A freelancer finishes a three month contract and someone on the team removes them from the shared vault. That single click feels like the offboarding step is done. It is not. Removing a person from a password manager and changing the passwords they had access to are two different operations, and a business plan that only does the first one leaves every login they ever saw still working exactly as it did the day before.
The problem is not one login, it is the count of them
A social team’s credential surface is wider than the social accounts themselves. There is the ad platform account running the paid boosts, the analytics dashboard pulling performance numbers for the client report, the stock media library the design contractor pulls assets from, and the CMS the freelance writer logs into to post. Each of those sits behind its own login, and each one tends to get shared with whoever is doing the work that quarter. Freelancers rotate through social teams more often than full time staff do, which means this list of logins does not shrink between contracts. It accumulates.
None of this requires a specific count to make the point. Every one of these logins is a place a departing contractor’s access has to be dealt with, and “dealt with” means something different depending on the tool.
What “revoke” means inside a password manager, and what it does not mean
This is the distinction the rest of the post turns on. Removing a team member from a shared vault, or from the organization entirely, stops that person’s password manager app or browser extension from displaying the saved credential going forward. It does not change the credential itself. The password behind that login is exactly what it was before the removal, unless someone takes the separate step of rotating it.
The case this bites hardest: any login the freelancer ever saw or copied outside the password manager’s own interface is not touched by deprovisioning at all. If they typed the password into a login form, if their browser separately saved it, or if they wrote it in a note somewhere, removing them from the vault does nothing to that copy. The password manager can only revoke what it controls, which is its own display of the secret. It cannot reach into a browser’s separate autofill store or a screenshot on someone’s laptop.
1Password Business: what the admin console does on offboarding
1Password Business costs $8.99 per user per month when billed annually, or $10.99 per user per month billed monthly, according to 1Password’s own business pricing page, fetched on 2026-09-09. The plan has a stated minimum of one user, priced per user, and includes identity provider integrations, role based vault sharing and permissions, and its Watchtower alerting.
1Password’s business security page, also fetched on 2026-09-09, discusses onboarding and offboarding at a program level. It lists SaaS offboarding and credential management among the capabilities the business tier is built around, but the page does not spell out, in terms specific enough to quote, exactly what happens to a suspended or removed member’s shared vault access at the moment of removal, or whether the product itself flags any vaulted items as needing rotation once that person is gone. [EVIDENCE NEEDED: 1Password’s own documentation stating explicitly whether shared vault access ends immediately upon suspension or removal, and whether the product flags any items for rotation afterward].
Dashlane Business: what the admin console does on offboarding
Dashlane’s Password Management plan, the base business tier at the URL Dashlane lists for its business password manager, costs $8 per user per month billed annually, according to Dashlane’s own pricing page, fetched on 2026-09-09. A separate Credential Protection package is priced at $4 per user per month billed annually on the same page; that is a different product built around detecting credential risk rather than managing the vault itself.
Dashlane’s business password manager page states that the plan lets an admin “automate user provisioning, deprovisioning, and management,” and separately advertises “automated onboarding and offboarding via SCIM.” That confirms Dashlane treats removing a user as an automatable admin action. What the page does not state is what happens to the specific shared items that removed user had access to: whether their view of shared vault items ends immediately, and whether any password gets changed as part of that removal. [EVIDENCE NEEDED: Dashlane’s own documentation on what happens to shared vault access at the moment a team member is deprovisioned, and whether any credential rotation is triggered]. Nothing on the page claims that removing a user changes any password automatically, so that claim should not be assumed either way.
Side by side: instant versus manual
| What happens | 1Password Business | Dashlane Business (Password Management) |
|---|---|---|
| Vault access on removal | [EVIDENCE NEEDED: not explicitly documented on the fetched page] | [EVIDENCE NEEDED: not explicitly documented on the fetched page] |
| Shared items auto rotated on removal | [EVIDENCE NEEDED: not stated] | Not documented as happening; page makes no such claim |
| Per seat price | $8.99/user/month billed annually ($10.99 billed monthly) | $8/user/month billed annually |
| Minimum seats | 1 user minimum, per 1Password’s own pricing page | [EVIDENCE NEEDED: not stated on the fetched pricing page] |
The one row both vendors’ own pages leave equally unresolved is the one that matters most for offboarding: neither page states, specifically enough to quote, that removing a user rotates the passwords they had access to. Treat that as unproven for both plans.
The five minute list versus the afternoon list
Picture the categories from the first section: an ad platform account, an analytics dashboard, a stock media library, a CMS login. Based on what removal actually does inside a vault, here is how each sorts.
- Ad platform account. If the freelancer only ever accessed it through the vault’s autofill, removing them from the vault stops that avenue. If they ever logged into the ad platform directly and stayed signed in on their own device, or if the platform issued them a personal user seat rather than a shared login, vault removal alone does not close that door. That still needs a manual check inside the ad platform’s own user management.
- Analytics dashboard. Same logic. A shared login stored only in the vault is cut off from that person’s app going forward. A login they typed once and let their browser remember separately is not.
- Stock media library. If licensing seats were issued per person rather than through one shared vaulted login, removing the vault entry does nothing, because the account was never the vault’s to revoke.
- CMS. If the CMS has its own user accounts with its own admin panel, that is a manual reset regardless of what the password manager does, because the CMS’s own user list is the thing that needs to change, not the vault entry pointing to it.
The general rule holding all four together: vault removal handles the case where the only way that person could see the password was through the vault. Anywhere the credential also lived outside the vault, in a browser’s own memory, in a note, in a personally issued account seat, removal from the vault is the five minute step and the manual reset is the afternoon step that still has to happen.
What a shared spreadsheet actually costs you here
A spreadsheet of logins has no access control step at all. It only has visibility: anyone with the link or the file can read every password in it, and there is no mechanism inside the spreadsheet that stops that once someone is no longer supposed to have it. “Removing” a freelancer from a spreadsheet means finding every row they could have seen and changing every one of those passwords by hand, because the spreadsheet itself never had a revoke function to begin with. That is the afternoon list outcome, but for every single login on the sheet, not just the subset that a real vault could not auto revoke. A business password manager narrows that afternoon list down to the credentials that lived outside its own vault. A spreadsheet never narrows it at all.
FAQ
If I remove a freelancer from our password manager, are the passwords they used now safe?
Not automatically. Removing someone from a vault or organization ends their ability to see the saved credential inside the app going forward, but it does not change the credential itself. If they ever typed the password into a browser that saved it separately, wrote it down, or a device they used stays logged into the account outside the vault, that exposure continues until someone actually rotates the password.
Do either of these plans auto rotate passwords when you remove a user?
Neither vendor’s own page states that removing a user automatically rotates the passwords they had access to. Dashlane’s page confirms that deprovisioning itself can be automated, but not that it changes any credential. 1Password’s business security page does not address this specifically either. Both are marked as evidence gaps in the ledger rather than assumed one way or the other.
Sources
- 1Password Business pricing, fetched 2026-09-09
- 1Password Business Security, fetched 2026-09-09
- Dashlane pricing, fetched 2026-09-09
- Dashlane Business Password Manager, fetched 2026-09-09
- sharing one account’s login without exposing the password, fetched 2026-09-09
- what a browser extension can see on a team laptop, fetched 2026-09-09
- invoicing tools for social media freelancers, fetched 2026-09-09
