
What's in this verdict
- What a business password manager actually costs
- Per user per month is the model, and what sits under it
- Illustrative per user pricing by tier
- What actually unlocks at each rung
- The SSO tax is a real budgeting problem
- Single sign on does not replace a password manager
- Directory provisioning and what it saves
- Secrets management for engineers is a separate meter
- The free personal plan bundled with employee seats
- Free and personal tiers, and where their ceiling sits for a business
- Minimum seat counts and the small team penalty
- Annual prepay against monthly billing
- Contractors, guests and shared vaults
- Shared vault design is a cost decision
- Who actually needs a licensed seat
- Onboarding and migration: the cost with no invoice
- Ongoing administration, recovery and the help desk line
- Audit logs, reporting and what compliance work actually needs
- Self hosted against vendor hosted
- A worked three year total at three business sizes
- What one credential incident costs, framed honestly
- Signs your password manager bill has drifted
- How to trial a password manager properly
- What to ask a vendor before you sign
- The bottom line
A password manager is one of the cheapest lines on a software budget and one of the most reliably underestimated. The sticker is a few dollars a head, the pricing page fits on one screen, and the whole thing looks like a decision somebody can make on a Tuesday afternoon. Then the quotes come back, single sign on turns out to sit a rung higher than expected, the contractors need somewhere to keep a shared login, the engineers want somewhere to keep API keys, and a purchase that looked like $4 a head is being modelled at three times that.
This verdict prices a business password manager the way it actually bills. It works through the per user model and what genuinely sits under it, maps the team, business and enterprise rungs and the specific features that gate each jump, treats the single sign on premium as the budgeting problem it is, prices contractors and shared vaults, puts an honest number on the rollout hours nobody invoices, and carries three worked totals across three years. It sits next to our verdict on the true cost of business software, which takes per seat billing apart in general, and our verdict on e-signature software cost, which shows the same rung pattern in a category that meters on something other than seats. Put your own headcount through the true-cost calculator and the companion on this page before you shortlist anything.
Key takeaways
- Illustrative per user bands: team or starter around $4 a month, business around $8, enterprise around $12, plus a developer secrets add-on around $9 per engineer. Personal plans bought individually run around $3.
- Single sign on and directory provisioning commonly gate the jump from the team rung to the business rung, which doubles the seat rate. On seventy seats with annual billing that premium is about $2,789 a year.
- Rollout is the line with no invoice. On the illustrative model here it is about $3,459 for a seventy seat deployment, roughly thirteen percent of the three year total.
- Contractors, guests and shared vaults are priced very differently between products, and minimum seat counts put a floor under a small team's bill that has nothing to do with headcount.
- Three year totals: about $3,973 for fourteen people, about $26,627 for seventy, about $121,739 for two hundred and forty five. Cost per person rises with size here, unlike most per seat software.
What a business password manager actually costs
Ask what a business password manager costs and a complete answer has five parts, only one of which appears on a pricing page.
There is the per user subscription, which is the number every comparison table shows and the number every internal approval is based on. There is the rung premium, which is what you pay because one control you need, usually single sign on or directory provisioning, sits above the rung the rest of your requirements would have justified. There is the add-on meter, most often a secrets management product priced per engineer. There is the one time rollout, which is configuration, policy design, communication and the per person time of actually getting everybody in. And there is the standing administration line, which is recovery, offboarding, vault housekeeping and the tickets that arrive when somebody changes phone.
Those five scale on four different things. Seats scale with headcount including external people. The rung premium scales with your compliance and identity requirements rather than your size. The add-on scales with how many engineers you employ. Rollout and administration scale with headcount and with how messy your credentials were before you started.
Everything below takes these apart with illustrative planning figures, and the companion on this page reprices the whole stack against your own numbers as you read.
Per user per month is the model, and what sits under it
Almost every product in this category is sold per user per month, billed monthly or annually, with a rung ladder and a small number of add-ons. That much is simple, and it is why the category is often waved through without modelling.
What sits under the seat varies more than the price does. A seat generally includes an unlimited personal vault for that user, apps and browser extensions across their devices, membership of any shared vaults an administrator grants, second factor options, and secure sharing with people inside the organisation. Storage limits, where they exist, apply to file attachments rather than to credential records, and they are rarely the binding constraint.
What is not automatically included is the administrative machinery: policy enforcement, provisioning, recovery, reporting and audit export. That machinery is the actual product a business is buying, and it is distributed across the rungs in ways that differ by vendor.
