How can a company backup lost account passwords?

Assuming that staff can follow the ideal of rotating Master Passwords every 3 months
What do we do in the event that someone loses an account password?

  1. Is there a way to do account recovery?
  2. Is there a way to access the KeeVault DB with an older master/account password?
  3. We are a distributed company, and master passwords are theoretically written on paper only…
  4. Would you recommend that alternate teams backup each the others master password inside Vault?

Modern best practise for passwords is to not enforce password rotation. Doing so forces users to select lower quality passwords than if they were asked to select just one strong password to remember for many years, or even forever.

Is there a way to access the KeeVault DB with an older master/account password?

Not at the moment (unless you are lucky, fast and technical enough to extract a copy of the older kdbx file from a device that has yet to receive the latest version of your Kee Vault). The underlying architecture of the app will allow for this feature in the future, although it’s likely to be something only available as part of a premium account due to the increased costs associated with that service. Maybe once you’re up and running with Kee Vault at your organisation you could let us know if you’re still interested in the feature so that we can better prioritse it among the other possible improvements for 2020.

If the master password is lost, the contents within the Kee Vault are lost - that’s a critical requirement to keep Kee Vault secure so can’t be worked around. However, there is an account reset feature which would allow the re-use of an email address with a new empty Kee Vault so you can’t get stuck with an account you’re paying for but unable to use.

Would you recommend that alternate teams backup each the others master password inside Vault?

That technically could work but is a business process question that only you and your team can decide upon really.