
How to Share Access Without Sharing Passwords
The first week of any project, I have to ask a client for access to four or five accounts. The domain. Google Analytics. Their Google Business Profile. Sometimes the website platform, sometimes the email tool. For years, the answer came back the same way: a list of usernames and passwords, typed into an email.
It works. It's also the weakest option on the table, and in almost every case the service already has a better one built in and turned on.
Start with a password manager
Everything in this post gets easier once your passwords live in a password manager instead of your head, a notebook, or a browser the whole family uses. This year, the case for one got a lot stronger.
Attackers are automating. Microsoft's 2026 Digital Defense Report, published October 1, describes AI agents beginning to run more of an attack on their own, with less of a person at the keyboard. Their explanation of why stolen logins matter fits in one sentence: "A valid credential can turn malicious activity into something that resembles legitimate use." Someone signing in with your real password doesn't look like an attack. It looks like you.
And the risky password usually isn't the short one. Verizon's 2026 Data Breach Investigations Report found credential abuse somewhere in 39% of breaches, and Descope's breakdown of the report points out that people are more than four times as likely to be using a password that has already leaked as one that's too weak. That's reuse. One old account gets breached, and automated tools try the same email and password everywhere else. That kind of tedious trying is exactly the work AI makes cheaper.
A password manager fixes that at the root:
- Every account gets its own long, random password, so one leak stays one leak.
- It only fills in a login on the real site, which makes it a quiet backstop against lookalike phishing pages.
- It gives you a safe way to share a login when a service offers nothing better (more on that below).
1Password and Bitwarden are the two I point clients to. Bitwarden has a free plan, and 1Password costs a few dollars a month. Set one up on a slow afternoon and move the important accounts first: email, domain, bank, and website.
Three rules that cover almost every situation
Delegate instead of sharing. Nearly every service a small business uses has a feature for letting someone else in without handing over your login. It's free, it takes about two minutes, and most owners have never been shown where it lives.
Grant the least access that does the job. Services usually offer several levels, and they tend to list the most powerful one first. The narrow option covers more work than you'd think.
Make sure you can take it back, and then actually take it back. Access that never gets removed is how a business ends up with six former vendors still holding keys.
Why emailing a password is worse than it feels
It feels harmless because nothing bad happens that day. Here's what's actually going on.
The message doesn't go away. It sits in your sent folder and their inbox, syncs to both of your phones, and lands in whatever backup either of you runs. It's still there in three years when neither of you remembers the project.
One login usually opens more than the thing you meant to share. A GoDaddy account often holds the domain, the business email, sometimes the hosting, and a credit card. Your website platform login might also hold customer records and order history. You meant to share one thing and you shared the whole account.
Two-factor authentication turns into a group project. If you've got it on, and you should, sharing a password means texting verification codes back and forth every time the other person signs in. Delegated access skips that completely, because they're signing in as themselves.
You have to change it afterward. A shared password means rotating it when the work ends, then updating it in the four other places you'd saved it and forgotten about.
What to look for, service by service
The feature exists almost everywhere. It just goes by a different name on every platform, which is most of why people give up and send the password instead.
Your domain registrar. GoDaddy calls it Delegate Access, and so do Namecheap and Network Solutions. This is the one worth getting right, because your domain is the single asset you least want to lose control of. Here's the full walkthrough for GoDaddy, including which of the four permission levels to pick.
Google Analytics and Search Console. Both work by adding a person's email address to the property, and both have levels that separate looking at reports from changing settings. Nobody needs your Google password to read your traffic numbers.
Google Business Profile. Add your designer as a manager. Do not transfer primary ownership, and be careful here, because this is the account small businesses lose most often. If the person who set up your listing years ago is still the owner and you can't reach them, you already know why this matters.
Your website platform. Squarespace has contributors, Wix has collaborators, WordPress has user roles, and Shopify has staff accounts. Same idea in all four: a named account with a role attached, separate from yours.
Facebook and Instagram. This is the one people get wrong most often, because the instinct is to hand over a personal Facebook login. You never need to. Page and account access is granted through Meta's business tools to the other person's own account, which means they can post as your business without being able to read your messages or see your family photos.
Your email platform. Mailchimp and most competitors support additional users with roles, so a designer building a template doesn't need the keys to your whole list.
I'm writing these up one at a time, with screenshots, because the exact buttons move around and a vague description doesn't help anyone at 9pm on a Tuesday.
When a service doesn't offer it
Some don't. Older tools, small niche platforms, and a few billing portals still assume one login per business. When that happens:
Share it through your password manager, not a message. This is where the one you set up pays for itself. 1Password and Bitwarden both let you share a login as an item, so the password gets used without being copied into an email or a text thread. Revoking it is one click, and you don't have to trust that everyone deleted the message.
Keep two-factor on your own phone where you can, so signing in still requires you.
Change it when the work is done. This is the step everyone skips. If you shared a real password, treat it as spent.
Take it back when the work is done
Walk the same list you granted, in the same order, and remove or downgrade every one. It takes about ten minutes and it's the difference between knowing who has access to your business and hoping you remember.
A few services have a middle setting worth using. GoDaddy, for one, lets you keep a delegate connected while giving them access to nothing, which means turning access back on next year is one click instead of a fresh invitation. For someone you'll hire again, downgrading beats deleting.
None of this is about distrust. You get a key back from a contractor after the remodel, and nobody takes it personally.
What I ask for, and what I don't
When we start a project, I'll tell you exactly which accounts I need, which permission level to pick, and why. I'll walk you through it on a call if you'd rather not do it alone.
I will never ask you to email me a password. If a service leaves us no other option, we'll use a password manager and you'll change it when we're done.
And when a one-time project wraps up, I'll ask you to remove me. If we're working together on an ongoing plan, I stay, because I'm the one keeping the site current. Either way, you should be able to answer the question "who has access to my website?" without going through old email to figure it out.
If that's how you'd like to work with someone, book a fit call and we'll talk about what your project needs. Thirty minutes, and I'll be direct about whether I can help.
Written August 2026, updated October 2026. Every service named here moves its settings around from time to time. If a screen doesn't match, search that company's help center for "delegate access," "users," or "permissions" and you'll land close.