The practical consequence is that two products at the same seat price can be very different purchases. Compare on the administration surface, not on the vault, because every vault in the category does roughly the same job.
Illustrative per user pricing by tier
Start with the numbers people search for, framed as planning bands rather than quotes, because pricing here moves and varies by vendor, region, contract length, seat count and how much of the identity machinery is switched on.
Free personal tiers cost nothing and are built for one individual, with device or item limits in some products and no administrative concept at all.
Individually bought personal plans commonly land around $3 per month and remove the personal limits. They are a consumer product and remain one no matter how many employees buy them.
Team or starter rungs commonly land around $4 per user per month. This is where shared vaults, an administrator role, basic policy and simple reporting appear.
Business rungs commonly land around $8 per user per month and are where single sign on, directory integration, granular vault permissions, stronger policy control and usable reporting typically live.
Enterprise rungs commonly land around $12 per user per month and add advanced provisioning, custom roles, audit log export and streaming, residency choices and contractual commitments.
Developer secrets add-ons commonly land around $9 per engineer per month and are a separate product bolted to the same account.
Illustrative password manager list price per user per month
Plan rungs and one commonly separated add-on, before minimum seat counts, contractor seats, rollout or administration time. Bar widths are drawn from each figure against the enterprise band.
The gap from team to business is about $4 a user and buys identity integration rather than anything about vaults. The gap from business to enterprise is another $4 and buys reporting, provisioning depth and contractual commitments. Neither gap makes a stored password any safer on its own.
Read that ladder against your own requirements rather than against a competitor’s stack. A business with no identity provider and a handful of shared logins is shopping the team rung. A business with a directory and a joiners and leavers process is shopping business at minimum. A business with an auditor asking for access reviews is shopping enterprise whether it wanted to or not.
What actually unlocks at each rung
Feature placement varies by product and moves between releases, so treat this as a shape to verify rather than a specification. The pattern is consistent enough to plan against.
The team rung buys shared vaults, an administrator who can create and assign them, invitation based joining, a basic policy set covering things like minimum master password strength and second factor requirements, and reporting that tells you who has logged in. For a business under about twenty people with no directory, this is frequently the correct and final answer.
The business rung buys identity: single sign on against your provider, directory based user creation, granular permissions on individual vaults, policy that can be enforced rather than requested, and reporting that can answer a question rather than only display a list. It also usually buys the bundled personal plan for employees.
The enterprise rung buys administration at scale: automated provisioning and deprovisioning, custom administrator roles so one person is not omnipotent, audit log export or streaming into your own tooling, data residency choices where offered, and the contractual and support commitments that a procurement process asks for.
The gate that catches most buyers is single sign on. It is the control most likely to be non negotiable and the one most likely to sit a rung above where the rest of your requirements landed. Establish where it sits in each product before you build any comparison table, because it will move your budget more than any other single answer.
The SSO tax is a real budgeting problem
The nickname is unkind and the pattern is real: single sign on and directory integration are commonly gated behind a higher priced rung rather than treated as a baseline security control, and the jump is rarely small.
On the illustrative bands here, moving from the $4 team rung to the $8 business rung to obtain single sign on doubles the per seat rate. Across seventy seats on annual billing that is about $2,789 a year, and about $8,366 across three years. Moving all the way to the $12 enterprise rung to obtain audit log export as well takes the same seventy seats to about $5,578 a year above the team rate.
Two arguments run against each other here and both have weight. Vendors point out that supporting enterprise identity protocols is genuine engineering, that it drags in certification, penetration testing and a support burden, and that the customers who require it are the ones with budget. Buyers point out that a control which materially reduces credential risk is a strange thing to price as a premium, because the effect at the margin is that smaller organisations run without it.
You will not resolve that argument during a procurement cycle. What you can do is price it explicitly, name it in the business case as its own line rather than burying it in a rate, and use it in negotiation. Our manual on negotiating SaaS pricing covers the timing and leverage that make that ask land, and a rung premium driven by one feature is a more persuasive thing to argue about than a general discount request.
Single sign on does not replace a password manager
This confusion appears in almost every evaluation and it costs money in both directions, so it is worth stating plainly.
Single sign on covers applications that speak an enterprise identity protocol. Everything else keeps its own credential. A real business runs a long tail of those: supplier and wholesaler portals, the router and firewall in the office, the wifi key, the domain registrar, the hosting account, an old finance system, a shared social account, a courier account, the smart lock, and the handful of tools one department bought without telling anyone.
