Put each person's own AI logins in a business password manager, and share only business-owned accounts the vendor lets more than one person use, through a shared vault with named members and an activity log. For ChatGPT and Claude, don't share one login at all: both vendors' terms forbid it, so give each person their own seat.
The terms aren't the only reason. A shared login destroys the audit trail. When three people use one ChatGPT account, you can't tell who pasted the customer list, whose chat produced the wrong quote, or whose access to remove when someone leaves, and changing the password locks everyone out at once. A password manager solves where logins are kept and who can see them. It can't turn one person's account into a team account.
What OpenAI and Anthropic's terms say about shared logins
Both vendors are explicit, and I checked the current wording in September 2026. OpenAI's Terms of Use say you "may not share your account credentials or make your account available to anyone else and are responsible for all activities that occur under your account". Its help page on account sharing adds that an account is meant for the person who created it, and that anyone else should sign up for their own. The business-facing Services Agreement is just as clear: customers won't share account access credentials or individual login credentials between multiple users.
Anthropic's Consumer Terms, effective 8 October 2025, say: "You may not share your Account login information, Anthropic API key, or Account credentials with anyone else." And: "You also may not make your Account available to anyone else." The same section makes you responsible for all activity under your account.
That's the vendors' position, not legal advice, and other AI tools set their own rules, which vary. The practical point for a small business is simple: an account used against its terms is one the vendor is entitled to act on, and all the risk sits with you. Many single-user plans for other tools carry similar clauses, so check each tool's terms before treating its login as shareable.
What a password manager should hold, and what it shouldn't
Once the terms are clear, the job of the password manager becomes clearer too. Here is how each kind of AI-related credential should be handled:
| Credential | Where it goes | Who can see it |
|---|---|---|
| Each person's own seat (ChatGPT Business, Claude Team, their own tool accounts) | That person's private vault | Only them |
| Owner or workspace-admin logins (billing, adding users) | An admin vault, with the second factor on a separate device | Owner and one named deputy |
| Business-owned accounts the vendor allows several people to use | A shared vault or collection | Named people who need it, read-only where possible |
| API keys for automations | A restricted vault or collection | The person who builds and maintains the automations |
| Recovery codes for two-factor authentication | Admin vault, plus a printed copy in the safe for the owner's accounts | Owner and deputy |
| Personal accounts someone has been using for work | Nowhere: move the work into a company account | n/a |
The last row trips up many small businesses. A staff member's personal ChatGPT or Claude account full of customer drafts isn't something to store more safely; it's something to replace with a company account the business controls, which is covered step by step in setting up company AI accounts instead of personal logins.
Choosing a business password manager: two options at list price
Plenty of password managers have business plans; these two are the ones small businesses ask about most, with prices from their own pricing pages, billed annually, as of September 2026:
| Plan | List price | Relevant features |
|---|---|---|
| 1Password Teams Starter Pack | $24.95 a month for up to 10 members; up to 10 extra seats at $4.99 each | Shared vaults with permissions, guest accounts, sharing with expiry dates, usage reports |
| 1Password Business | $8.99 per user a month; 14-day free trial | As above, plus custom policies and access monitoring |
| Bitwarden Teams | $4 per user a month; free trial | Unlimited collections for sharing, event and audit logs, authenticator (TOTP) codes, passkey storage |
| Bitwarden Enterprise | $6 per user a month; free trial | Adds granular access control, single sign-on, enterprise policies |
For a five-person team, Bitwarden Teams costs $20 a month and 1Password's Starter Pack $24.95, so price rarely decides it. Choose the one your least technical colleague finds easiest in a ten-minute trial, because a password manager that staff avoid is worse than none. Check the current plan pages, 1Password's business pricing and Bitwarden's business pricing, before buying, since features move between tiers.
Setting up the vaults for a small team
Allow about two hours for a team of five, most of it spent collecting logins from people's browsers and notebooks.
- Secure the password manager itself first. A strong master password and two-factor authentication for every member, owner included. The steps for each AI tool's own two-factor setting are in turning on two-factor authentication for every AI account.
- Create the vaults before inviting anyone: Admin (owner and deputy), Shared tools (only accounts the vendor allows to be shared), Automation keys (the automation builder only). Each person also gets a private vault for their own seats.
- Invite staff and set permissions. 1Password lets you grant read-only or full editing access when sharing a vault; Bitwarden uses collections and user groups. Default to read-only; editing is for whoever changes the passwords.
- Move logins in, then delete the old copies. Browser-saved passwords, spreadsheets and sticky notes. A password manager that runs alongside a "passwords" spreadsheet has only added a second place to leak.
- Add the two-factor codes where appropriate. 1Password can act as an authenticator for saved logins, and Bitwarden's business plans include authenticator codes. For admin and billing accounts, keep the second factor on a separate device instead, so one breached vault doesn't hand over both factors.
