# Shared Vaults and Groups — 1Password and Secrets Hygiene for Developers

Source: https://www.geekswithgeeks.com/en/secrets-hygiene/team-shared-vaults

> Give access through groups and shared vaults instead of sending secrets in messages.

## Never paste secrets in chat

Chat history is searchable, retained and copied to many devices. Put the secret in a shared vault and give the person or **group** access to that vault. When they leave, you remove access once and the secret stays in one place.

## Share by access, not by copy

A shared vault gives access without copying the value into chat or email, and access can be removed later.

![Three steps: grant, use, revoke.](assets/figures/secrets-hygiene/section-4-map.svg) — Figure 4.1 — Grant, use and revoke access.

## A shared office cabinet

Instead of photocopying a document for everyone, you keep one original in a cabinet and decide who holds a key to it. Updating the original updates it for all.

## Use groups, not individuals

Grant access to groups like "Backend" or "SRE". People joining or leaving a team then get or lose access automatically, with no vault-by-vault editing.

**Quiz:** What is the safest way to give a teammate the production database password?

- [ ] Paste it in the team chat
- [ ] Email it with the subject "password"
- [x] Share the vault that holds it
- [ ] Write it on a sticky note

*Answer:* Share the vault that holds it. Sharing the vault keeps one source of truth and lets you revoke access later.
