Mirror

A Password Manager Is the One Tool Nobody Argues About — So We Tested Whether It Deserves That

1Password at three seats for four months, including the migration nobody warns you about and the one feature that turned out to matter more than the vault.

Every list of essential small-team software includes a password manager, and the recommendation is always made in the same tone — obvious, settled, not worth discussing. I find that tone suspicious in software reviews generally, so I spent four months actually paying attention to what we got out of 1Password beyond the thing everyone assumes.

a spreadsheet of passwords dissolving into a locked vault

Setup at three seats cost $19.95 a month on the Teams plan. The migration is where I want to spend most of this, because it is the part that is glossed over and it is the part that determines whether the tool works at all. We came from a shared spreadsheet, which I am aware is bad, and which I suspect is more common in small teams than anyone admits publicly.

The import took four minutes. Reviewing the import took nine days. Of 148 entries, 31 were duplicates with different passwords for the same service, and in eleven of those I could not determine which one was current without logging in to check. Nineteen entries were for services we no longer used, three of which were still billing us — that discovery paid for the first fourteen months of the subscription in one afternoon, which is not a benefit anyone lists on the pricing page.

The feature that turned out to matter was not the vault. It was the item history. Twice now, someone has changed a shared credential without telling the others, and both times the resolution was thirty seconds in the history view instead of a Slack conversation that would have started with “did you change the—” and ended with someone feeling accused. Shared secrets are a social problem more than a technical one, and the log is what makes it a technical one again.

Watchtower — the built-in breach and weak-password scanner — was less useful than advertised for us specifically, and I think the reason generalises. It flagged 40 items as weak on day one. Thirty-four of those were logins for services where the account has no meaningful power: a font marketplace, two stock photo sites, a forum. Fixing them is not zero-value but it is close, and the count sat there in red for weeks making the dashboard feel like a failure state. I would rather it ranked by consequence than by count.

The browser extension is the part you actually use, and it is good but not invisible. In four months I logged fourteen occasions where autofill did not trigger and I fell back to copy and paste — almost all on sites with multi-step login forms, where the password field appears after the email is submitted. That is roughly once every eight days. Tolerable, and worth knowing, because the marketing implies it never happens.

On whether it deserves the unanimous recommendation: yes, but not for the reason the recommendation is usually made. The security argument is real and I do not dispute it, but security arguments are hard to feel, and things you cannot feel do not survive a budget review. What made this stick for us was the audit — knowing what accounts exist, who touched them, and which ones are quietly charging us. That is an operations benefit, and it is the one I would lead with if I had to sell this to a partner who was unconvinced.

The one thing I would check before committing: whether the people you are buying it for will accept a master password they cannot recover. We lost a day to this. There is no back door by design, which is the correct design, and it is also a conversation you want to have before someone locks themselves out of a vault on a Friday.