Password Management for Business
GravIT rolls out a business password manager properly: encrypted vaults for every staff member, shared access by team, dark web and breach monitoring, and the bit most rollouts skip: moving everyone's existing passwords across and teaching them how to use it. Geelong owned and operated, and we run our own business on the same thing.
Passwords should be like underwear
Change them regularly. Don’t share them with anyone. Don’t leave them lying about on the desk. And never, ever use the same pair all week.
Everybody knows the rules. Nobody keeps them, because remembering eighty unique passwords is not a discipline problem, it’s an impossible one. So people do the human thing and reuse one. Then a shopping site you forgot about gets breached, and that same password is quietly tried against your email, your bank and your accounting system by a machine that never gets bored.
A password manager fixes it by removing the memory problem entirely. Your staff remember one strong passphrase. Everything else is long, random, different every time, and typed for them.
The one we roll out, and why
We tested the field and standardised on one business password manager for our clients, and we run our own business on it, which is the only recommendation that really counts. Here is what it does beyond storing passwords.
Two vaults, kept apart
Every staff member gets a personal vault of their own alongside the business one. Their home banking and their Netflix login stay genuinely private (you can’t see them and neither can we), which is exactly why people actually use it instead of quietly going back to the browser.
Encrypted before it leaves the desk
Records are encrypted on the user’s own device, so what’s stored in the cloud is unreadable without their key. Nobody at the vendor can read your passwords, and neither can we. We consider that a feature rather than a limitation.
Dark web monitoring
It continuously watches the trade in stolen credentials for your people’s accounts, and tells you when one turns up. Most businesses find out they were in a breach years late, from somebody else.
Breach alerts on the passwords you hold
Beyond watching for leaked accounts, it checks the passwords in your vaults against known compromised ones and flags the weak, reused and exposed, so “change that one now” is a specific instruction rather than a nag.
One sign-in, the one they already have
It signs in against your Microsoft 365 accounts, so there’s no new password to remember and no separate list of users to maintain. Someone offboarded in 365 loses vault access with them.
Reporting you can hand to someone
Activity and compliance reports show who has access to what and what changed. That is the evidence an insurer, an auditor or a larger customer asks for, and the same paperwork that makes Essential Eight conversations short.
The week someone leaves
This is the part owners feel. A staff member resigns, and their logins go with them: the supplier portal only they ever used, the domain registrar, the social accounts, the software subscription billed to a card nobody can find. Getting back in means proving ownership to a support desk overseas, or losing the account.
With a business vault, their work passwords were never really theirs. On their last day their business vault is reassigned to whoever picks up the work. Access moves across intact, nothing locks anyone out, and their personal vault leaves with them as it should.
It also settles the other awkward question: what that person still has access to tomorrow. The answer is nothing, and you can show it in a report rather than hoping.
What we do to set it up
- Licensing and tenancy setup
- Sign-in tied to your Microsoft 365
- Import from browsers and any existing manager
- Shared folders structured by team and role
- A short crash course for every user
- Browser password saving turned off afterwards
The catch, since there always is one
A password manager only works if people use it, and the first fortnight is a genuine change of habit. That is where most rollouts quietly die: the licences get bought, half the staff never log in, and everyone drifts back to the browser and the spreadsheet.
So we do more than hand over licences. We move each person’s existing passwords across for them, out of Chrome, Edge or whatever they were using, sit them down for a short crash course on their real logins, and turn off browser password saving afterwards so there is one obvious place things live. Then we check adoption a few weeks later, because a vault half the office ignores is money you spent on nothing.
Pricing is a small monthly amount per user, and it scales with headcount rather than a big up-front number. Ring us for today’s rate, and ask what it would cost to recover one account you have been locked out of, which is usually the more interesting number.
Frequently asked questions
Is it safe to keep all our passwords in one place?
It sounds like putting every egg in one basket, but the alternative is worse: the same reused password across eighty accounts, which is one basket already, just one you cannot see. The vault encrypts records on each user's own device before anything is stored, so what sits in the cloud is unreadable without their key. Nobody at the vendor can read it, and neither can GravIT.
What happens if someone forgets their master passphrase?
They keep an emergency recovery method set up during onboarding, and administrators can restore access to the business vault so company logins are never stranded. Personal vaults are genuinely private, which is the trade-off for people trusting it with their own accounts.
Can our staff still see each other's passwords?
Only what you share deliberately. Shared folders are structured by team and role (accounts staff see the finance logins, the workshop does not), and personal vaults are visible to nobody but their owner.
What happens to the passwords when a staff member leaves?
Their business vault is reassigned to whoever takes over the work, so nothing is lost and nobody gets locked out of a supplier portal or domain registrar. Their personal vault goes with them. It is the single best reason to stop keeping work logins in personal browsers.
Do we still need multi-factor authentication?
Yes. A password manager fixes reused and weak passwords; MFA covers the case where a password is captured anyway. They are complementary, and both are in the Essential Eight work we do.
Isn't the browser's built-in password saving good enough?
It is better than a sticky note and worse than a vault. Browser stores are tied to one person's profile, so nothing can be handed over when they leave, there is no shared team access, no breach monitoring and no reporting. We turn browser saving off after rollout so there is one obvious place passwords live.
How long does a rollout take?
For a typical small business, licensing and setup is quick and the real work is people: importing each user's existing passwords and running a short crash course. We stage it so nobody is locked out mid-day, then check adoption a few weeks later.
Get the passwords out of the spreadsheet
Most businesses are, right up until the week it costs them. We can have your team sorted without anybody losing a login.