Those credentials exist whether or not there is somewhere sanctioned to keep them. If there is nowhere, they live in a spreadsheet, a shared notes document, a pinned message or somebody’s memory, and every one of those is worse than the thing you declined to buy.
The correct read is that the two tools do different jobs and shrink different problems. Single sign on reduces the number of passwords in circulation and centralises the ones it covers. A password manager holds what remains and makes sharing it survivable. Most organisations that buy one end up buying the other, which is precisely why the pricing interaction between them matters.
Directory provisioning and what it saves
Directory provisioning, often described as automated user lifecycle management, creates an account when somebody joins your directory and removes it when they leave. It is usually the second identity feature after single sign on and it is sometimes a rung higher.
The security case is the strong one. Manual deprovisioning fails quietly and predictably: somebody leaves on a Friday, the checklist is followed on Monday, and one system is missed. In a password manager that miss is not a dormant account, it is a person who still holds the contents of every shared vault they were in. Automated removal turns that from a process risk into a directory event.
The cost case is smaller but real. If offboarding takes an illustrative thirty minutes of administrator time per leaver at $85 an hour, a business with twenty leavers a year is spending about $850 a year on the manual version, plus whatever the misses eventually cost. That does not usually pay for a rung jump on its own, and it should not be presented as though it does.
Price provisioning honestly: mostly a control, partly a saving. Then check one detail that catches people out, which is whether removing a user actually removes their access to shared vault contents or merely disables their login, and what happens to items stored in their personal vault when the account is deleted.
Secrets management for engineers is a separate meter
If you employ engineers, there is a second product in this category and it is usually priced separately.
A password manager stores credentials that humans type. A secrets manager stores credentials that software uses: API keys, database connection strings, signing keys, service account tokens, certificates. The difference that matters commercially is that secrets are fetched by machines at runtime, need to be rotated on a schedule, need injection into build pipelines and containers, and need an access log that records a service rather than a person.
Vendors handle this in three ways. Some sell a developer or secrets add-on at an illustrative $9 per engineer per month on top of the base seat. Some include a limited version at the enterprise rung. Some do not compete here at all, which means your engineers will be using something else and you should price that separately rather than assume it is covered.
Scope it by engineers rather than headcount. In the worked example below, eight engineers on a $9 add-on is $864 a year at monthly billing, which is modest, but the same add-on across thirty engineers is $3,240 and starts to matter. Our verdict on remote monitoring and management software covers the adjacent question of tooling that holds privileged access to your estate, which is a related exposure worth thinking about at the same time.
The free personal plan bundled with employee seats
Many business rungs bundle a free personal or family account for each licensed employee, and it is worth understanding as both a benefit and a piece of commercial design.
The benefit is real. Credential reuse mostly starts at home, and an employee who has nowhere good to keep personal logins will reuse a pattern that eventually touches something of yours. Giving them a proper personal vault at no extra charge is one of the few security controls that costs nothing and that people actually adopt, because it is useful to them rather than imposed on them.
Value it at an illustrative $3 a month standalone and sixty bundled accounts is about $2,160 a year of benefit that appears on no invoice. That is a legitimate figure to put in a business case, clearly labelled as an estimate of value rather than a cash saving.
The commercial design is equally real: an employee who keeps their personal life in a vendor’s product is a customer for life and an advocate at their next employer. That does not make the benefit less genuine. It does mean you should not treat the bundled account as a reason to choose one product over another, because most of the category does it and none of it is administered by you.
Free and personal tiers, and where their ceiling sits for a business
Free tiers in this category are real products and are built for one person. Understanding exactly where they stop saves an argument later.
A free personal tier typically gives one user a vault, apps across devices in most products, and password generation. Some limit device count or item count. All of them share one property that decides the question: there is no administrator. Nobody can create a shared vault on your terms, enforce a policy, see who has access to what, remove access when somebody leaves, or produce a record of any of it.
That ceiling is fine for a sole trader with no staff and no shared logins. It is fine, arguably, for two founders who share three credentials and trust each other completely. Beyond that it stops being a plan.
The failure mode is not a bill, it is an exit. When somebody leaves a business running on personal free accounts, there is no lever to pull. The credentials they held are in their own vault, on their own devices, under their own control, and the only remedy is to change every one of them by hand. Our verdict on CRM free tiers against paid plans works through the same free against paid decision in a category where the ceiling is a feature limit rather than a control gap.
Minimum seat counts and the small team penalty
Minimum billable seats set a floor under your bill that has nothing to do with how many people you employ, and they are easy to miss because they are usually written next to the rung rather than in the price.
