TL;DR: Duke University tripled enrollment after migrating to a new password manager, while security teams still found groups sharing vaults, mixing personal and work accounts, and bypassing consistent password hygiene, according to 1Password. The lesson is that password security improves only when usability and governance are aligned, not when tools exist in name only.
At a glance
What this is: This is a case study showing that Duke University increased password-manager adoption, yet inconsistent vault sharing and account separation still exposed a governance gap.
Why it matters: It matters because IAM teams cannot treat password management as a tool rollout alone, especially where shared accounts, personal-use bleed-through, and training consistency determine whether security actually improves.
Context
Password security is not only a user-behaviour problem. In this case, Duke University had the right intent and a broadly deployed password manager, but daily use was uneven and governance expectations were not being followed consistently across teams.
The identity lesson is straightforward for human IAM programmes: adoption metrics can improve while control quality remains mixed. When users can still share vaults, keep personal and work credentials together, or bypass standard workflows, the organisation has coverage without consistent enforcement.
Key questions
Q: Why do password managers fail when users do not change their workflows?
A: Password managers only reduce risk when they are actually used the same way across teams. If users keep sharing vaults, mixing personal and work accounts, or bypassing standard onboarding, the organisation gets deployment coverage without control consistency. That leaves weak traceability and limited governance value.
Q: When does password-manager adoption stop being a security improvement?
A: It stops being a meaningful security improvement when usage is optional in practice. If teams can still collaborate through shared accounts, store business credentials alongside personal ones, or ignore approved setup patterns, the organisation has adoption statistics without reliable enforcement.
Q: What breaks when shared password vaults have no clear owner?
A: Accountability breaks. Without a named owner, the organisation cannot confidently review access, prove who should maintain the vault, or determine whether the sharing model still matches the business need. That also complicates incident response because no one is clearly responsible for the credential set.
Q: How should IAM teams handle shared passwords and shared credentials?
A: IAM teams should treat shared passwords as a control exception that increases risk and weakens accountability. If shared access is unavoidable, it needs a documented owner, tight privilege boundaries, frequent review, and a clear plan to eliminate it. The safer default is to move to individual accountability or privileged session controls.
Technical breakdown
Why password-manager adoption can outpace governance
Password managers reduce password reuse and improve credential quality, but they do not enforce operating discipline by themselves. The security model still depends on how people create vaults, share access, separate identities, and follow standard workflows. If those practices are left to local habit, the tool becomes an enabler of convenience rather than a control plane for password hygiene. That is why adoption figures alone can be misleading: they measure rollout success, not necessarily identity governance maturity.
Practical implication: measure password-manager usage alongside vault structure, account separation, and sharing patterns.
How mixed personal and work use weakens human identity controls
When employees store both personal and organisational credentials in the same place, the boundary between managed and unmanaged access becomes blurry. That creates offboarding, audit, and recovery problems because the organisation cannot easily distinguish what is corporate, what is personal, and what is shared. In practice, the risk is not only exposure of passwords, but the loss of governance context around those passwords. Human identity controls depend on clean ownership and clear administrative boundaries.
Practical implication: require separate organisational and personal password domains for all users with corporate access.
Why shared vaults undermine accountability
A shared vault can be useful when it is intentionally designed for team access, but it becomes a control failure when multiple people simply pile into one account. Shared access destroys traceability, complicates least-privilege enforcement, and makes it harder to prove who can reach what. In a mature IAM programme, shared secret storage must be exceptional, documented, and reviewable. Otherwise, the organisation has no reliable path from credential usage back to accountable ownership.
Practical implication: inventory shared vaults and review whether each one has a named owner, explicit purpose, and access review cadence.