- Switch on the activity or event log and look at it once, so you know where it is when you need it.
Then give staff five rules on day one, short enough to remember:
- Type AI tool passwords only into the password manager, never into a note, chat or spreadsheet.
- Never paste a password or API key into ChatGPT, Claude or any other assistant.
- Use your own seat. If you need access to a tool, ask for a seat rather than borrowing someone's login.
- Treat any email asking you to "confirm" your password manager login as phishing until the owner says otherwise.
- If you think a password was seen, say so straight away. Changing it takes two minutes; finding out later takes much longer.
A garden centre moves off one shared ChatGPT login
Consider an illustrative garden centre where five staff shared one ChatGPT Plus account at $20 a month. The password was on a card by the till computer, and the two-factor codes went to the owner's phone, so every new device meant a text to the owner. Two things forced a change. A seasonal worker who'd left in September was still using the login from home in November, which the owner only noticed when unfamiliar personal chats appeared in the history. And the history also showed that someone had pasted the trade customer list into a chat, with no way to tell who.
The owner looked at who actually used ChatGPT and how often. Three staff used it daily for product descriptions, supplier emails and the events programme. Two used it once or twice a month, and the business was already on Google Workspace Business Standard, which includes Gemini in their work accounts. The new setup:
| Item | Before | After |
|---|---|---|
| ChatGPT | 1 Plus login shared by 5: $20 a month | ChatGPT Business, 3 seats at $20 each billed annually: $60 a month |
| Occasional users | Same shared login | Gemini in their existing Workspace accounts: no extra cost |
| Password storage | Card by the till | Bitwarden Teams, 5 users at $4: $20 a month |
| Training on business content | On, unless someone had switched it off | Off by default on Business |
| Leaver's access | Continued until the password changed | Seat removed in minutes; nobody else affected |
| Monthly cost | $20 | $80 |
So the change cost $60 a month more, $720 a year. What it bought: each person's chats are their own and attributable, business data is excluded from training by default, a leaver can be removed without disrupting anyone, and every password lives in one place with a log. Setup took an afternoon. When one of the daily users left in the spring, removing her seat and her vault access took ten minutes, and nobody else had to learn a new password. Signs that a single shared plan has stopped fitting are covered in more depth in when a shared ChatGPT plan stops being enough.
The audit trail you lose with one login
An illustrative dry cleaner shows the cost in a single incident. Three counter staff shared one Claude Pro login. A complaint reply promising a full refund and free re-cleaning, beyond the shop's policy, went to a customer. The draft was in the shared Claude history, but so were drafts from all three staff that week, and nobody remembered writing that one. The owner couldn't coach the right person, couldn't tell whether the other replies that week needed checking, and noticed while looking that a customer's phone number had been pasted into a different chat.
Then the fix itself caused a problem: the owner changed the Claude password mid-afternoon on a Saturday, and all three staff were locked out during the busiest hours. With individual seats, the owner could have seen whose chat produced the reply, and removing or resetting one person's access would have touched nobody else. That is what "audit trail" means in practice: knowing who did what, and being able to act on one person without stopping everyone.
Three smaller cases, and how each was handled
A sole trader's own logins. An illustrative music teacher works alone, so there's nothing to share, but she had eleven AI and teaching-tool logins spread across two browsers and a notebook. She moved them into a password manager's personal vault and left sealed written instructions for getting into it with her partner, so the business's accounts, including Claude Pro and her booking system, can be reached if she's ill. For a one-person business the password manager's job is continuity rather than sharing.
An API key in a spreadsheet. An illustrative pet shop's automation connecting its web shop to OpenAI had its API key typed into a Google Sheet "so it's easy to find", in a folder three staff could open. The owner moved the key into a restricted vault the automation builder alone can see and deleted it from the sheet. Because the sheet's version history still held the old key, and three people could have seen it, she also generated a new key in OpenAI's platform and switched the automation over. API keys give direct, billable access, so they deserve tighter handling than most passwords.
The owner's admin account, with a named deputy. An illustrative optician's practice runs ChatGPT Business with the owner as the only workspace owner. When she was abroad for two weeks and a new locum needed a seat, nobody could add one. The practice now keeps the admin login in the Admin vault shared with the practice manager, with the owner's second factor on a hardware key kept in the practice safe for emergencies. Better still, the practice manager was given an admin role in the ChatGPT workspace itself, so there's no need to use the owner's login at all. Where a tool lets you add a second admin, do that instead of sharing the owner's login.
When a shared vault item is acceptable
Shared vault items have a place, with four conditions. The vendor allows the account to be used by more than one person, or it's a business-owned admin account that needs a named backup holder. Only named people can see it, never "everyone". The password manager's activity or event log is on. And the password is changed the day anyone with access leaves, with the change noted in the item.
