How long a password link should last, and how many views
Pick an expiry and view limit for a password link: why one view does most of the work, a table by scenario, Friday and time-zone traps, and limits by plan.
How to hand over a password, collect one from a client, or retire one properly. Useful whether or not you use ShareShield.
Pick an expiry and view limit for a password link: why one view does most of the work, a table by scenario, Friday and time-zone traps, and limits by plan.
For agencies and MSPs. Ask for your own login first, send a secret request instead of an email, use these request scripts, and know what to refuse.
Private keys, .pfx bundles, recovery codes, ID scans: how to send a sensitive file by share link, 7-Zip, age or one-time link, with the passphrase kept apart.
Four ways to send a password securely and when each is right, a step-by-step for one-time links, the follow-up most people skip, and common mistakes.
When someone leaves, which shared passwords and keys to rotate and in what order, how to find the ones nobody wrote down, and how to keep an audit trail.
A short password sharing policy template for 10 to 200 people: copyable clauses with commentary, mapped to ISO/IEC 27001:2022 A.5.17 and Cyber Essentials.
A runbook for a leaked password or key: contain it, check sign-in logs in Entra ID, Google Workspace and CloudTrail, decide on UK GDPR notice, prevent a repeat.
For developers: scoped, short-lived keys, secret managers (Vault, AWS Secrets Manager, 1Password CLI, Doppler), when a one-time link fits, and rotating safely.
How to share a password with an external contractor, vendor, auditor or client: their own account, guest vault access or a one-time link, and how to end it.
How IT and HR get a new employee their first password safely: temporary passwords with a forced change, Temporary Access Pass, MFA enrolment and a checklist.
Keep the staff Wi-Fi password off whiteboards, run a guest network that's really separate, and handle printer PINs and door, alarm and safe codes properly.
Who can read a password sent by email, Slack or Teams, for how long, and whether you can take it back. Plus what to do if you have already sent one.