Skip to content
For teams & SMB

Shared credentials without the shared spreadsheet

Folders and roles instead of a document everyone edits. A record of who opened what. And an offboarding process that takes a minute rather than an afternoon of guesswork.

Sound familiar?

The three habits every growing team has

The credential lives in a chat thread

Searchable by everyone who was ever in the channel, retained by the chat provider, and impossible to revoke.

Nobody knows which password is current

Two spreadsheets, three versions, and one person who knows the real one. Rotation stops happening because rotation breaks things.

Offboarding is a guess

Someone leaves and the honest answer to "what did they have access to?" is a shrug and a hope.

What changes

Structure first, then everything else gets easier

Folders and roles carry the access model

Build a folder per client, per environment or per team. Attach roles with read or write rights, then assign people to roles. Adding the fourth engineer becomes one click instead of a conversation about which documents to share.

  • Pre-defined roles: admin, manager, user, read-only
  • Per-user overrides where a role is not quite right
  • A rights matrix that shows the real model in one screen
Folder administration in Teampass: every folder with its complexity requirement and its settings

Every access leaves a trace

Views, edits and shares are recorded against the item. When a service gets compromised, you can answer "who had this, and when did they last use it" instead of assuming the worst about everyone.

  • Per-item history
  • Leaver risk report listing what a departing account could reach
  • Rotation tracking, so overdue credentials surface on their own
The history of an item: creation, edits, tag changes and file uploads, each with an account and a timestamp

Sharing outside the team, without giving out an account

Secure Send hands a client or contractor exactly one credential, under an expiry and a view limit, with an optional passphrase you pass through a different channel. When it expires, it is gone.

  • No account for the recipient
  • Expiry and view count enforced server-side
  • Optional recipient passphrase
An item in Teampass, with Secure Send in the toolbar next to Share and Notify
Daily use

The part that decides whether people adopt it

A password manager only works if using it is faster than not using it. That is what the browser extension is for.

Autofill in the tab

No switching windows, no clipboard, no half-typed passwords in the wrong field.

Domain matching

Credentials fill on the domain they belong to, which takes the edge off phishing pages.

Capture on sign-up

New credentials land in the right folder instead of a sticky note.

Ctrl-K anywhere

The command palette in the web app finds an item without a single click.

The extension is the paid part of Teampass — from €49 a year for three users, with a 30-day trial. The server, and everything on this page except autofill, stays free. See pricing.

Getting started

A rollout that does not stall

  1. Start with one team

    Model their folders and roles properly. A good first tree becomes the template for the rest.

  2. Import, then rotate

    Pull in the spreadsheet, run a posture scan, and rotate what it flags before anyone relies on it.

  3. Roll out the extension

    Adoption follows convenience. Autofill is what turns a policy into a habit.

Questions

Straight answers

How long does a rollout take?

Installing takes an evening. Modelling folders and roles takes longer, and it is the part worth doing carefully — start with one team’s credentials rather than importing everything on day one.

Do we need the paid extension?

No. The web interface covers everything. Teams buy the extension because autofill removes the copy-paste habit that leaks credentials into clipboards and chat windows — but it is an add-on, not a requirement.

What happens when someone leaves?

Disable the account and their access is gone. The leaver risk report shows which credentials they had reached, so you know exactly what to rotate instead of rotating everything or, more commonly, nothing.

Can we give a client or contractor one credential without an account?

Yes — Secure Send produces a link with an expiry, a view limit and an optional passphrase. No account, no standing access.

Who can read our passwords?

Only users your folder and role model grants access to. Administrators can manage the instance, but personal folders are decryptable only by their owner and the recovery account.

Get the credentials out of the chat thread.

Free, self-hosted, and running before the end of the day.