Most companies get here the same way. Someone gets tired of the spreadsheet, a password manager gets bought, everyone installs the extension, and the subject is closed for two years.
It is a real improvement. It is also where a second question starts: is a password manager enough for a business?
The short answer is no, and it is not enough at home either, which is why Inheriti® 2.0 exists for personal use. For a company with staff, contractors and accounts that outlive the people who opened them, there are five specific places where a password manager runs out.
Stop the whole company from depending on one master password
A password manager is one vault behind one master password. Everything inside it is protected by that single secret, and the strength of your entire company’s security is the strength of one string in one person’s head.
That is not a criticism of the encryption. The encryption is usually excellent. It is a statement about shape: one key opens everything, so one compromise opens everything. Phishing that master password, capturing it on an infected laptop, or simply watching it get typed in a shared office, all produce the same result.
The spreadsheet had one readable file. The password manager has one openable vault. The single point of failure was not removed, it was made harder to reach.
In Inheriti® Business no single secret opens the company. The organisation key is derived in your browser from a PIN the owner memorises, using Argon2id with a random salt. The PIN and the key never reach our servers, and the organisation key alone still opens nothing.
Store secrets so that no single place holds enough
This is the difference that matters most, and it is architectural rather than behavioural.
A password manager stores your secrets as one encrypted blob in one place. Sync it, back it up, export it, and there is still one object that contains everything. Whoever gets that object gets your company’s entire credential set, and from that moment the only thing standing between them and it is the master password.
Inheriti® Business never keeps a whole secret anywhere. A data asset is encrypted in your browser, then split with Shamir’s Secret Sharing into data shares, key shares and a custodian share pair. Every share is separately encrypted with a per plan key, which is itself wrapped with the organisation key and sealed with a key pair that never leaves the Inheriti® HSM.
Those shares are then distributed across multiple storage layers: the Inheriti® Vault, the organisation’s smart contract on InheritiChain, and a separate custodian depot. No single location holds enough to reconstruct anything, including us.
A stolen vault file is a puzzle with the picture on it. A stolen share is a piece with nothing on it at all.
Give people access without leaving the password in a document
The second thing a business needs is for people to actually work, and this is where every vault drifts.
Be clear about what this does and does not change. An authorised member can read the credential and use it, and copy it into the login screen it belongs to. That is the point of giving someone access. What changes is that reading it is a controlled, recorded event instead of an open document that anybody who finds it can read.
Sharing in a password manager means handing over the secret. The moment a colleague or a contractor can use a credential, they have it. It lands in a personal manager, a screenshot, a chat thread, a notes app on a phone. Removing them from the shared folder later removes the convenience, not the copy.
Access here is not a file you pass around. A member opens the secret inside Inheriti® Business, and their access is checked against their team membership at the moment they open it. Where it matters you can require other members to approve first, and every opening is recorded. When membership ends, access ends with it: share records are marked invalid, and rotating a secret purges the old ciphertext, so a leftover share on a laptop that walked out the door cannot be authorised and cannot be served.
Know who opened what, without asking around
Ask a password manager who has access and it will tell you. Ask it who actually opened the production database credentials on the fourteenth, and it usually cannot.
That gap becomes expensive at exactly the wrong moment: during a client security review, during an audit, or during an incident when you are trying to work out what to rotate.
Every access request, every approval and every reveal in Inheriti® Business is written down as it happens, in your organisation’s audit trail, with the person, the role, the time and the plan. Exports can be scoped to one member, one team or one plan, and close with an integrity page carrying a SHA-256 hash of the document, so the report proves it was not edited afterwards.
Keep working when the person with the keys is not there
The last gap is the one nobody plans for. The person who set up the vault is unreachable, and the master password was never written down anywhere on purpose, because writing it down was the thing you were told never to do.
Now the vault is a locked box in the middle of your company.
A Business Continuity plan solves that without giving anything away in advance. Access is scoped to a team rather than a person, moderators approve releases at a threshold you set, and the Dead Man Switch exists for the case where you cannot respond at all. It has no schedule and no heartbeat: it sleeps until someone requests access, then asks you for an answer, and one answer cancels the request. Only silence, for as long as your plan says, lets it pass. Even then it is an extra gate, never a shortcut, because approval and authentication still apply.
What Inheriti® Business does about it, and why you need it
Put the five together and the pattern is clear. A password manager improves where your secrets live. It does not change that they live somewhere whole, that using them means copying them, that opening them leaves no record, and that one person’s memory is holding the roof up.
Inheriti® Business changes all four:
- Nothing is stored whole. Encryption happens in your browser, and the result is split into shares spread over multiple storage layers, so there is no single object worth stealing.
- Nobody holds the keys alone. The organisation key is derived on your device and never reaches our servers, the plan key is sealed in the HSM, and a reveal needs an authorised member of the right team, at that moment, with the approvals the plan requires.
- Access is checked at the moment of use. It follows team membership, so it ends when someone leaves, and rotation makes any leftover share inert.
- Every open is on the record. Requests, approvals and reveals are logged and exportable with a verifiable integrity page.
- The company survives one absence. Continuity is part of the plan instead of a note in a drawer.
That is the honest answer to the question. A password manager is enough to stop passwords being lying around. It is not enough to answer who can open what, who did open it, and what happens when the one person who knows is not there. Those three questions are what a business gets asked, by clients, by auditors, and eventually by reality.
Where to start this week
List the accounts the business cannot run without. Banking, domain registrar, cloud admin, payroll, the backup system. Usually five to ten lines.
Mark every line that only one person can open. Those are the ones a password manager does not fix.
Move those into a plan in Inheriti® Business, scoped to the team that needs them, with the approvals that fit how you actually work. Then delete the copies that stayed behind, because the move is only finished when they are gone.