The password spreadsheet that will not die.

The scenario:

Somewhere in your client base there is a spreadsheet called passwords.xlsx. It has been “temporary” for four years. Half your team knows which client it is. 

The fix is not a lecture about password managers. The fix is a migration path so small and boring the client cannot object to it. 

Frame it as risk transfer, because it is. While credentials sit in a shared file, every leaver, every stolen laptop, and every phish puts the whole client at stake, and the client believes you have it handled. One compromised spreadsheet has turned into a full incident response bill more times than anyone admits. The migration is an afternoon of work spread over a fortnight. 

The prompt:

You are building a credential hygiene migration plan for an MSP client still using shared spreadsheets for passwords. 

Context: [client size, the systems in the spreadsheet, the password manager you offer] 

Build: 

  • A 30-minute audit checklist to find every credential store the client uses, not only the one you know about 


  • A migration order: which credentials move first and why, admin accounts at the top 


  • The client-facing one-pager explaining what changes for their staff, in plain language 


  • A closure step: the date the spreadsheet is deleted, confirmed in writing 


Make the whole plan fit inside two weeks of normal workload.