Illustrative minimums run around five billable seats on team rungs, around ten on business rungs, and considerably more on enterprise agreements, which are frequently negotiated rather than listed. The mechanism is straightforward: you pay for the minimum or your headcount, whichever is larger.
Work a small case. Three people on a $4 team rung with a five seat minimum pay $240 a year rather than $144. That is an effective $6.67 per actual user per month against a $4 sticker, and $96 a year of pure structure. It is not a large sum, and it is a two thirds increase on the number the approval was based on.
The minimum matters most at the moment you choose a rung. A twelve person business moving to a business rung with a ten seat minimum is unaffected. An eight person business moving to the same rung is unaffected too. A five person business is paying for ten seats, which means the effective rate is $16 rather than $8, and at that point the honest comparison is against the rung you were leaving rather than against the sticker you were promised.
Annual prepay against monthly billing
Annual commitment discounts here behave like the rest of business software and the arithmetic is the usual one.
The common shape is roughly ten to twenty percent against monthly billing, often presented as two months free on a twelve month term, which is about seventeen percent. This verdict models seventeen percent throughout. On the seventy seat example that is about $1,289 a year, which is a meaningful fraction of a bill that size.
Take the discount when you are confident about the next twelve months and the seat count is stable or growing. Decline it while you are still validating the product, because a prepaid year of a tool nobody adopted is worse than a monthly bill you can stop.
Two details are worth asking about explicitly. First, what happens when you add seats mid term: most vendors prorate additions to your renewal date, which is fine, but a few require a new term for the added seats. Second, what happens when you remove seats mid term, which in almost every case is nothing at all until renewal. A prepaid annual contract fixes your floor, not your ceiling, and a business expecting to shrink should model that before committing.
Contractors, guests and shared vaults
Every business of any size eventually needs to share a credential with somebody it does not employ, and the three ways vendors handle that produce very different bills.
Full seat billing treats an external collaborator as a user like any other. It is simple, it is the most common shape, and it is the most expensive. Ten contractors on an $8 business rung with annual billing is about $797 a year.
A guest or limited role gives an external person access to specific shared vaults at a reduced rate, or with a small free allowance, and typically without a personal vault of their own. Where it exists it is usually the right tool and the pricing is worth confirming in writing, because a guest allowance that is free up to a cap and full price above it is a different budget from a flat guest rate.
No external concept at all means the only way to share is to issue a licensed account, which is full seat billing with extra steps and a worse offboarding story.
The structural question underneath the pricing is expiry. An external account that nobody time limits is a standing grant of access to whatever vault it was added to, and it will outlive the engagement by default. Ask whether access can be given an end date at the point of granting, because a control that requires somebody to remember is not a control.
Shared vault design is a cost decision
How you structure shared vaults looks like an administration question and behaves like a pricing one, because vault design determines how many people need a licensed seat.
The two failure patterns are opposite and equally common. One vault for everything means everybody needs access to the vault that holds the payroll login, which means either everybody sees it or nobody uses the vault. A vault per credential means dozens of vaults, each with its own membership list, and an administration burden that grows faster than the business does.
The workable middle is a vault per function with membership drawn from the team that performs it: finance, marketing, operations, engineering, and one restricted vault for the small number of genuinely sensitive credentials. Membership then follows the org chart, which is a thing that already exists and already changes when people move.
Design this before you migrate anything, because moving items between vaults later is manual work and because the design decides who needs a seat. A business that discovers halfway through a rollout that twelve people need access to one vault has usually discovered a vault design problem rather than a licensing requirement. Our verdict on document management software cost covers the same permission modelling question for files, where the mistakes look nearly identical.
Who actually needs a licensed seat
Seat count is the easiest line to overbuy in this category, because a password manager feels like something everybody needs and the honest answer is that almost everybody does.
That makes this category different from most per seat software. In a CRM or an e-signature product the seat holders are a subset of the business, often a small one. Here, anybody who logs into anything on behalf of the company benefits from a vault, which means the seat count really is close to headcount, and a business trying to trim it is usually trimming the wrong line.
Two genuine exceptions exist. People with no company logins at all, which in some operational businesses is a real population, do not need a seat and should not be given one out of tidiness. And service or shared accounts should not hold a seat of their own if the product allows a credential to be owned by a vault rather than by a user.
Everything else is a design question rather than a licensing one. If it looks like you can save money by giving fewer people seats, check whether what you are actually doing is pushing those people back into a spreadsheet. Our verdict on the true cost of business software covers the general pattern of seat trimming that quietly relocates the work.
