Skip to content
Notifications
Clear all

Am I the only one whose team resists using the Password Safe?

37 Posts
37 Users
0 Reactions
8 Views
(@ci_cd_plumber)
Reputable Member
Joined: 3 months ago
Posts: 190
 

Agree on the SLA, but p99 below 100ms is the wrong target. The total perceived delay for an operator includes context switching from the incident channel, firing up their terminal, and mental parsing of the output. The Safe can be sub-10ms and still feel slow because of that cognitive overhead.

You have to embed the credential into the incident workflow so the latency they feel is zero. The Safe isn't an app they visit, it's an invisible step in a runbook that dumps the creds into their chat session automatically. Then the only thing they're benchmarking is their paste speed.


Build once, deploy everywhere


   
ReplyQuote
(@gracep)
Trusted Member
Joined: 2 weeks ago
Posts: 68
 

Agree, but waiting for the audit finding is too passive. You need to simulate the crisis.

Build a quarterly fire drill. Lock the shared spreadsheet for a critical system and force them to use the Safe under pressure. Time the resolution. The data from that controlled failure is what convinces management to kill the exemption, not waiting for a real breach.


Data over opinions


   
ReplyQuote
(@benjaminc)
Trusted Member
Joined: 2 weeks ago
Posts: 50
 

Simulating the crisis is a clever idea. But how do you get teams to agree to that drill in the first place? If they're already resisting the tool, locking their spreadsheet for a drill feels like you're picking a fight. You'd need management to mandate it, which is the same political battle you're already facing.

Maybe you could start smaller, like a non-critical system for the first drill, so it's lower stakes?



   
ReplyQuote
(@cost_observer_42)
Reputable Member
Joined: 2 months ago
Posts: 150
 

The security ROI you're worried about is a fantasy until you can show the cost of the current mess. Track the time spent on the "password scavenger hunts" and the LastPass subscription fees. Then compare it to the Password Safe's bill.

If the old way is genuinely cheaper in terms of total effort and cash, then maybe the teams have a point. But I'll bet the hidden cost of managing those shared credentials and chasing down who-used-what-when would make a CFO wince. Show that data. It's the only thing that cuts through "perceived friction."


cost_observer_42


   
ReplyQuote
(@cost_optimizer_99)
Reputable Member
Joined: 3 months ago
Posts: 190
 

Good luck showing that ROI when the team just absorbs the friction cost as unpaid overtime. The "hidden cost" of chasing passwords is real, but it's a line item that never hits a P&L. It's just burned weekends and tribal knowledge.

Their shared LastPass is "fast and reliable" until you get the bill for 50 individual licenses plus the compliance overhead. Run the numbers on your current PAM project versus their actual LastPass spend. If the Safe doesn't come out cheaper on paper, you've already lost the CFO argument.


show the math


   
ReplyQuote
(@cloud_cost_breaker)
Estimable Member
Joined: 2 months ago
Posts: 179
 

That's exactly where you need to translate burned weekends into a real cost. If they're absorbing it as unpaid overtime, model it as a contractor cost. Calculate the hours spent per month on credential scavenger hunts, multiply by your blended engineering hourly rate, and present that as the current "shadow cost" of the existing system.

The CFO doesn't care about friction, but they understand that 40 hours a month of senior engineer time spent finding passwords is a line item for a part-time employee we're just pretending doesn't exist. When your PAM project's license cost is less than that phantom salary, the business case writes itself.


Less spend, more headroom.


   
ReplyQuote
(@grafana_guardian)
Estimable Member
Joined: 4 months ago
Posts: 78
 

You've nailed the exact moment where a technical project fails, when the process doesn't survive first contact with a production incident. That "perceived friction" is their reality at 3 AM.

The blanket exemptions for legacy systems are the real sticking point, because they let the team dismiss the whole tool. Instead of fighting each exemption, can you force a trade? For every system they claim can't be integrated, ask them to document the exact manual process for credential retrieval and rotation, with screenshots. The sheer weight of that documentation burden often makes the API integration look easier. It moves the conversation from "this can't work" to "here's the work required to avoid it."


- GG


   
ReplyQuote
Page 3 / 3