Learn · updated August 2026
How to choose a business password manager
Your team already shares credentials somewhere. The only question is whether that somewhere is designed for it. A practical guide to picking one, from a vendor with obvious skin in the game and sources you can check.
Start with the threat, not the feature list
A business password manager exists to fix three concrete failure modes: credentials shared over chat and spreadsheets that never get rotated; leavers who keep working access because nobody remembers what they knew; and one compromised laptop exposing everything the whole company shares. Judge every product against those three, and feature grids get much shorter.
The four properties that actually matter
1. Client-side, zero-knowledge encryption
If the vendor can read your vaults, then so can an attacker who breaches the vendor, and so can a court order served on the vendor. Ask for the exact inventory: which fields are encrypted on your device, and which are readable server-side. Titles and URLs count. (Primer: what zero-knowledge encryption really means.)
2. Off-boarding that revokes cryptographically
Removing a member must do more than flip a permission bit. The honest mechanism re-encrypts the affected vaults under a new key, so whatever key material the leaver's devices ever held stops mattering. Ask each vendor what technically happens at revocation; the answers vary more than the brochures do.
3. Identity that follows your directory
Sign-in should ride the identity system you already run (Microsoft Entra ID, Google Workspace), so joiners get access with their work account and leavers lose it with the same account. The critical follow-up: does SSO weaken the encryption story? The right architecture keeps them separate; SSO answers who you are, while decryption keys still come only from a secret on your device.
4. Exit rights in writing
What happens when the trial lapses, the card expires, or you simply leave? The acceptable answer is read-only access and export, indefinitely enough to be safe, in the terms rather than in a support chat. A vault that can hold your data hostage has misunderstood its job.
Pricing traps to check before signing
- Security sold by tier. If SSO, audit logs, or policy controls only exist in the enterprise tier, the cheaper tiers are deliberately less safe. Prefer vendors whose plans differ in counting, not in protection. (Keyvaci's position: every security feature in every plan.)
- Seat packs. You should pay for people you actually have, prorated, not pre-purchased bundles of empty chairs.
- The renewal cliff. Check what the price becomes after year one, in writing.
A one-week evaluation your team can actually run
- Day 1: Create the organisation with the trial. Time how long until the first real credential is stored and shared. Note every step where a secret appeared on screen or in email.
- Day 2: Onboard three real members through your directory. Verify a suspended directory account loses vault access.
- Day 3: Run the off-boarding drill: revoke one member from a shared vault, then confirm what the vendor says happened cryptographically.
- Day 4: Break glass: have one member "forget" their master password and run the recovery flow end to end. Who could read what, at which step?
- Day 5: Read the audit log of your own week. Could you answer "who saw the banking password and when?" without asking support?
Any product that survives that week honestly is a serious candidate. Keyvaci is built to be run through exactly this drill, in a 14-day trial, with no card: what you will find inside.
Comparing your shortlist
Whatever shortlist you assemble, run the same one-week drill on every candidate and compare three things side by side: what technically happened at revocation and recovery, which pricing tier each security capability lives on, and what the terms promise about your data after you stop paying. Those three answers separate products faster than any feature grid.
Run the one-week drill on us
14 days, every feature, no credit card, and a security team that answers hard questions in writing.