Onboarding and migration: the cost with no invoice
This is the line most buyers leave out entirely, it lands in year one, and on the worked example below it is roughly thirteen percent of a three year total.
It has two parts. Configuration and policy work is the administrator’s side: connecting identity, designing the vault structure, writing the policy set, building the communications, running a pilot group and fixing whatever the pilot surfaces. The illustrative model here prices it at six hours plus an hour for every eight people, at $85 an hour, which is about $1,254 for a seventy seat deployment.
Per person onboarding is everybody else’s side: installing the extension and the app, enrolling a second factor, importing whatever is already saved in a browser, and being shown the shared vaults they belong to. The illustrative model prices it at forty five minutes each at a loaded $42 an hour, which is $31.50 a head and $2,205 across seventy people.
Together that is about $3,459 one time, more than half of a full year of licences. The single thing that reliably shrinks it is doing the credential inventory before the rollout rather than during it, because a migration that discovers the credentials as it goes takes several times longer than one that starts from a list. Our manual on migrating to new software covers the sequencing that keeps that work contained.
Ongoing administration, recovery and the help desk line
After the rollout there is a standing cost, and it is larger than most buyers expect relative to a licence this cheap.
The recurring work is recovery and lifecycle. Somebody changes phone and loses their second factor. Somebody forgets a master password. A leaver has to be removed and the credentials they held have to be rotated. A new hire has to be added to the right vaults. A vault has to be reorganised when a team splits. None of it is difficult and all of it takes time from somebody competent.
The illustrative model here prices administration at half an hour of administrator time a month for every twenty five people at $85 an hour, which is about $20 per person a year. On seventy people that is $1,428 a year, or roughly sixteen percent of a three year total, and it is a fifth of what the licences cost.
Two design choices move that number materially. Whether recovery is self service through a recovery key or a trusted contact, or whether it requires an administrator every time. And whether joiners and leavers flow from your directory or are handled by hand. Both are rung dependent, which is a quieter reason the higher rungs sometimes pay for themselves. Our verdict on help desk software cost is worth reading alongside this if these tickets currently arrive somewhere unmeasured.
Audit logs, reporting and what compliance work actually needs
Reporting is where the enterprise rung earns its premium for some buyers and buys nothing at all for others, so it is worth being precise about what is on offer.
The useful capabilities are a small set. An event log that records logins, item access, vault membership changes, policy changes and administrative actions, with enough retention to cover a review period. A view of credential health across the organisation, meaning reused, weak and old credentials, without exposing the credentials themselves. Reporting on second factor coverage. Export or streaming of the event log into your own logging tooling, which is what turns it from a screen into evidence.
The gating pattern is consistent: basic activity views appear at the team and business rungs, and export, streaming and longer retention sit at enterprise. If a customer questionnaire or an auditor has asked you for access reviews and evidence, that is a requirement rather than a preference and it will decide your rung.
What this verdict cannot tell you is what any framework, contract or regulator requires of your organisation. Requirements differ by sector, jurisdiction, customer contract and certification scheme, and they change. Establish the requirement first with someone qualified to interpret it, write it down as a capability list, and only then look at pricing pages, because buying a rung to satisfy a requirement you have not written down is how budgets get spent on reassurance.
Self hosted against vendor hosted
A minority of products in this category can be run on your own infrastructure, and the trade is not the one people expect.
The stated attraction is control: the encrypted data sits on hardware you own, on a network you control, and no third party holds it. For some organisations that is a genuine contractual or policy requirement rather than a preference, and where it is, the question is closed.
The cost picture is less flattering. Self hosting replaces a per seat subscription with a smaller licence or none at all, plus servers, plus backups you have tested, plus patching, plus monitoring, plus somebody who is on the hook when authentication fails on a Sunday. For a small business that trade is almost never favourable, because the sysadmin hours cost more than the seats and the availability is worse.
The honest test is whether you already run infrastructure to a standard you would trust with this. If you have monitoring, tested restores and an on call rotation, self hosting is a real option and the licence saving is genuine. If you do not, self hosting a credential store is taking on the single least forgiving availability problem in your estate to save a few dollars a head.
A worked three year total at three business sizes
Three illustrative scenarios, using the bands above throughout: seats as listed, a developer secrets add-on at $9 per engineer per month, annual prepay at seventeen percent below monthly where taken, configuration at six hours plus an hour per eight people at $85 an hour, per person onboarding at forty five minutes each at $42 an hour, and administration at half an hour a month per twenty five people at $85 an hour.
