How to Leave Passwords and Account Instructions for Your Family

Prepare an account list your chosen helper can find, and make a separate, secure arrangement for passwords and recovery information. Keep passwords, recovery codes and keys out of ordinary worksheets. Set up any supported legacy-contact or emergency-access features, then check that your helper understands the instructions and what those features allow.

An older man and a woman look at a document together beside a laptop.

Start with an account map, not a loose password list

A family member first needs to know which accounts matter and what you want done with them. List the main email address, phone subscription, photo storage, essential household services and any important digital records. Add the service's purpose and the person who should coordinate the next step.

Keep this account map separate from the actual passwords and recovery material. The map can say where a secure plan is held without exposing it. Do not put all your access secrets into a document that is routinely emailed, printed for several relatives or stored in a broadly shared folder.

Be specific about your wishes: preserve selected family photos, keep business files separate, close an unused profile or leave a private conversation private. A general instruction to give someone everything can be difficult to apply and may disclose information about other people.

Choose someone who understands the responsibility

Ask the person before naming them in your instructions. They need enough confidence to follow the plan and enough judgment to respect privacy. They do not need to become an expert in every service. Identify a second person or appropriate professional they can ask if a task is unfamiliar.

Explain whether the role is preserving memories, helping the estate representative identify accounts, or using a provider's designated contact feature. Those roles are not identical. A password manager's technical access setting does not appoint an estate representative or authorize every action in a bank account.

Tell the helper where the non-secret account map is stored and when it was last reviewed. If you name a different person in a provider setting, make that distinction clear. Otherwise relatives can assume that one appointment controls all services.

Check the recovery method your password manager actually supports

If you use a password manager, read its official family, recovery or emergency-access guidance while you can still change your own settings. Available features depend on the service, account and plan. Verify the complete process, including what the chosen person must accept and what they can access.

For example, Bitwarden documents a configured emergency-access process with a trusted contact and a waiting period. 1Password provides family recovery guidance and an Emergency Kit. These are different mechanisms; do not assume that buying a family plan automatically gives relatives access to everyone's private vault.

Treat a printed emergency kit or recovery secret as sensitive. Choose storage that protects it from casual access while remaining reachable by the intended person through the appropriate arrangements. The useful question is not only whether it is safe, but whether the helper can find the correct current version when needed.

Plan for passkeys and other sign-in requirements

Knowing a password may not be enough to sign in. An account can also depend on a phone, an authenticator app, a security key or a passkey stored in a device or password manager. Identify these dependencies in your own planning without disabling security simply to make the handover look easier.

Record the recovery method and the location of securely stored recovery material, not the codes themselves in an ordinary workbook. A passkey is not a password that someone can copy from a printed list. Check the service's supported sharing or recovery arrangements for the exact account.

Avoid a circular plan where the only recovery instructions are inside the account they are meant to recover. Consider how the intended person can find the first non-secret instructions without already having your phone or email access. Keep the detailed secrets protected through a separate arrangement.

Configure provider contacts and explain their limits

Use the relevant settings in your own accounts rather than relying only on a written wish. Apple Legacy Contact and Google Inactive Account Manager support different kinds of planning. Check the people selected, what they may receive and which event triggers the process.

Apple's Legacy Contact access does not include passwords or passkeys stored in iCloud Keychain. Google's inactivity plan is based on account inactivity, not a legal finding of death. Neither should be described as a universal key to every device or connected service.

Keep a note of the configured feature, account, contact and review date. If a provider requires an access key, verify that the intended person has received it and knows where it is securely stored. Do not paste the key into the general account inventory.

Test understanding without triggering an emergency

Sit down with the helper and walk through a fictional first step. Can they find the account map, identify the right provider and explain whom to contact? Can they distinguish a photo-preservation wish from an instruction to close an account? Fix unclear wording while you can discuss it.

Do not submit a death-related request, trigger emergency takeover or share every credential just to test the plan. Check saved settings and follow any safe verification steps documented by the provider. The purpose is to test that the handover is understandable, not to cause account changes.

A useful instruction might say: the family photo library is in this service; the nominated contact knows the secure key location; coordinate with the estate representative before closure; keep work documents separate. That gives a clear sequence without making the worksheet a password vault.

  1. Confirm the helper is willing and their contact details are correct.
  2. Check that invitations and required confirmations are complete.
  3. Locate the current instructions and separate secure recovery material.
  4. Explain what should be preserved, kept private or closed.
  5. Record a review date and the changes still needed.

Review the plan when accounts or relationships change

Update the plan after changing your main email address, phone number, password manager, important device or nominated helper. Review account recovery settings as well as the written map. An accurate list from last year can become misleading after one important change.

Remove obsolete instructions from the current handover and tell the affected people when their role changes. Keep historical notes only where they serve a clear purpose and cannot be mistaken for current access instructions. Check that the secure location remains accessible under the arrangements you intend.

If you are planning for incapacity as well as death, seek advice on the appropriate legal authority. Provider inactivity, account recovery and an estate appointment are different processes. This article helps organize practical information; it does not establish that authority.

Use the workbook for the account map and wishes

The Fort Legacy PDF's inventory and handover worksheets can record which accounts matter, who coordinates the work and where separate instructions are held. You can prepare those entries now and use the wider guide to explain the after-loss tasks your family may face.

Keep actual passwords, PINs, recovery codes and access keys outside the PDF. Buying or completing the guide does not configure a password manager, appoint a representative or activate a provider's legacy feature. The value is a clear, portable record that supports the arrangements you set up.

Official sources