Blog · Fundamentals · 16 August 2026
What is an enterprise password manager?
The term gets stretched to cover everything from a consumer app with an admin console to a full privileged-access platform. Here is a working definition, the capabilities that actually matter, and an honest note on when you do not need the word "enterprise" at all.
The working definition
An enterprise password manager is a system that stores and controls the credentials an organisation owns: the bank portals, cloud root accounts, admin panels, API keys, and licences that belong to the company rather than to any one person. That single word, ownership, is what separates it from a consumer password manager. A consumer tool answers "how do I remember my passwords?". An enterprise tool answers "who in this company can open what, who actually did, and what happens when they leave?".
The five capabilities that define the category
- Client-side, zero-knowledge encryption. Credentials are encrypted on employee devices before transmission, so the vendor stores ciphertext it cannot read. If the vendor can read your vaults, so can whoever breaches or subpoenas the vendor. Ask for the exact inventory of what is encrypted; here is ours.
- Directory-driven identity. Sign-in should ride the identity system you already run, such as Microsoft Entra ID, so joiners get access with their work account and leavers lose it the same way. See how SSO-first onboarding works.
- Shared vaults with enforced roles. Read, write, and admin roles per vault, enforced by cryptography rather than by a checkbox the server promises to honour.
- Cryptographic revocation. Removing a person re-encrypts what they could open, so their old key becomes useless mathematics. A permission flag that somebody forgot to check is not offboarding.
- An audit trail that cannot be edited. Who opened which vault, revealed which credential, and when, in a log that is append-only even for the vendor.
What "enterprise" does not have to mean
It does not have to mean a sales call, a per-module pricing maze, or a security tier you pay extra to unlock. Those are business models, not requirements. A five-person company holding its bank credentials and cloud root account has exactly the same five needs listed above; it simply has fewer people. That is why every Keyvaci plan carries every security feature, and the plans differ only in how they are counted.
Do you actually need one?
Run this two-minute test. Can you answer, today, without asking around: where is the company bank login stored, who can see it, when was it last changed, and what would you do in the next hour if the person who knows it resigned? If any answer is "a spreadsheet", "not sure", or "panic", you need the category, whatever you choose within it. Our buyer's guide with a one-week evaluation drill shows how to test any candidate against these five capabilities using real workflows instead of feature grids.
See the five capabilities running in one product
14 days, every feature, no credit card. Sign in with company SSO or a plain email address.