A twelve person business, team rung, billed monthly. Twelve employees plus two contractors is fourteen seats at $4, which is $672 a year with no annual discount taken. No engineers, so no secrets add-on. Administration on fourteen people is $285.60 a year, making the running cost $957.60. Configuration at 7.75 hours is $658.75 and onboarding fourteen people at $31.50 is $441, so the one time rollout is $1,099.75. Year one is $2,057.35 and each further year is $957.60. Three year total: about $3,973, which is about $7.88 per user per month and about $80 per employee a year.
A sixty person company, business rung, eight engineers, annual prepay. Sixty employees plus ten contractors is seventy seats at $8, which is $6,720 a year at monthly rates and $5,577.60 on annual prepay. Eight engineers on the $9 secrets add-on is $864 a year, or $717.12 prepaid, bringing licences to $6,294.72. Administration on seventy people is $1,428, so the running cost is $7,722.72 a year. Configuration at 14.75 hours is $1,253.75 and onboarding seventy people is $2,205, so the rollout is $3,458.75. Year one is $11,181.47. Three year total: about $26,627, which is about $10.57 per user per month and about $129 per employee a year.
A two hundred and twenty person company, enterprise rung, thirty engineers, annual prepay. Two hundred and twenty employees plus twenty five contractors is two hundred and forty five seats at $12, which is $35,280 a year at monthly rates and $29,282.40 prepaid. Thirty engineers on the secrets add-on is $3,240, or $2,689.20 prepaid, bringing licences to $31,971.60. Administration on two hundred and forty five people is $4,998, so the running cost is $36,969.60. Configuration at 36.625 hours is $3,113.13 and onboarding is $7,717.50, so the rollout is $10,830.63. Year one is $47,800.23. Three year total: about $121,739, which is about $13.80 per user per month and about $168 per employee a year.
Where three years goes for the seventy seat example
Shares computed from the worked example against a $26,627 three year total, with business seats at $8, a secrets add-on at $9 per engineer, seventeen percent annual prepay, administration at $20 per person a year and a $3,459 one time rollout. Shares rounded to whole numbers.
Licences of every kind are about seventy one percent of the total and internal time is the rest. That ratio is what makes this category behave unlike its price tag: at $8 a head the software is cheap enough that the hours around it become the argument.
Notice which way the unit cost moves. Per user per month across three years, the fourteen seat business pays about $7.88, the seventy seat company about $10.57 and the two hundred and forty five seat company about $13.80. That is the opposite of most per seat software, where scale earns a discount, and it happens because the controls a larger organisation must have sit on higher rungs. Load your own numbers into the companion on this page to see where your version lands.
What one credential incident costs, framed honestly
Every business case for this category eventually reaches for a comparison with the cost of a breach, and most of them reach for a statistic. This verdict will not, because the honest position is that published averages are drawn from populations that look nothing like a sixty person company, and quoting one as though it applies to you is a decoration rather than an argument.
What can be said without inventing anything is the shape of the response. A credential compromise consumes people first: someone establishes what was accessed, someone rotates every credential that account could reach, someone reviews logs across several systems, someone decides what has to be told to whom, and everybody else stops doing their normal work while it happens. Any external help, legal input or notification obligation arrives on top of that.
A useful internal comparison avoids the fake precision entirely. The seventy seat programme above costs about $26,627 across three years, which at an illustrative $85 an hour is roughly 313 hours of skilled internal time. Ask your own team how many hours a serious credential incident would absorb before anything external was counted. That is a question people can answer from experience, and it lands better in an approval meeting than a borrowed number.
Then be honest about the limit of the argument. A password manager reduces credential reuse, makes sharing survivable and makes removal possible. It does not prevent phishing, it does not fix an unpatched system, and it is one control among several. Sell it as what it is.
Signs your password manager bill has drifted
Because seats track headcount and headcount moves without a purchasing decision, drift here is normal rather than exceptional. Five signatures recur.
Seats exceed people. Pull the user list and compare it with your directory. Leavers who were never removed are both a bill and an access problem, and on an $8 rung ten of them is $960 a year.
Contractor accounts have outlived their engagements. External access almost never gets removed on time unless it was given an end date at the point of granting. Review it quarterly and expire by default.
You are on a rung for one feature nobody uses. If you moved up for audit export and nobody has exported an audit log in a year, that is a renegotiation, not a renewal.
