Blog · Playbook · 16 August 2026
Stop sharing passwords in chat
Somebody needs the login, chat is where the conversation already is, and the paste takes three seconds. That is how almost every team ends up with its most dangerous secrets in its most searchable system. Here is the honest cost, and a fix that fits in one afternoon.
What a pasted password actually costs
- It is searchable, forever. Chat retention means the password sits in an index that anyone with workspace access, including future joiners and integrations, can query years later. Try searching your own workspace for the word "password". Budget your mood accordingly.
- It survives every departure. A leaver keeps whatever they scrolled past. Nobody can even list what that was, which makes real offboarding impossible.
- It inherits every chat compromise. One phished chat session, one over-scoped bot, one export by a workspace admin, and the paste is out. Chat platforms are superb collaboration tools and were never designed to be secret stores; using them as one quietly couples your credential security to their breach headlines.
- It rots invisibly. Which paste is the current password? The one from March or the one from Tuesday? Nobody knows, so nobody rotates it.
The one-afternoon migration
- Hour 1: capture the top twenty. Do not aim for completeness. List the twenty credentials whose leak would hurt most: bank, registrar, cloud roots, payroll, the shared SaaS everyone uses. Create vaults by blast radius, for example "Finance", "Infrastructure", "Shared SaaS".
- Hour 2: move and assign. Put each credential in its vault with a named owner, grant teams the minimum role they need, and let members sign in with the company identity they already have; with Entra ID SSO there is nothing new to remember.
- Hour 3: rotate what chat already saw. Any password that ever appeared in chat is burned; assume it. Rotate the top twenty as you move them, so the vault starts clean and the old pastes become harmless trivia.
- Hour 4: make chat the pointer, not the store. Team norm from today: chat messages link to the vault entry, never contain the secret. Pin the rule; it enforces itself once the vault is faster than scrolling history, and revealing a credential now leaves an audit event instead of a search result.
Measuring that it worked
Three checks a month later: workspace search for "password" returns pointers instead of secrets; every top-twenty credential shows a last-rotated date after migration day; and the audit log, not anyone's memory, answers who opened the bank login this month. The cost of all this is a few dollars a month; the alternative was already costing more, invisibly.
One afternoon. Twenty credentials. Done properly.
14 days, every feature, no credit card. Sign in with company SSO or a plain email address.