Decide whether a password needs to be shared

Start with the task someone needs to perform. A household member may need to pay a bill; a colleague may need to administer a service. Check whether the provider offers an additional user, delegated role or authorised contact. Separate accounts make permissions easier to limit and revoke, and help preserve an activity record. Knowing a password does not itself give legal permission to use an account.

Avoid sharing a work login outside the organisation or treating access to a financial account as a substitute for formal authority. Discuss privacy and consent with everyone involved. Family members and partners deserve clear responsibilities, not blame for risks created by an unclear system.

Choose a method with a recovery plan

Where credential sharing is permitted, a reputable password manager with scoped sharing can keep selected entries apart from the rest of your vault. Check the provider’s current plan, sharing permissions and recovery documentation before relying on it. A password manager also needs its own backup and emergency access arrangement.

An encrypted message protects one part of the journey but the recipient can still copy, photograph or forward a secret. Disappearing messages do not prove every copy has gone. An in-person conversation can avoid a stored chat but can still be overheard or forgotten. Physical storage needs an agreed access route and protection appropriate to the contents.

Separate everyday access from a future handoff

Everyday shared access should work now through the provider’s normal controls. A future handoff is for information you intentionally keep on hold. Begin with an inventory, document locations and support contacts rather than collecting every password in one message.

ZeroLatch can deliver a scoped inventory and instructions after a missed check-in and safety period. It does not transfer assets, establish legal authority or confirm death. Simple permits authorised service-managed key recovery; Private requires a separate password or ZeroLatch recovery phrase. Neither option replaces an independent backup or a real recipient rehearsal. Start with harmless information and read the security model and backup checklist.

Practise and maintain the arrangement

Use a harmless example to check that your chosen person can find the official login, understand their role and locate the next recovery step. Do not send real master passwords or wallet seeds to a public form or a support inbox. Review access when a relationship, job or device changes. Revoke permissions that are no longer needed and rotate exposed secrets through the relevant provider. Record what was tested and when, without putting the secret itself in that record.