Administration is being done by somebody expensive. Recovery and vault housekeeping done by an engineer costs several times what the licence does. Either delegate it or buy the rung that makes it self service.
Nobody has looked at the credential health report. The reporting you are paying for is the only part of the product that tells you whether any of this worked. Our manual on cancelling a SaaS subscription covers doing the exit cleanly if the answer is that it did not.
How to trial a password manager properly
Every product in this category demos beautifully, because saving and autofilling a password is a demo that cannot fail. Structure your trial around what happens afterwards.
Import your actual mess. Not a clean sample vault. Export what people currently keep in their browsers and in whatever spreadsheet exists, and import that, duplicates and all. How the product handles a messy import is most of the migration experience.
Test the ugliest login you own. Every business has one: a portal with a non standard form, a legacy system that breaks autofill, a site that rejects long passwords. Try those, not the ones that work everywhere.
Run one full joiner and one full leaver. Create somebody through your directory, put them in vaults, then remove them and verify exactly what they lose and when. This is the test that separates products and it is the one most trials skip.
Break a second factor on purpose. Have a pilot user lose access and run the real recovery path, timing it and noting who had to be involved. Recovery is the support cost you will be living with.
Try it on a phone in the field. Autofill behaviour on mobile varies more between products than anything on a desktop. Our manual on running a software trial covers writing the success criteria before the trial rather than after.
What to ask a vendor before you sign
Nine questions, in writing, before any signature.
Exactly which rung includes single sign on, which includes directory provisioning, and which includes audit log export?
What is the minimum billable seat count on that rung, and does it change at renewal?
How are external collaborators billed, is there a guest role, what does it cost, and is there a free allowance?
Can access to a vault be granted with an end date, and what happens automatically when that date passes?
When a user is deprovisioned, what happens to their personal vault contents and to their access to shared vault contents?
What is the recovery path if a user loses both their master password and their second factor, and does it require an administrator?
What is retained in the event log, for how long, and can it be exported or streamed on our rung?
Is a secrets management product for engineers included, an add-on, or absent, and what is the per engineer rate?
What is the bulk export if we leave, does it include shared vaults and attachments, and is it self service?
The bottom line
A business password manager is cheap per seat and rarely cheap in total. The bands are real and useful as a floor: around $4 at the team rung, around $8 at business, around $12 at enterprise, with a developer secrets add-on around $9 per engineer. But at prices that low the licence stops being the interesting number, and the three lines around it start to dominate.
Those three are the rung premium you pay because single sign on or audit export sits above where your other requirements landed, the rollout hours that arrive in year one and appear on no invoice, and the standing administration time that recovery and lifecycle work consume every month. On the seventy seat example here, licences are about seventy one percent of a three year total and internal time is the rest, and cost per person climbs with size rather than falling.
So price it as a programme rather than a subscription. Count contractors as seats until a vendor tells you otherwise in writing, check the minimum before you check the rate, do the credential inventory before the rollout rather than during it, and put the identity premium in the business case as its own line so it can be argued about honestly.
Run your own headcount through the companion above and the true-cost calculator before you shortlist, and get the guest billing, the seat minimum and the deprovisioning behaviour confirmed in writing before you commit to a term.
VetLoft buys the tools it writes about and accepts no vendor payment for a verdict, and this page is published on that basis: educational material only, and not security, legal, procurement or compliance advice for your organisation. Every seat rate, add-on rate, minimum seat count, prepay discount, hourly rate, rollout estimate and multi year total on this page is an illustrative planning figure chosen to show how the meters in this category behave, not a quotation from any vendor, and pricing here moves often enough that a band which was typical when this was written may read differently by the time you shop. Where features sit on the rung ladder varies by product and shifts between releases, so treat the ladder above as a shape to verify rather than a specification. Nothing here states what any regulation, certification scheme, insurance policy or customer contract requires of you regarding credential storage, access control, retention of access records or breach notification, because those obligations differ by sector and territory and change over time. No claim is made about the security of any particular product or architecture. Establish your own requirements with a qualified professional, and confirm rung contents, seat minimums, guest and contractor billing, provisioning and deprovisioning behaviour, recovery paths, log retention, export rights and renewal terms directly with each vendor in writing before you commit.
Frequently asked questions
How much does a business password manager cost per user per month?
