For most small teams, the deciding question isn’t which vault encrypts better. It’s what happens when someone forgets their password or leaves. Choose Bitwarden if you want open-source software and directory sync on its Teams plan, and either accept that admin account recovery needs Enterprise or move up to it. Choose 1Password if lockouts are the bigger worry: owners and admins can recover a team member’s account, and the Teams Starter Pack is sized for teams of up to 20. Choose Keeper if handing over a departing employee’s vault matters most: its Account Transfer policy moves a locked user’s records to someone else.
All three give each person an encrypted vault, generate strong passwords, and let a team share logins without pasting them into chat. Bitwarden and Keeper describe their encryption as zero-knowledge; 1Password describes end-to-end AES 256-bit encryption. NIST’s digital identity guidelines (SP 800-63B) tell sites to allow password managers and autofill, and note that password managers make stronger passwords more likely, especially when they include a password generator.
This comparison is desk research from each vendor’s plan pages and help documentation, checked on October 9, 2026. None of these products was used hands-on for this page. Plan prices change often, so they aren’t quoted here.
Bitwarden vs 1Password vs Keeper at a glance
| Bitwarden | 1Password | Keeper | |
|---|---|---|---|
| Small-team plan | Teams (per seat, unlimited users) | Teams Starter Pack (10 members, up to 20) | Business Starter (5 to 10 seats) |
| Admin account recovery | Enterprise plan only | Owners and admins can recover members | Account Transfer for business plans |
| Directory and SSO | Teams: directory sync and SCIM; SSO on Enterprise | Business adds Okta, Entra ID, OneLogin, Duo | Enterprise adds SCIM, SAML 2.0 SSO, AD/LDAP |
| Hardware security keys | Up to 10 keys, plus Yubico OTP | FIDO U2F keys as a second factor | FIDO2 WebAuthn keys such as YubiKey |
| Sharing with non-users | Bitwarden Send | Share items with anyone | One-Time Share |
Bitwarden: open source, with SCIM on the Teams plan
Bitwarden’s business plans come in two tiers. Teams covers centralized ownership, secure sharing through collections, event logs, directory sync through the Directory Connector, and SCIM provisioning, with unlimited users at a flat per-seat rate. Enterprise adds granular access control, passwordless SSO, enterprise policies, the option to self-host, and a free Families plan for every user.
Every business seat also gets Bitwarden’s Premium features: two-step login with up to 10 hardware security keys, Yubico OTP, Duo, email or an authenticator app; encrypted file attachments (5 GB personal and 5 GB for organization items); an integrated authenticator for TOTP codes; vault health reports; and personal emergency access. Event logs record more than 50 event types and, according to Bitwarden, are retained indefinitely and exportable.
The catch for a small team is recovery. Bitwarden’s help center says account recovery, which lets an admin reset a member’s master password or two-step login, is available for Enterprise organizations. On Teams, an admin can’t reset a member’s master password, so keep company logins in shared collections rather than personal vaults, and have each member save their two-step login recovery code.
1Password: account recovery and guests built in
1Password’s Teams Starter Pack includes 10 members, and you can add up to 10 more seats for 20 in total. 1Password Business is priced per user and adds identity-provider integrations (Okta, Entra ID, OneLogin, Duo and others), Watchtower alerts, and expanded role-based vault sharing and permissions.
Its strongest small-team feature is recovery. 1Password’s support documentation says a team administrator or owner, or anyone in a custom group with the Recover Accounts permission, can restore access for a member who can’t sign in. The member gets a new Secret Key, creates a new account password and keeps all their data. 1Password recommends making sure at least two people can recover accounts.
Other details from 1Password’s business plan page:
- Apps for macOS, iOS, watchOS, Windows, Android and Linux, and browser extensions for Chrome, Safari, Edge, Firefox and Brave.
- Two-Key Derivation: account access combines your password with a Secret Key.
- Sharing with anyone, even people without 1Password, with expiration dates and share history, plus limited-access guest accounts (5 on Teams Starter Pack, 20 on Business).
- SOC 2 Type II certification, as 1Password states it.
Keeper: offboarding by account transfer
Keeper’s Business Starter plan covers 5 to 10 seats. Business has a 5-seat minimum and adds delegated administration. Both include an encrypted vault for every user, shared team folders, an admin console with a policy engine, team management, a Risk Management Dashboard, a Security Audit, and a free Family plan for every user. Enterprise adds SCIM provisioning, Active Directory and LDAP sync, Entra ID integration, SAML 2.0 single sign-on, and Duo and RSA two-factor options.
Keeper’s documentation describes an Account Transfer policy for business and enterprise customers that moves a user’s vault to another user if they’re terminated or leave abruptly. It has to be set up in advance: the policy is enabled on a role, users must log in and accept it, and the admin locks the account before transferring it. After the transfer, the original account is permanently deleted. Keeper says this does not give admins ongoing access to anyone’s vault.
