Your Bookkeeper Calls In Sick. Does the Shop Still Run?
One person in your shop holds the logins for payroll, the card processor, and the supplier portal. When she is out for a day, you find out exactly what that costs. A shared vault and a two-page sick-day plan end the scramble, and you can set both up in a weekend.
It is a Tuesday morning, the register is warmed up, and your bookkeeper sends a text: stomach bug, out for the day. No problem, until you need to post payroll and can't remember where the payroll portal password lives. It is in her browser. Or it is in an email she forwarded to herself a year ago. Or nobody has it, and you find out at 2 p.m. when the supplier says she never got the invoice.
That one person in your shop is what I call the keyholder. She can open the Google Business Profile, log into the card processor, approve the weekly supplier order, and reset the website password. The shop runs on her logins the way it runs on her key, except nobody pins the key to a board.
The good news is that the fix is cheap. A shared password vault plus a two-page sick-day plan covers most of the risk, and you can set it up in a weekend. Here is the plan, in plain words.
Here is what usually stops when the keyholder calls in: payroll posts, the online booking or order page, replies to review notifications, the card processor dashboard where refunds live, and any supplier portal that needs an invoice approved. None of these tools need a genius. They need a password, and that password sits in one brain, one phone, or one laptop instead of a place the rest of the shop can reach.
It gets worse in two ways. First, every time the keyholder is out, you learn the password the slow way, and the slow way is where passwords leak: a sticky note on the monitor, a text that says try the one from last year, a shared screen over the phone. Second, the keyholder quietly becomes load-bearing. She starts to know things only she knows, and that makes her harder to thank and harder to replace.
What a shared password vault actually is
A password manager is an app that stores your logins in one locked place and fills them in for you when you type. The shared part is the point: everyone on the team gets access to the accounts they need, and nobody is copying passwords into texts or spreadsheets. You have probably seen the names: Bitwarden, 1Password, Google Password Manager, and the lock icon your phone already makes. They all do the same basic job, and a shared plan works with any of them. If the term is new to you, this is the two-minute version: how a password manager works.
Set it up as one shared vault for the business. Each person logs in with their own account, so when someone leaves, you remove them without changing a single password. That is the whole trick. The passwords stay, the people rotate, and the shop never has to reset the bank login because someone quit.
A sick day, the version with a plan
Same Tuesday morning, same text from your bookkeeper. Here is the version that does not hurt.
You open the vault on your own phone. It holds the payroll portal, the card processor, the supplier portal, and the Google Business Profile, each in a labeled folder. You approve the invoice in two minutes. The morning shift gets the register pin from the small card you keep in the office drawer, and the day is back to normal by 9 a.m.
No one guessed a password. Nothing was screenshotted into a group chat. The only thing that changed between the two versions of that morning was the plan you made in advance.
Write one rule on the office wall: if only one person can open it, it is not a business account. It is a personal account the business is borrowing. That rule sorts most access questions in ten seconds.
Build the plan in a weekend
You do not need a software project. You need one evening with a coffee and a phone. The steps, in the order that saves the most trouble first:
- Create the shared vault and invite the two or three people who really need it. Keep the invite list short. You can always add people later, and it is far easier to add than to audit.
- Make one folder per system: payments, supplier, marketing, books. Move the logins in and give each one a plain name like "Payroll portal" or "Card processor dashboard." Future-you is not the person who knows what "shop2019" was for.
- Put the master password that unlocks the vault on a small card, in a place that is not the keyholder's pocket. The office drawer or a locked cash box works. If the vault is locked and the keyholder is the only one who has the key, you have not fixed anything.
- Write a two-page sick-day note: what each login is for, who to call when a portal misbehaves, and where the note lives. Store the note inside the vault and print one copy for the office drawer.
The accounts nobody thinks to protect
The payroll portal is obvious. The surprises are the boring accounts. The domain name for your website lives in someone's personal email. The shop's phone number is on a carrier plan tied to the owner's credit card, so the shop's number can be canceled by a billing statement sent to the wrong person. The Wi-Fi password is whatever the sticker on the router says, and it has never changed. The local bank's business account was opened with the owner's personal ID and never changed hands.
When you build the folder list, make one folder called "boring but deadly" and put the domain, the carrier, the bank, and the insurance account in it. A stranger who owns your domain name can read every email your customers send to it. That one folder is worth more than most audits.
The habits that keep it working
A shared vault that nobody touches for a year becomes a new keyholder: the vault itself. A few small habits keep it honest, and none of them take long.
Once a quarter, have one person test that a second device can actually log into the important accounts. It takes fifteen minutes, and it is the difference between "we have a plan" and "the plan works." When someone leaves, remove them from the vault the same week and decide in that same meeting whether any password needs rotating. And when the supplier portal demands a new password, update the vault, not a sticky note. The sticky note is where good passwords go to die.
One more habit, because it is the one shops forget: when you change your business phone, domain, or email, update the vault entry and the sick-day note in the same sitting. Logins are cheap to fix while you are in the app. They are expensive to reconstruct from memory in a group chat at 7 a.m. on a Monday.
None of this is expensive, and none of it needs a tech person. The real cost is the one you already pay, just in pieces: the 9 a.m. scramble, the screenshotted password, the invoice that never got approved. Put it in one place on a Saturday, and the sick day stops being a fire drill. Your keyholder can still call in on Tuesdays. That is what a plan is for.