The Credential Handoff Problem
When web agencies and freelancers onboard new clients or hand over completed projects, they frequently exchange sensitive access details. This includes CMS logins, domain registrar credentials, and web hosting access.
Emailing these credentials or dropping them in a long-running Slack channel creates a significant security risk. While email and chat platforms are not inherently insecure, their retention policies mean that any plaintext passwords sit in a searchable inbox indefinitely. If a client's email is ever compromised in a phishing attack years later, those credentials could be stolen, leading to potential liability.
Secure Handoff Checklist
To protect both your agency and your clients, establish a secure credential handoff process:
- Access Inventory: Document exactly what systems the client needs access to. Avoid handing over unnecessary credentials.
- Least Privilege and Individual Accounts: Instead of sharing a single master administrative account, create distinct, limited-permission accounts for the client and each team member where possible.
- Temporary Transmission: When passing temporary credentials or initial setup passwords, do not use email or chat. Use Hush to transmit the initial password securely.
- Prompt Rotation: Instruct the client to immediately log in, change the temporary password, and store the new credential in their own secure password manager.
- Post-Handoff Cleanup: Once the project is complete, revoke the agency's temporary access or rotate the administrative passwords. Ensure no lingering access remains.
Knowing the Limits
When using Hush for client handoffs, remember that it represents one limited transmission step, not a comprehensive onboarding system.
Hush ensures the password does not persist in chat history, but it cannot prevent a client from saving a screenshot, ignoring password rotation advice, or using a compromised device. It is a transmission tool, not a substitute for proper access controls or client education.
For more information, see our Agencies Use Case, our guide on securely sharing passwords, or read about handling recovery codes. Review our Privacy Policy and Security pages for full technical details.