guide · Digital legacy

Password emergency access: plan the route without sharing a password sheet

Review emergency-access options, account dependencies and recovery instructions so your chosen person knows the approved route when needed.

Last reviewed . Rules change — check with the provider before you rely on this guide.

Write down the access process, not every secret #

A household account inventory should identify essential services and where protected access instructions live. It should not become a broadly shared list of passwords, recovery codes or device PINs. Check what your password manager supports and what you want your chosen person to be able to do.

Check four details with your provider #

Features differ. Read the current documentation before relying on an emergency-access arrangement.

  • Who can be designated and whether they need their own account.
  • Whether the invitation must be accepted and confirmed.
  • What kind of access is granted and which information is included.
  • What request, notification and waiting steps apply.

Distinguish emergency access from account recovery #

As one example, Bitwarden offers designated emergency contacts who can request access under its emergency-access process. That is a provider-specific capability, not a universal feature of password managers. Review the current permissions and setup requirements directly with the provider, and do not assume it also grants authority to operate every account whose credentials are stored.

Source: Bitwarden: About emergency access

Map the dependencies that could block the plan #

A helper may need their own email or device to receive instructions. Your usual recovery route may itself depend on an inaccessible phone or email account. Record those dependencies and ask the provider how its approved process handles them. Google, for example, says its deceased-account process does not supply account passwords.

Source: Google: Requests regarding a deceased user’s account

Confirm the setup before depending on it #

Ask the chosen person to confirm their role and show that they can find the provider instructions, without exposing the vault. Use any safe test process the provider supports; do not trigger a real takeover casually. Revisit the plan after changing password managers, contacts, devices or recovery methods.

WiseTomorrow is a technology service for organizing and sharing information. It does not provide legal, tax, financial or estate-planning advice, does not replace a will, trust, power of attorney, beneficiary designation or advance directive, and does not verify that stored documents are valid. Consult a licensed professional for advice about your situation. Read the full legal disclaimer.

Sources and editorial notes

Prepared by WiseTomorrow, the maker of Wise Box. These resources help organize information; they are not an independent product review. No specialist review is claimed. How these resources are prepared.

Have a correction? Contact WiseTomorrow.

Keep going