Email is not a good place to share passwords.
Messages may be forwarded, stored for years, copied into backups, or exposed if a mailbox is compromised.
If a password must be shared, businesses should use a secure password manager or another approved method designed for sensitive information.
Shared accounts should also be avoided whenever possible. Individual user accounts make it easier to know who performed an action and to remove access when someone leaves.
For systems that still require a shared credential, the password should be changed when team membership changes and stored in a controlled location.
The same principle applies to text messages and chat. Convenience should not create a permanent record of important credentials.
Passwords are keys to business systems. They should be handled like keys, not like ordinary conversation.
