pass on business logins. Bitwarden's emergency access offers view or takeover access after a wait time you set, and 1Password's recovery page advises having at least two people who can recover accounts.
Setup order for the first week
The ACSC's advice is to start with your most important accounts, generate a new unique password for each, then turn on multi-factor authentication where the account offers it. For a creator business, that suggests an order.
- Create the manager account with a long random-word passphrase, switch on multi-factor sign-in for the manager itself, and never let a browser save that passphrase.
- Move your email accounts in first, since every other reset routes through them.
- Add payout, banking and subscription platform logins next, each with a freshly generated password.
- Work through social, scheduling and design tools, deleting each password from the browser's own store once it is in the manager.
- Build the vault structure below before inviting anyone, so the first helper only ever sees the team vault.
Item sharing versus handing over a login
Pasting a password into a chat leaves a permanent copy in someone else's message history, outside anything you can revoke. A password manager gives you three better options, and a fourth that beats all of them.
- Use the tool's own team seats or roles first. When a scheduler, design tool or platform lets you invite a helper under their own name, no password changes hands at all.
- Use a shared vault or collection for ongoing work, so the helper always sees the current password and you can remove them in one step.
- Use an expiring link for a one-off. 1Password item sharing sends a copy that expires when you choose and can be limited to named email addresses, though later edits are not passed on. Bitwarden Send adds passwords and access limits, with a lifespan of 31 days at most.
- Hand over a full login only when nothing else exists, and treat it as temporary: plan the password change before you share it.
Remember that anything done with a shared login is recorded as you. Platforms that support delegated access or roles give you a cleaner record of who did what, which matters if a post, a refund or a payout change is ever disputed.
Vault structure template
Set vaults up by who may open them, not by app category. Then every access decision becomes a question of which vault an item belongs in.
| Vault | Who can open it | What goes in it | House rule |
|---|---|---|---|
| Personal | You alone | Personal email, banking, health, family and government logins | Never shared, never mixed with work items |
| Business, owner only | You, plus your emergency contact through the manager's emergency feature | Primary business email, subscription platform logins, payout accounts, domain registrar, telco account for the business line | Helpers work through roles or the team vault instead |
| Team shared | You and named helpers | Logins for tools that have no per-person seats, such as a shared stock library | Each item has an owner and a reason, noted in the item |
| One vault per helper | You and that one person | Items only their tasks need | Offboarding becomes one removal plus a known rotation list |
| Emergency instructions | You, and your trusted contact after an approved request | A secure note on where things live, who your accountant and telco are, and what to pause | Reviewed whenever your setup changes |
Store your business line's number, telco PIN and account details in the owner-only vault; our guide to a second phone number for creators explains why that line should stay out of public view. Where to keep recovery codes, which should never sit inside the account they restore, is set out in the SIM swap guide linked above.
Offboarding checklist when a helper leaves
Removing someone from a vault does not remove what they already saw. Apple's guide to managing shared passwords says a person removed from a shared group may still have access to the accounts shared while they were in it, and that you should change those passwords. The same logic applies to every manager.
- Remove the person from the team or family account and from every shared vault and collection on their last day.
- Revoke any item links or Sends you created for them that have not yet expired.
- List every item they could open, using the team vault and their own vault; that list is your rotation list.
- Change those passwords, starting with email, payout and subscription platform accounts, and save the new ones only to vaults they cannot open.
- Remove their seats, roles and delegated access inside each platform and connected tool.
- Sign out sessions you do not recognise and confirm the recovery email and phone on each account are still yours.
- If they ever enrolled an authenticator or passkey on a shared account, remove it and enrol your own device instead.
- Move anything they created that you still need into an owner-only vault before you delete their vault.
- Record the date access ended in your access register, alongside what you changed.
- Collect or wipe any phone or laptop you supplied, and sign out of the password manager on it.
Finished content and contracts are a separate access problem; our cloud storage comparison for creators includes a sharing-permission audit for shared folders and links.
Limitations of this comparison
This page compares documented features and published prices only, read on 2 October 2026; it does not rank the products or test their security. Promotions end, plans are renamed, and regional prices and taxes differ from the US dollar figures shown. A password manager also cannot fix a weak master passphrase, a phone left unlocked, or a helper who copied details before leaving. If you run a registered business with staff, contracts or insurance requirements, ask a qualified IT security adviser to review your setup, and check your bank's terms on stored passwords as the ACSC suggests.