How to Share Passwords Safely With a Virtual Assistant

Giving a virtual assistant access to your business does not have to mean sharing master passwords or opening every account. This guide explains how to use password managers, MFA, limited permissions, confidentiality rules, and a simple access register to delegate more securely.
Two professionals confirming secure account access for virtual assistant work

The fastest way to give a virtual assistant access is also one of the easiest ways to create unnecessary risk: send your own password in a message and move on.

If you need to share passwords safely with a virtual assistant, a better approach is to separate the work from the access. Decide what the assistant actually needs to do, give the lowest level of access that makes that work possible, add appropriate authentication, and keep a record you can review or revoke later.

That does not require turning VA onboarding into a cybersecurity project. It requires a few deliberate controls before sensitive accounts and information start moving between people.

This checklist walks through that setup, from deciding what access is necessary to removing it when a responsibility changes or ends.

Inventory the Accounts and Data Your VA Actually Needs

Start with the responsibility, not the login.

If your VA will prepare WordPress drafts, they need enough access to create and edit content. That does not automatically mean they need hosting, domain, billing, or full administrator access.

If they are maintaining a spreadsheet, they may need permission to edit one folder or file rather than your entire Drive.

Before granting anything, create a simple access map:

ResponsibilitySystemWhat the VA needs to doAccess needed
Prepare blog draftsWordPressCreate and edit postsAuthor or Editor, depending on workflow
Update lead recordsCRMEdit assigned recordsStandard user with relevant records
Maintain shared filesGoogle DriveView or edit selected foldersViewer, Commenter, or Editor as required
Prepare analytics reportsGA4View and export reporting dataLowest role that supports the approved reporting task

The exact role names will vary between platforms. The important question stays the same: what is the minimum access that still allows the work to be completed properly?

This should happen alongside the wider virtual assistant onboarding process, not after the VA has already started asking for credentials one account at a time.

Use a Password Manager Instead of Sending Credentials in Messages

When a platform supports individual users, collaborator invitations, or team accounts, use those options first. They make it easier to identify who has access and remove that person later without changing somebody else’s account.

Some systems still require a shared login. That is where a team password manager becomes useful.

Instead of copying the password into email, chat, a task comment, or a spreadsheet, store the credential in a managed vault and grant the appropriate person access through the password-management system.

Current VA-specific security guidance recommends this approach, and virtual assistant hiring guidance similarly identifies password managers, MFA, and avoiding credentials in chat as useful security basics.

Tools such as 1Password, Bitwarden, and LastPass offer business or team sharing features, although the exact permissions differ by product and plan. Check what your chosen tool actually allows before assuming that every shared credential can be hidden, restricted, or audited in the same way.

A useful rule is:

Named account when possible. Managed vault when a shared credential is genuinely necessary. Raw password in a message only as something to avoid, not as the normal workflow.

Also keep the vault itself protected. A password manager does not help much if the master account uses weak authentication or access remains active long after somebody no longer needs it.

Enable MFA Before Sensitive Access Becomes Routine

A password should not be the only thing standing between an important business account and somebody trying to sign in.

Microsoft’s explanation of two-factor authentication describes 2FA as requiring two distinct forms of identity verification. MFA applies the same general idea using two or more factors.

For accounts that support it, enable MFA before the VA begins using them regularly.

Priority accounts may include:

  • email;

  • password managers;

  • file storage;

  • CMS and website administration;

  • CRM systems;

  • analytics and advertising accounts;

  • financial or billing systems;

  • project or client systems containing sensitive information.

CISA recommends requiring MFA wherever possible and advises using the strongest option available. Its guidance places security keys and stronger authenticator methods above text or email codes.

That does not mean every small business needs hardware security keys for every tool. It does mean you should use stronger options when the platform and risk justify them rather than automatically choosing the easiest method.

Think about the operating workflow too. If every VA login depends on you forwarding a one-time code manually, you have created both a security problem and a bottleneck.

Where possible, use named accounts with their own approved MFA method or an organization-supported authentication setup.

Apply Least-Privilege Access Instead of Sharing Admin by Default

Security becomes easier when a compromised or mistaken account cannot reach everything.

The NIST definition of least privilege describes the principle as restricting users to the minimum access necessary to complete assigned tasks.

That maps neatly to virtual-assistant work.

A VA preparing WordPress content may need Editor access but not the ability to install plugins or change administrators.

A VA organizing shared files may need one project folder rather than the whole company Drive.

A VA preparing reporting may need access to reporting data without permission to change account configuration.

The same principle is useful when delegating analytics. My guide to GA4 reporting with a virtual assistant shows how the required role changes depending on whether the person is viewing and exporting reports or creating features that require higher permissions.

Do not treat the highest permission level as the convenient default.

Start lower. Expand access when the responsibility actually requires it.

Keep Files and Work Inside Controlled Collaboration Spaces

Credentials are only one part of secure delegation.

Your VA may also work with client files, reports, contact data, internal documents, calendars, or project information. Those should have deliberate sharing rules too.

For example, Google Drive’s sharing controls let you choose roles such as Viewer, Commenter, or Editor, while some eligible work and school accounts can also use expiration settings for certain access.

Use those controls instead of making a folder broadly accessible just because it is quicker.

The same principle applies to communication. Keep the task and its context in the approved project or communication system, but keep passwords and recovery information out of ordinary chat messages and task comments.

For scheduling work, prefer proper calendar delegation, shared-calendar permissions, or an approved scheduling tool over sharing the password to your main email account.

If the delegated work involves shared spreadsheets, the guide to spreadsheet collaboration with a virtual assistant covers permissions, protected ranges, version history, validation, and change rules in more detail.