Breaches seen in the wild
- Okta support system breach 2023: A support service account credential saved in a personal Google profile let attackers take HAR files and hijack five Okta customers' sessions.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Adoption is not governance. This case shows that password-manager rollout can improve convenience while leaving security controls inconsistent. A programme can increase enrollment and still fail to standardise account separation, vault ownership, and expected usage. The practitioner lesson is to treat adoption as a leading indicator, not evidence that the control is operating as intended.
Mixed personal and corporate credential storage is a governance smell, not a user preference. Once personal and work identities share the same storage context, organisations lose clarity over ownership, retention, and review. That weakens offboarding and incident investigation because the identity boundary is no longer clean. The implication for human IAM is that credential hygiene must be paired with explicit data and account boundaries.
Shared vault sprawl creates an accountability gap. If five groups can operate from the same account structure without a named administrative model, the organisation has convenience without traceability. That is the point where password management turns from a security control into an undocumented collaboration pattern. Teams should read this as a signal that governance rules need to be embedded into the operating model, not left to local discretion.
User experience is a control property, not a soft benefit. The article reinforces a familiar but often under-acted-on truth: when the workflow is hard, people route around it. In password governance, that means the control design itself must absorb human behaviour rather than assume compliance. The practical conclusion is that human IAM programmes fail when security architecture ignores how people actually work.
Named concept: password governance adoption gap. This is the distance between a password-management tool being deployed and it being used in a controlled, standardised way. Duke's experience shows that the gap is closed by workflow design, onboarding, and ownership discipline, not by licence count. Practitioners should use this concept to separate rollout metrics from real governance maturity.
What this signals
Password governance adoption gap: The real control problem is the distance between deploying a password manager and getting standardised, reviewable use across the organisation. Once teams create local workarounds, the tool no longer tells you much about actual governance quality.
Human IAM programmes should watch for vault sprawl, shared-account behaviour, and blurred personal-versus-corporate storage because those are the operational signs that password policy is not embedded in daily practice.
The security gain comes from workflow design and onboarding discipline, not from licensing a tool and assuming adoption will follow.
For practitioners
- Standardise vault ownership Require every shared vault to have a named business owner, a documented purpose, and a defined membership review process.
- Separate personal and work identities Prohibit storage of organisational credentials in personal vaults for users who handle corporate systems or data.
- Build onboarding around workflow habit Add short, role-based training that shows how to generate, save, and share passwords inside the approved workflow.
- Measure governance quality after rollout Track whether groups are sharing one account, mixing credential types, or bypassing standard password-manager usage.
Key takeaways
- Duke's experience shows that password-manager rollout can improve coverage without fixing the underlying governance model.
- Shared vaults and mixed personal-and-work usage weaken accountability, offboarding, and auditability even when a password manager is in place.
- Password security improves when the workflow, ownership model, and training are aligned with how people actually work.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | SP 800-63B — Authentication | The article is about password use quality and authentication behaviour in a human IAM programme. |
| Recommendation — Use SP 800-63B to align password practices with user-friendly authentication controls. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article highlights inconsistent access handling and shared-use practices around credentials. |
| Recommendation — Apply PR.AA-05 to tighten access scope and review who can use shared password resources. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Password storage, shared access, and ownership are access-control governance issues. |
| Recommendation — Implement A.5.15 to define and enforce access rules for password storage and sharing. | ||
Key terms
- Password governance evidence: Password governance evidence is the reporting and audit trail that shows password controls are actually enforced. It includes settings, exceptions, rejected attempts, and remediation status, giving security and audit teams a way to verify that policy exists in practice, not just in documentation.
- Shared Vault: A shared vault is a controlled container for information that multiple people need, such as travel details or recovery data. Its purpose is to replace ad hoc sharing with explicit access boundaries, so the right items are visible to the right people without exposing unrelated credentials or documents.
- Human Identity Hygiene: Human identity hygiene is the day-to-day discipline of keeping user credentials, accounts, and access patterns organised, current, and separable across business and personal use. In practice, it depends on user behaviour, support processes, and governance controls working together rather than on technology alone.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org