For HR and onboarding
Sending a new starter their password, without the welcome email that keeps it forever
Before someone’s first day, they need a password for their laptop or their work account. It usually goes in the welcome email to their personal address, where it stays long after they’ve changed it, or should have. ShareShield sends it as a link that opens once and then deletes the password.
- From
- People team <people@company.example>
- To
- priya.k@example.net
- Subject
- Welcome to the team, Priya
Hi Priya,
We’re looking forward to Monday. Your laptop will be waiting at reception from 9:30, and your sign-in is priya.k@company.example.
Your password is: Harbour-Kettle-27
Your password is here, and the link opens once: https://app.shareshield.net/secret/p4tz-8hn-q2wWe’ll text you the passcode.
See you Monday,
Jess, People team
01What usually goes wrong
The welcome email is the weak spot
The welcome email goes to a personal address you don’t control. Think about who can read it from there: anyone else who uses that phone or the family tablet it syncs to, the personal email provider’s backups, the partner it gets forwarded to so they know the start time. On your side, it sits in your sent folder, in the shared HR inbox if you sent it from there, and in your company’s mail archive. The password is still in all of those places next year, and so is anyone who later gets into one of them.
Text messages and chat apps aren’t much better: the message sits on the phone, often backed up to the cloud, and nobody deletes it.
The fix doesn’t need a new process. Keep the welcome email, take the password out of it, and put a link in its place that works once.
02Five steps for first-day passwords
Five steps, the same every time
Print this, or paste it into your onboarding checklist. It works the same for every new starter.
- 1
One password per link.
If there’s a laptop password and an email password, send two links. If one is opened by the wrong person, only one password needs changing.
- 2
Send it to the person, locked to them.
Add the new starter’s personal email address under “Email it to” and tick “Only these recipients can open it”. Anyone else who gets hold of the link is asked for a 6-digit code sent to that address, so a forwarded email isn’t enough.
In the send form: Recipients
- 3
Add a passcode and give it to them another way.
Read it out on the welcome call, or send it by text message. The link and the passcode should never travel together; ShareShield never puts the passcode in the email. Five wrong passcodes destroy the secret.
In the send form: Passcode
- 4
Make the expiry fit the start date.
Send it a day or two before they start and let it expire soon after day one. If they haven’t opened it by then, something is wrong and you want to know.
In the send form: Time
- 5
Ask to be told when it’s opened.
You’ll get an email the moment they open it, so you can tick it off the onboarding list without asking.
In the send form: Notify
Your secret link is ready
Share this link with the person who needs it. Send the passcode separately.
- Name
- Laptop password, Priya
- Expires
- Tue 7 Oct, 17:00
- Views
- 1 view, then destroyed
- Passcode
- Yes
- Who can open it
- Only the recipients below
Emailed to
- priya.k@example.netSent
03What if…
The awkward cases, answered
- The start date moved.
- Burn the link from your dashboard, then send a new one closer to the new date. A burned link stops working straight away.
- They say the link doesn’t work.
- Check the secret in your dashboard. If it shows as opened and they say they didn’t open it, treat the password as known to someone else: ask IT to reset it, then send a new link. If it expired, just send a new one.
- I sent it to the wrong address.
- Burn it. If it hasn’t been opened, nobody saw the password.
- They opened it and then lost the password.
- The link won’t open again; that’s the point. Ask IT to reset the password and send a new link.
04When someone leaves
Getting shared logins back from a leaver
People often leave holding passwords nobody else has: the company social accounts, the office Wi-Fi admin page, a supplier portal.
Before their last day, send them a secret request for each one. They fill in a one-time form, and each password arrives in your ShareShield account rather than in a handover document. Then change every one of them.
Need a password, key or other secret from a colleague or client? Send them a request: they get a one-time link to a form, and their answer comes back to you as a secret link.
The request link expires after
1 day3 days7 days05HR and IT, sharing the job
IT sets the rules, HR sends the links
Team Members
Manage your team and control access permissions
| Member | Role | Status | Joined | Last Active |
|---|---|---|---|---|
| Sam Okaforsam@company.example | owner | Active | 12 May 2026 | Today |
| Lee Brennanlee@company.example | admin | Active | 12 May 2026 | Yesterday |
| Jess Pateljess@company.example | member | Active | 3 Jun 2026 | Today |
| Tom Reidtom@company.example | member | Active | 3 Jun 2026 | 29 Sep 2026 |
Put HR and IT in the same ShareShield organisation. IT, as the organisation’s owner, sets the rules once: the longest a link can last, a passcode on everything, and which email domains links can go to. HR, as members, send the links, and the send form only offers what the rules allow.
Give IT’s other staff the admin role so they can see every link HR has sent (never the passwords in them) and burn one if needed. If your company signs in with Microsoft, IT can connect ShareShield to it so nobody needs another password.
Which feature does what
| You want to | Use |
|---|---|
| Send a first-day password | A one-view link, recipients only, with a passcode |
| Know it’s been received | Notify on open |
| Cancel a link | Burn |
| Get a password back from a leaver | A secret request |
| Make everyone follow the same rules | Organisation policy, set by IT |
06Further reading
Guides for onboarding and leavers
Take the password out of your next welcome email
Send one now without an account, or set up an organisation with IT so the whole team works the same way.
