Team security

Sharing Client Credentials Across an Agency Team

Scope access by client and role so each person sees only the accounts they work on, share individual secrets through encrypted expiring links, keep a record of who accessed what, and revoke and rotate when someone leaves. For standing team logins, use a password manager.

Don't share client logins in Slack, email, or a shared spreadsheet. In those channels you can't see who opened or forwarded a secret, and you can't remove one person's access without changing the password for everyone. Scope access by client and role so each teammate sees only the accounts they work on, share any individual secret through an encrypted link that expires, keep a record of who accessed what, and when someone leaves, revoke and rotate. Use a password manager for the team's standing logins, and keep the client-facing exchanges isolated per client.

The problem with a shared pile of passwords

When credentials live in a team channel, a shared sheet, or sticky notes, every person who was ever in the room has seen them. You can't answer a simple question: who on the team accessed this client's accounts, and when? And offboarding becomes a scramble. Research attributed to the Ponemon Institute suggests most organizations have delayed or incomplete access removal after someone leaves. For an agency holding dozens of clients' logins, that's real exposure.

Scope, share, and offboard

The fix isn't one tool, it's a shape. Access is scoped by client and role, individual secrets move through encrypted links rather than messages, and every access leaves a trail you can review when someone departs.

ChannelScoped to one person?Revoke without changing for all?Audit trail?
Encrypted one-time linkYesYesYes
Password manager (team vault)YesYesYes
Slack / chatNoNoNo
Shared spreadsheetNoNoNo

The client-credential lifecycle

  1. Collect from the client through an encrypted request, into that client's own space, not a personal inbox or a general channel.
  2. Scope access by client and role. A teammate sees only the clients they work on. Juniors don't see every client's secrets.
  3. Share an individual secret to a teammate, contractor, or the client through an encrypted, expiring link, never the message body.
  4. Keep the audit trail of who accessed which client's credentials, so you can answer a client who asks.
  5. Offboard cleanly. When someone leaves or a contractor's work ends, revoke access and rotate the credentials they could see.
  6. Use a password manager for the team's standing shared logins. It and a secure intake tool complement each other.

Where doconvoy fits

For the client-facing parts of that lifecycle, doconvoy collects a client's credentials through an encrypted request, keeps each client in an isolated project so one client's secrets are never visible to the whole team, and lets you share a secret out through an encrypted one-time link with expiry and access controls. Team access is assigned per workspace and project, and every access is logged for offboarding and client questions. It isn't your team password vault. For standing internal logins, pair it with a password manager.

Collect, share, and audit client credentials with per-project isolation.

Isolate credentials per client

Related: Receive client credentials · Secure Sharing · Workspaces & Projects · Team Management · For agencies

Common questions

Where should an agency store client passwords?

A team's standing shared logins belong in a dedicated password manager with role-based access. For the client-facing exchanges, collecting credentials from a client and handing access to a teammate or contractor, use an encrypted request and one-time links kept isolated per client, with an audit trail.

How do we stop one client's credentials being visible to the whole team?

Scope access by client and role. Each teammate should see only the accounts for the clients they work on, with each client's secrets isolated rather than pooled in one shared channel or spreadsheet.

What should happen to credentials when someone leaves?

Disable their access, review which credentials they could see, and rotate those credentials. An audit trail of who accessed what makes this reliable rather than guesswork.