The practical problem with informal sharing
Sending a password in chat creates unmanaged copies. Putting one in a spreadsheet makes it hard to distinguish who needs it now from who used to. Subment records the subscription owner and members alongside the credential, so access can be reviewed as responsibilities change.
How access is controlled
Members have a workspace role and access to an individual subscription can be set to View, Use or Manage. Stored secrets are masked until an authorized person requests them. A recent sign-in confirmation is required before a login is revealed or copied, and those sensitive actions are recorded.
Security boundaries worth knowing
Secrets are encrypted individually before storage, with a key scoped to their workspace. Exports never contain passwords, keys or 2FA codes. Subment can decrypt a secret for an authorized request, so it is not a zero-knowledge system.
For the complete technical description and its limits, see Subment Security.