For agencies
Get client logins in, and hand them back, without a single password in email
Every project starts with “can you send us the logins?” and ends with “here are your logins”. In between, the passwords sit in inboxes, Slack channels and the project tracker. ShareShield gives you a form for the first part, a self-deleting link for the second, and a record of both.
Alex Morgan (alex@studio.example) is asking you for a secret
Available for
1 day3 days7 days01Kick-off
Ask for access with a form, not a favour
At kick-off you need the registrar, the hosting panel, the CMS admin, the analytics property and whatever else the client has. The client usually sends them in one email.
Follow it for a month: it went to your account manager, CC’d to the client’s MD and your studio’s hello@ inbox, which three people read. It was forwarded to the freelancer who started in week two. It sits on every phone those mailboxes sync to, in both companies’ backups, and in the search box of anyone who types “password”. Any one of those accounts being compromised next year exposes it again.
Send a secret request for each one instead. The client gets an email from ShareShield showing your name and your note, opens a one-time form, pastes the password and presses send. It lands in your ShareShield account.
They don’t need an account, and the form stops working once it has been used. Requests stay open for up to 7 days, so send them when the client is ready to answer.
Need a password, key or other secret from a colleague or client? Send them a request: they get a one-time link to a form, and their answer comes back to you as a secret link.
The request link expires after
1 day3 days7 days02Build
Let a freelancer in for the week, not forever
Email the link straight to the people who need it, and optionally make sure only they can open it.
Mid-project, a freelance developer needs the staging database password, or the copywriter needs the CMS login for an afternoon. Send it as a link locked to their email address: anyone else who gets hold of the link has to enter a 6-digit code sent to that address first. Set the expiry to match the job.
When their part is done, change the password. ShareShield gets the password to the right person once; it doesn’t take it back out of their head.
03Launch
A handover the client remembers for the right reasons
At launch the client should end up owning every account you set up for them. Send each login as its own secret, emailed directly to the named contact and locked to them.
10:02 sent to the client’s contact
Your secret link is ready
Share this link with the person who needs it.
Secret linkhttps://app.shareshield.net/secret/w8kd-3n5-qhzCopy linkShow QR code- Name
- Shop owner login
- Expires
- Mon 6 Oct, 10:02
- Views
- 1 view, then destroyed
- Passcode
- None
- Who can open it
- Only the recipients below
Emailed to
- ops@client.exampleSent
11:40 opened, and on the record
EventsTime Actor Action Target IP 3 Oct, 11:40 anonymousAnonymous Secret opened secret: w8kd3n5qhz 192.0.2.61 3 Oct, 11:39 anonymousAnonymous Recipient verified by email code secret: w8kd3n5qhz 192.0.2.61 3 Oct, 10:02 useralex@studio.example Secret emailed to recipients secret: w8kd3n5qhz 203.0.113.42 3 Oct, 10:02 useralex@studio.example Secret created secret: w8kd3n5qhz 203.0.113.42 Turn on notify-on-open and you get an email when each secret is opened, so “did you get the logins?” stops being a question.
For the things that aren’t a password, such as an SSL private key, a list of recovery codes or the signed access schedule, use a file secret. Files are encrypted like text and downloaded once.
File secrets need an active paid plan: up to 1 MB on Standard, 10 MB on Professional and 25 MB on Enterprise.
Send a secret04After
When someone leaves, the agency still knows what they shared
Organization secrets
Every secret shared by members of your organization. Content is never shown here.
| Name | Owner | Status | Expires | Views left | Opened by | |
|---|---|---|---|---|---|---|
| Shop owner login | alex@studio.example | viewed | 6 Oct, 10:02 | 0 / 1 | ops@client.example | |
| Staging DB (freelancer) | jo@studio.example | active | 6 Oct, 09:15 | 1 / 1 | — | Burn |
| Analytics admin | sam@studio.example | expired | 29 Sep, 17:00 | 1 / 1 | — | |
| Untitled | alex@studio.example | burned | 26 Sep, 12:30 | 1 / 1 | — |
Put the team in a ShareShield organisation and the agency, not each person, can see what has been shared. Owners and admins see every member’s secrets and requests (not their contents) and can burn anything still live, which matters on the day an account manager hands in their notice.
Set a policy so every link the team sends expires within a few days and opens once, and limit recipient email domains to your own and your clients’. Nobody has to remember.
When a link isn’t enough
For logins the whole team uses daily, use a password manager
If five people at the agency log into the same client’s CMS every day, a one-time link is the wrong tool. Put that login in a shared vault in a password manager such as 1Password or Bitwarden.
Use ShareShield for the handovers around it: getting it from the client, giving it to a freelancer, handing it back at the end.
05Which feature does what
The features behind each stage
| Stage | What you’re doing | Feature |
|---|---|---|
| Kick-off | Getting logins from the client | Secret request |
| Build | Giving a freelancer temporary access | Email recipient, recipients only, short expiry |
| Launch | Handing every account back | Email recipients with open tracking; file secrets |
| After | Keeping control as people come and go | Organisation roles, admin burn, enforced policy |
06Further reading
Guides for the next project
Send your next client a request instead of asking for an email
Secret requests are included on every plan, Free included. Your client needs nothing but the link.