Keeper also lists permanent or time-limited sharing with individuals or teams, One-Time Share for people who don’t use Keeper, view-only, edit, share or owner permissions on records, an integrated TOTP generator, and 24x7 support by live chat and email for business users. Keeper states that its platform is SOC 2 Type II audited and ISO 27001 certified, among other certifications it lists.
Security keys for the owner and admin accounts
The password manager account is now the key to everything else, so the people who can see, share or recover other members’ logins deserve the strongest second factor. All three products accept hardware security keys: Bitwarden supports up to 10 keys per account, 1Password accepts FIDO U2F keys as a second factor, and Keeper supports FIDO2 WebAuthn keys such as YubiKey. Keeper’s setup guide has you keep a standard two-factor method as a backup for when a key isn’t available, and registering two keys per admin, one kept somewhere safe, serves the same purpose.
| Key | Connects by | Protocols (per Yubico) | Best for |
|---|---|---|---|
| YubiKey 5C NFC | USB-C and NFC | FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH, PIV, OpenPGP | Admins on USB-C laptops and NFC phones |
| YubiKey 5 NFC | USB-A and NFC | Same as YubiKey 5C NFC | Desktops and laptops with USB-A ports |
| Security Key C NFC | USB-C and NFC | FIDO2/WebAuthn and FIDO U2F only | Staff who only need passkey-style 2FA |
- YubiKey 5C NFC is the most flexible choice for an admin. Yubico describes the YubiKey 5 Series as supporting FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP, OATH-HOTP, smart card (PIV) and OpenPGP, so it also covers Bitwarden’s Yubico OTP option.
- YubiKey 5 NFC is the same multi-protocol key with a USB-A connector, for older desktops and docks.
- Security Key C NFC is Yubico’s FIDO-only key. It covers FIDO2/WebAuthn and FIDO U2F but not Yubico OTP or smart card use, which is enough for staff whose accounts accept FIDO security keys.
At the time of writing, all three keys are sold on Amazon by Yubico’s own store.
How to choose
- Decide how you’ll handle lockouts and departures before you buy. If an admin must be able to restore a member’s access, that’s built into 1Password, and on Bitwarden it requires Enterprise. If you need to take over a departing person’s private vault, Keeper’s Account Transfer does that, but only if it was enabled and accepted beforehand.
- Keep shared logins out of personal vaults. Put every company login in a shared collection (Bitwarden), shared vault (1Password) or shared team folder (Keeper) owned by the business, so recovery is the exception, not the plan. Then add the password manager to your regular permission audit checklist.
- Match the plan to your identity setup. If staff sign in with Google Workspace or Microsoft 365, check which tier connects to it: Bitwarden puts SCIM on Teams and SSO on Enterprise, 1Password puts identity-provider integrations on Business, and Keeper puts SCIM and SSO on Enterprise.
- Plan for contractors. For one-off handoffs, use Bitwarden Send, 1Password item sharing or Keeper One-Time Share instead of email. For ongoing outside help, 1Password’s guest accounts limit a person to specific vaults.
- Require two-factor authentication for everyone, and give admins security keys.
Access changes belong in your monthly office operations checklist, and files that hold credentials or client records follow the same ownership rules as your shared files.
Frequently Asked Questions
What happens to a password vault when an employee leaves?
It depends on the setup you chose before they left. Keeper’s Account Transfer policy moves a locked user’s records to another user, but it has to be enabled, and the user has to accept it, ahead of time. 1Password and Bitwarden Enterprise let admins recover a member’s access. In every product, keep shared logins in shared vaults, collections or folders so they never depend on one person’s account.
Can we share a login with a contractor who doesn’t use our password manager?
Yes. Bitwarden Send, 1Password item sharing and Keeper One-Time Share all send information to people without an account. 1Password also offers limited-access guest accounts for ongoing work.
Do we still need two-factor authentication with a password manager?
Yes. All three products support two-factor authentication on the password manager account itself, including hardware security keys. Turn it on for everyone, and use security keys for the owner and admin accounts.
Sources
Checked October 9, 2026.
- Bitwarden: business plans and features, About Account Recovery
- 1Password: business pricing and plan features, Recover accounts for family or team members, Use your security key as a second factor
- Keeper: Business Password Manager plans, Account Transfer Policy, Two-Factor Authentication
- Yubico: YubiKey 5C NFC, YubiKey 5 NFC, Security Key C NFC
- NIST: SP 800-63B Digital Identity Guidelines, Authentication and Authenticator Management
See Also
If you want to move from general advice into actual product choices, start with Business Phone Service for a Small Team: VoIP Options and 911 Rules, E-Signature Tools for a Small Business: Docusign, Dropbox Sign or Google Workspace, and SOP Template for Appointment Scheduling: Simple Process for Small Teams.
For a wider picture after the basics, Brother QL-800 Review: Office Labels, Red Printing and the Width Limit and CRM for Beginners: A Simple Guide for Small Business Teams are the next places to read.