Illustrative planning bands, which move by vendor, region, contract length and feature mix, put a team or starter rung around $4 per user per month, a business rung around $8, and an enterprise rung around $12. A separate developer secrets add-on commonly sits around $9 per engineer per month on top. Those bands are narrow compared with most business software, which is exactly why the category gets underestimated: at $8 a head the licence for a sixty person company is a rounding error next to the rollout hours and the administration time that follow it. On the illustrative build in this verdict, a seventy seat deployment spends about $10.57 per user per month once three years of running cost and the one time rollout are counted, against a $8 sticker.
What is the SSO tax and how much does it actually add?
It is the industry nickname for the pattern where single sign on and directory integration are gated behind a higher priced rung rather than sold as a standard security control. On the illustrative bands here, moving from the $4 team rung to the $8 business rung to get single sign on doubles the per seat rate, which across seventy seats on annual billing is about $2,789 a year and about $8,366 across three years. Vendors argue that identity integration carries genuine engineering, certification and support cost, and that the buyers who need it are the ones who can pay. The counterargument, made just as often, is that pricing a security control as a premium feature encourages smaller organisations to go without it. Both positions are defensible, and neither changes what you have to budget.
Does single sign on remove the need for a password manager?
No, and treating it as if it does is one of the more expensive mistakes in this area. Single sign on covers applications that support an enterprise identity protocol, and a real business runs a long tail of things that do not: supplier portals, local router and firewall logins, wifi keys, registrar and hosting accounts, legacy finance systems, social accounts with one shared login, and API keys. Those credentials exist whether or not you have somewhere to put them, and the alternative storage is a spreadsheet, a notes app or somebody's memory. The correct read is that single sign on reduces the number of passwords in circulation and a password manager holds the ones that remain, which is why most organisations buying one are also buying the other.
Do free personal password manager plans for employees actually save money?
They are a real benefit and a poor substitute for a business plan. Many business rungs bundle a free personal or family account for each licensed employee, which is genuinely useful because most credential reuse starts at home and the bundled account gives people somewhere to keep the rest of their life. Valued at an illustrative $3 a month standalone, sixty of those bundled accounts is about $2,160 a year of benefit that never shows on the invoice. What they do not give you is the thing you are buying: shared vaults, policy enforcement, provisioning, recovery and an audit trail. A company running on employees' personal free accounts has no administrative control at all, and no way to remove access when somebody leaves.
What do minimum seat counts do to a small team?
They set a floor under your bill that has nothing to do with your headcount. Illustrative minimums in this category run around five billable seats on team rungs, around ten on business rungs, and considerably more on enterprise agreements. A three person business on a $4 team rung with a five seat minimum pays $240 a year rather than $144, which is an effective $6.67 per actual user per month against a $4 sticker, and $96 a year of pure structure. The minimum matters most at the moment you are choosing a rung, because the jump to a rung with a higher minimum can cost more in enforced empty seats than in rate.
How much should we budget for rolling one out, and is it really a cost?
It is a cost, it lands in year one, and it is the line most buyers leave out entirely. The illustrative model in this verdict prices configuration and policy work at six hours plus an hour for every eight people at $85 an hour, and per person onboarding at forty five minutes each at a loaded $42 an hour, which covers the account, the browser extension, second factor enrolment and importing whatever the person already keeps in a browser. For a seventy seat deployment that is about $3,459 one time, roughly thirteen percent of the three year total and more than half of a full year of licences. The one thing that reliably shrinks it is doing the credential inventory before the rollout rather than during it.
How should we price contractors, agencies and other external people?
Ask exactly how the vendor bills them before you design any shared vault, because the answer differs sharply and it is rarely on the pricing page. Some products bill an external collaborator as a full seat, some offer a limited guest role at a reduced rate or with a small free allowance, and some have no external concept at all, which means the only way to share is to hand out a licensed account. On the illustrative bands here, ten contractors on an $8 business rung with annual billing is about $797 a year, which is real money on a bill of that size. The structural question underneath is time limits: an external account that nobody expires is a standing grant of access to whatever vault it was added to.
What should a business budget for a password manager over three years?
Three illustrative shapes from this verdict, using the bands throughout. A twelve person business with two contractors on a team rung billed monthly lands near $3,973 across three years, about $7.88 per user per month and about $80 per employee a year. A sixty person company with ten contractors and eight engineers on a business rung with a secrets add-on and annual billing lands near $26,627, about $10.57 per user per month and about $129 per employee a year. A two hundred and twenty person company with twenty five contractors and thirty engineers on an enterprise rung lands near $121,739, about $13.80 per user per month and about $168 per employee a year. Cost per person rises with size in this category, which is the opposite of how most per seat software behaves.