The goal is not to scatter work across security tools. It is to make the approved place for each kind of information obvious.

Set Confidentiality and Data-Handling Rules in Writing

Technical controls answer the question, “What can this person access?”

Written rules answer another question: “What are they allowed to do with what they can access?”

Depending on the work, those rules may cover:

  • information that must remain confidential;

  • whether client data may be downloaded locally;

  • whether files may be stored on personal devices;

  • whether information may be entered into AI or third-party tools;

  • whether external sharing is allowed;

  • how suspected mistakes or unusual activity should be reported;

  • what should happen to downloaded material when the engagement ends.

For sensitive work, a confidentiality clause or NDA may also be appropriate. An NDA is a legally binding confidentiality agreement, but its wording and enforceability can depend on the jurisdiction and situation.

An NDA should therefore complement sensible access controls, not replace them.

A signed document does not make an unnecessarily shared administrator password safer.

If the legal wording matters to your business, have an appropriately qualified professional review it rather than relying on a generic template alone.

Maintain a Simple Access Register

As a working relationship grows, access tends to accumulate.

One task requires WordPress. Another requires Drive. Then a CRM account is added. Six months later, nobody remembers which systems were granted for which responsibility.

An access register prevents that from becoming guesswork.

It does not need to be complicated:

Tool or systemVA accountPermissionMFADate grantedReview or removal trigger
WordPressNamed VA userEditorYes[date]Role changes
Google DriveNamed emailSelected foldersYes[date]Project ends
CRMNamed VA userStandard userYes[date]Responsibility changes
Shared password vaultVA vault memberApproved collectionYes[date]Engagement ends

Update the register when access changes rather than trying to reconstruct everything during offboarding.

This becomes especially important when you scale your business with virtual assistants and one stable responsibility develops into several connected workflows.

When a responsibility changes, ask whether the old access is still necessary.

When the engagement ends, review the register and remove what is no longer needed. That can include named user accounts, password-vault membership, shared groups and folders, active sessions, API or app access, and other permissions created for the work.

If an actual shared password was exposed to the person rather than controlled through a revocable account or vault, changing that credential may also be appropriate.

What Not to Do

A few shortcuts create far more exposure than they save in setup time.

Do not share your main administrator login when the platform supports individual users. A named account is easier to limit, identify, and revoke.

Do not paste passwords into ordinary email, chat, task comments, or shared spreadsheets. Keep credential handling separate from normal project conversation.

Do not grant every permission “just in case.” Give access when the work creates a real need for it.

Do not treat MFA recovery codes as everyday login credentials. Recovery information should remain controlled rather than circulating through routine messages.

Do not let old access remain indefinitely. Responsibilities change, projects end, and permissions should change with them.

Do not rely on an NDA as your security system. Agreements, authentication, account permissions, and access reviews solve different parts of the problem.

Security Prep Checklist for Working With a VA

Use this before giving a virtual assistant access to important business systems.

Before access is granted

CheckComplete when
☐ List the required systemsYou know which accounts, folders, and data are genuinely needed for the first responsibility.
☐ Create named accounts where possibleThe VA does not need to sign in as the owner or main administrator when a collaborator account exists.
☐ Set up credential sharingAny genuinely shared login is handled through an approved password manager rather than ordinary messages.
☐ Enable MFAImportant accounts use an appropriate second authentication factor.
☐ Choose the lowest suitable permissionThe VA can complete the agreed work without unnecessary administrative control.
☐ Define confidentiality rulesSensitive information, downloads, third-party sharing, AI use, and reporting expectations are clear where relevant.
☐ Prepare the access registerEvery granted system can be reviewed later instead of relying on memory.

While access is active

CheckComplete when
☐ New access is recordedNew tools and permissions are added to the register when granted.
☐ Credentials stay out of project chatTasks and questions can be discussed without copying passwords into the conversation.
☐ Permission increases have a reasonHigher access is connected to a genuine change in responsibility.
☐ Sensitive issues are escalatedThe VA knows what to do when access is missing, unusual activity appears, or a security-sensitive mistake occurs.
☐ Access is reviewed when the role changesOld permissions are not automatically carried into a new responsibility.

When a responsibility or engagement ends

CheckComplete when
☐ Remove or downgrade named accountsAccess matches the work that remains.
☐ Remove password-vault membershipShared collections or credentials are no longer available unnecessarily.
☐ Remove shared folders, groups, and app accessCollaboration permissions have been reviewed.
☐ Review sessions, tokens, or integrations where relevantAccess routes created for the work have been closed when needed.
☐ Change genuinely exposed shared credentials when appropriateA password that can no longer be controlled through account removal is replaced.
☐ Record the removalThe access register shows what was revoked and when.

Secure Delegation Starts With Controlled Access

Working securely with a virtual assistant is not about distrusting the person you hire.

It is about building the working relationship so that neither of you has to depend on risky shortcuts.

Use named accounts where possible. Keep shared credentials in an appropriate password manager. Enable MFA. Grant the lowest useful permissions. Keep sensitive files inside controlled workspaces. Document confidentiality expectations. Track access so you can review and remove it later.

At Boost VA, Tools & Access is an explicit part of onboarding because account setup needs to connect to the work being delegated rather than becoming an improvised password exchange after the task has already started.

If you already know which recurring work or project you want to hand off and need dependable execution inside your existing systems, you can explore my virtual assistant support and send me the workflow you want help with.

Operational note: This guide covers practical access-management steps and is not legal or professional cybersecurity advice. Legal, contractual, privacy, and security requirements can vary by business, system, data type, and jurisdiction.

Share Post:

Related Articles