Consider what the common approaches actually do. A password sent by text sits in two phones indefinitely, including in cloud backups of both. Sent by email, it sits in two mailboxes and every backup of them, searchable forever, and email is the account most likely to be compromised. Written in a shared document, it is visible to everybody with access to that document, including people added later. In each case the credential outlives the reason for sharing it.

A shared vault fixes this structurally rather than by discipline. You grant access to specific items rather than to everything, the person never needs to see or type the password, and revoking access is a single action that takes effect immediately. When somebody leaves, you remove them from the vault rather than trying to remember which of nine services they were given and changing each one.

Two habits go with it. Grant access to the minimum required, because the instinct to add somebody to the whole vault is what makes offboarding risky later. And for anything genuinely critical, such as banking or your domain registrar, consider whether sharing is necessary at all rather than performing the task yourself.

If you have already shared credentials by text or email, the fix is to change those passwords rather than to delete the messages. The message is the copy you know about. Assume there are others.

Review who has access to what on a schedule rather than only when somebody leaves. Access accumulates: somebody needed a tool for one project two years ago and still has it. A quarterly look at each shared item, asking whether everybody listed still needs it, takes ten minutes and closes the gap that offboarding checklists miss, which is people who are still with you but no longer doing the work that required the access.

For anything genuinely critical, consider whether sharing is the right answer at all rather than how to share it safely. Banking, the domain registrar, and the account holding your customer data are places where performing the task yourself, or granting somebody their own limited account rather than your credentials, is frequently the correct answer. Many services now support additional users with restricted permissions, which removes the sharing question entirely.