Most small-business password policies fail for the same reason: they are either too vague (“use strong passwords”) or too corporate (“passwords must be 16 characters, changed every 90 days, never reused, and stored only in the approved enterprise vault”).
Neither version works well for a team of 8, 20, or 45 people who already share logins, keep passwords in browser autofill or spreadsheets, and have no one whose full-time job is enforcing rules.

A usable password policy for small teams has three jobs only:
Stop the most dangerous shared-credential habits
Make unique, strong passwords the path of least resistance
Create a clear, low-drama way to handle new accounts and offboarding
Everything else is secondary.
The Core Rules (Keep These Short)
Rule 1: No shared passwords for important systems
Email, banking, payroll, domain registrar, Microsoft 365 / Google Workspace admin, password manager master accounts, and any tool that holds customer or financial data must have individual logins. Shared credentials on these systems are the single most common source of preventable incidents.
Rule 2: Every important account uses multi-factor authentication
Where MFA is available, it is required. Authenticator apps are preferred over SMS. This rule alone blocks a large percentage of credential-based attacks even when a password is weak or reused.
Rule 3: A company password manager is the standard way to store credentials
Browser-saved passwords, shared Google Docs, Slack messages, and sticky notes are not acceptable for work accounts. The password manager becomes the single place where credentials live. This is both a security control and a practical offboarding tool.
Rule 4: Passwords for critical systems are unique and randomly generated
The password manager generates them. Employees should not be inventing their own “clever” passwords for banking, email, or admin accounts. Length and randomness matter more than complexity rules that people try to outsmart.
Rule 5: When someone leaves, their access is removed the same day
This includes the password manager, email, cloud storage, project tools, and any shared vaults. The policy is incomplete without a matching offboarding step.
What You Do Not Need in the Policy
You can safely leave out:
Mandatory 90-day password changes (these often create worse habits)
Detailed complexity requirements that people work around
Long lists of prohibited password patterns
Requirements that every single low-risk tool follow the same strict standard
Focus the strict rules on the systems that can actually hurt the business. Lower-risk tools can follow lighter guidelines.
How to Roll It Out Without a Big Fight
Announce the change as an operational improvement, not a security crackdown.
A practical sequence looks like this:
Choose and pay for a straightforward password manager (several good options exist at small-team pricing).
Set up the company vault and admin account with MFA.
Move the most critical shared logins into the vault first and create individual accounts where possible.
Give every employee access and a short 15-minute walkthrough.
Set a firm date after which shared spreadsheets and browser-saved work passwords are no longer acceptable.
Add the password manager and MFA checks to your new-employee laptop setup and offboarding checklists.
Most resistance fades once people experience how much faster it is to find a credential in a shared vault than to ask around or dig through old emails.
Handling the Inevitable Exceptions
There will be a few systems that still require a shared login (some older vendor portals, certain industry tools, etc.). Treat these as exceptions:
Store the credential only in the password manager
Limit the number of people who can see it
Change it immediately when anyone with access leaves
Review the list of exceptions every six months
Documenting the exceptions is better than pretending they do not exist.
One-Page Policy Template (Copy and Adapt)
Company Password Policy – Short Version
Important systems require individual accounts and MFA.
All work passwords are stored in the company password manager.
Critical passwords are unique and generated by the password manager.
Shared passwords are not allowed on email, banking, payroll, admin portals, or customer data systems.
When an employee leaves, all access is removed the same day.
Exceptions must be recorded and reviewed twice a year.

That is enough to guide daily behavior. Longer documents tend to be ignored.
Final Note
A password policy only works if people can follow it under normal time pressure. The version above prioritizes the highest-risk behaviors and replaces them with clearer, easier habits.
Shared logins and undocumented credentials are not a technology problem. They are an operational habit. Change the habit with a short, enforceable policy and a password manager that makes the right action the easy one.
Secure enough starts with knowing who has access—and being able to take it away cleanly.
No feedback yet — submit the first.