Skip to content

In the life of one shared password: Shared

Cask

Most passwords a team shares never really go away.

They sit in a chat thread, a notes app, a screenshot on someone's phone. Cask is for sharing passwords, keys, and anything else confidential with your team, in a way anyone can use, and where nothing lives longer than it should.

The shared password
  • A chat threadstill there
  • A screenshotstill there
  • A notes appstill there
The three places our own planning documents named.

In the life of one shared password: Kept

We built a vault for the team I lead.

Our own team kept its keys, settings, and shared logins scattered in exactly those places. So we built a vault.

Everything in it is locked, and nothing is kept in plain text. Before anyone sees a secret, the vault writes down who is looking and when. If it can't write that down, it doesn't show the secret. People who only need to use a secret can see it and copy it. People who manage secrets can only change the ones they added.

  1. Check 1: You're signed in

  2. Check 2: You're on the team

  3. Check 3: You're allowed to see this one

  4. Check 4: Your visit is written down

  5. If the visit can't be written down, the envelope stays shut.

  6. Now you see it

What the vault we built checks, in order, before it shows a secret.

In the life of one shared password: Copied

Then someone pressed copy.

The vault did its job. But every vault has the same edge, and it's the copy button. The moment a secret is copied, it goes straight back to the chat thread, the notes app, the screenshot.

Our own planning documents said so, and left the question open: people copy secrets into unsafe places, some secrets never get changed, and should a revealed secret hide itself again after a while? Nobody had answered it. That edge is where Cask starts.

The vault

Copy

After copy, nobody knows where it went.

The vault keeps a secret safe until the moment it's copied.

In the life of one shared password: Living

A secret should have a lifetime.

In Cask, every secret you share has an age and an end. When you share something, you say who it's for and how long they need it: an hour, a week, until the project is over. When the time is up, it disappears from their view, unless someone decides to renew it.

Kept until someone remembers to delete it.

Renewed for another week

Gone

Two lifetimes, with no numbers. The plum line is how Cask is designed to work.

A secret that nobody renews was probably a secret nobody needed.

The design team can see this for one day. After that, it disappears unless you renew it.

Choose how long. An illustration of how sharing is meant to work.

In the life of one shared password: Understood

No training needed.

Many of the people building products today didn't come from software. They came in because AI made building possible for them. They shouldn't have to learn what an environment variable is to share one safely.

So Cask speaks plainly. Who can see this. How long it lives. Who has looked at it. Anyone should know what to do the moment they open it.

What sharing could look like. An illustration.

In the life of one shared password: Someone leaves

When someone leaves.

The hardest day for a team's secrets is the day a person leaves. Usually nobody knows everything they could see, so nothing gets changed, or everything does in a panic.

Cask can show every secret that person had access to, and turn it into a short checklist of what to change, so the job actually gets finished.

Leaving: a teammate

  • Payment account login(changed)
  • Email service key(changed)
  • Office Wi-Fi(changed)
  • Social media login(not changed yet)
  • Hosting account(not changed yet)

3 of 5 changed

An illustration.

And for someone outside the team, a freelancer or a client, there's a link that opens once and then stops working.

Here's the login you asked for

The secret, hidden as dots

The first time

This link has already been used.

The same link, again

A link that opens once. An illustration.

In the life of one shared password: Anything confidential

Not only for engineers' keys.

It started with keys and logins, because that's what an engineering team shares. But every team has things only some people should see: bank details, contracts, access codes, the recovery codes for an account everyone depends on. Cask is for all of it.

Bank detailsA contractAccess codesRecovery codesAn API keyShared logins
Some of what a team keeps that only some people should see.

Share what's needed, for as long as it's needed. Then let it go.

You are in the studio: Cask