If an item fails any of those, the answer is usually seats. ChatGPT Business costs $25 a seat billed monthly or $20 billed annually, with a two-seat minimum; Claude Team is priced the same way, also from two seats. For a sole trader who needs a second person occasionally, two seats at $40 to $50 a month can be more than the need justifies, in which case the second person gets their own individual plan instead. The trade-offs between plans are set out in ChatGPT Plus vs ChatGPT Business.
Offboarding in ten minutes once everyone has their own seat
- Remove their AI seats in each tool's admin area, and check who now owns any shared projects they created.
- Remove them from the password manager, which removes access to every shared vault at once.
- Change any shared item they could see, starting with the Shared tools vault. The activity log shows which items they opened recently.
- Revoke API keys they created and issue new ones to whoever maintains the automations.
- Check connected apps they authorised on business accounts, which keep working after a password change.
The full sequence, including accounts that were shared before you tidied up, is in the staff offboarding checklist for AI tools and shared accounts. With separate seats and a password manager in place, it's a routine ten-minute job instead of a Saturday-afternoon lockout.
Password managers and AI logins: follow-up questions
Can I share my ChatGPT Plus login with my business partner?
Not within OpenAI's terms, which say you may not share your account credentials or make your account available to anyone else. Two people who both use it daily are better served by ChatGPT Business at two seats, or by two individual plans. A password manager doesn't change that; it just stores the login more safely.
Should two-factor codes live in the password manager too?
For everyday staff accounts it's a reasonable convenience, and both 1Password and Bitwarden can generate the codes. For the owner and admin accounts that control billing and users, keep the second factor on a separate device, such as a phone passkey or a hardware key, so that one compromised vault can't open everything.
What does a password manager cost for a five-person team?
At September 2026 list prices billed annually, Bitwarden Teams is $4 a user a month, so $20 for five people, and 1Password's Teams Starter Pack is $24.95 a month for up to 10 members. 1Password Business is $8.99 a user a month. Both vendors publish their current prices, so check before buying.
Is a shared login ever acceptable for an AI tool?
Only where the vendor's terms allow it, or for a business-owned admin account that needs a named backup holder. Even then, keep it in a shared vault with named members, turn on the manager's activity or event log, and change the password whenever anyone with access leaves.
Further reads
- Is Claude Team Worth It for a Small Business? — Whether Claude Team seats earn their cost for a small business.
- How to Check Which Apps Can Access Your Business Accounts — Find the connected apps that outlive a password change.
- How to Train Staff to Spot AI-Written Phishing Emails — The phishing emails that target stored passwords.
- How to Write an AI Usage Policy for Your Small Business — Put the one-person-one-login rule in writing.
- Shadow AI: Is Your Team Using AI Without Telling You? — Find AI accounts staff opened without telling you.
- Microsoft 365 Business Premium vs Standard for AI Security — Identity controls that come with Microsoft's higher plan.
- Automation Audit: Find the Zaps and Scenarios Nobody Owns — An inventory template, platform-by-platform checks and a triage table for finding orphaned Zaps and Make scenarios before one quietly breaks.
- How to Set Up Single Sign-On for Your Team's AI Tools — The five stages of SSO for ChatGPT Business and Claude Team, what SSO still leaves manual, and how to avoid locking your own team out.
- Who Owns AI Chat History When an Employee Leaves? — What happens to a leaver's AI chats on ChatGPT Business, Claude Team, Copilot and Gemini, who can read or export them, and a handover plan that works.
- How to Spot Deepfake Voice and Video Scams Aimed at Your Business — Spot deepfake voice and video scams by the request, not the voice: warning signs, a copyable verification protocol and a drill to test it on staff.
- What Is an AI Browser Agent, and Should Staff Use One? — What an AI browser agent does, which jobs it suits, how prompt injection can hijack it, and the settings and staff rules that keep mistakes small.
- How to Choose a Virtual Assistant Agency: Questions and Prices — Compare virtual assistant agencies on published prices, the cost per hour you'll really use, contract terms, account access and how their assistants use AI.
- What an AI Consultant Needs From You: Access, Data, and Time — The access, sample data, staff time and decisions an AI consultant needs from you, grouped as a checklist with why each matters and how to check it's ready.
- Who Owns the AI Workflows a Consultant Builds for You? — Legal ownership and practical control of AI automations: assignment vs licence, whose accounts they run in, platform transfer rules and sample clauses.
- AI Tools and AI Development: The Complete 2026 Guide — the AI hub, including every tutorial in the AI-for-business series.
Sources: OpenAI Terms of Use and OpenAI Account Sharing Policy (help pages), OpenAI Services Agreement, Anthropic Consumer Terms (effective 8 October 2025), 1Password business pricing and support pages on one-time passwords and shared vaults, Bitwarden business pricing, checked September 2026.