Blog / Households

Sharing the numbers without sharing a password

In most households one person knows where everything is and the other has a rough idea. That arrangement works fine right up until the week it needs to work, which is exactly the week the person who knows is unavailable.

One shared household ledger connected to two people's views, one with full access and one view-only, beside a badge reading zero shared passwords.

In nearly every household we have talked to, one person does the money. They know which account the mortgage leaves from, when the insurance renews, roughly what the pension is worth, and which of the credit cards is the one with the sensible rate. The other person knows their own salary and their own card, and would need about a day and several phone calls to reconstruct the rest.

This is not a criticism of either of them. Specialisation is efficient, and most couples arrive at it without discussing it. The problem is narrower than "you should both be involved", and it is this: the arrangement has a single point of failure, and the failure mode is not hypothetical. Illness, a work trip during a payment deadline, a phone lost abroad, a bereavement. The moment the arrangement is tested is the moment the person who holds it is unavailable, by definition.

The usual response — "I should really write it all down" — never happens, because writing it all down is a two-hour job with no immediate payoff. What does work is smaller and structural.

The point is not fairness, it is redundancy

Shared visibility is often framed as a fairness question, and that framing is why it stalls. It becomes a conversation about trust and control, which is a hard conversation, and hard conversations get postponed.

Reframed as redundancy, it is much easier: if one of us cannot get to a phone for two weeks, can the other one keep the household running without ringing four institutions and guessing at passwords? That question has no emotional charge, has an obvious right answer, and can be solved in an afternoon.

The practical minimum for redundancy is short:

  • Where the money is. Which institutions, which accounts, what each one is for. Not balances to the penny — the list.
  • What leaves automatically, and when. Rent or mortgage, insurance, utilities, subscriptions, loan payments. Specifically, which account each one leaves from.
  • What is owed, and to whom. Cards, loans, tax due. The uncomfortable one, and the one most often held by exactly one person.
  • How to get in. Not a shared password — see below — but a documented path: which accounts exist, and how access would be recovered.

If both people can answer those four, the household is resilient. Everything past that is optional.

Three models, three different things to share

Couples arrange money in one of three ways, and each needs a different sharing setup. Trying to apply one model's answer to another is where most household finance tools become annoying.

Fully joint. One pot, both names, everything shared. Sharing is easy — the question is only whether both people actually look. In this model the risk is not access, it is that one person still does all the work and the other has a login they have never used.

Fully separate. Two independent sets of finances, expenses split by agreement. Here the shared object is small and specific: the split, what each has paid, and who is behind. Sharing everything is neither wanted nor necessary; sharing nothing means arguing from memory about who paid for the boiler.

Hybrid — the most common by far. Joint account for shared costs, individual accounts for everything else. The shared object is the joint pot plus each person's contributions to it, and the private object is each person's own money. A tool that cannot represent "shared" and "mine" as different things will be fought with constantly by anyone in this model.

0
Shared passwords required · 2 people, separate logins
Household space, bothFull access Each person's own spacePrivate Accountant, business onlyRevocable Credentials handed overNone
Three separate scopes, three separate logins, one of them time-limited. The structure that matters is not who can see what today — it is that removing someone's access later is a click rather than a password reset across nine institutions.

Visibility and control are different permissions

A great deal of household friction comes from conflating two things that a good setup keeps apart.

Visibility is being able to see the position: balances, what is coming out, what is owed. It is what redundancy requires, and it is almost never the thing anyone actually objects to.

Control is being able to move money and change arrangements. It is a separate question with separate answers, and for some households — where one person has a compulsive spending problem, or where the money is genuinely one person's from before the relationship — visibility without control is precisely the right arrangement.

Most tools offer only "shared" or "not shared", which forces households into an all-or-nothing choice they did not want to make. When you can grant sight of a set of records without granting authority over the accounts behind them, the conversation gets much easier, because the ask is smaller.

This applies to more than partners

The same structure covers an accountant, a bookkeeper, an adult child helping an ageing parent, and a business partner. In every case what is wanted is scoped, revocable visibility for a defined period — and in every case the default in practice is handing over a password, which grants everything, forever, to everyone who ever learns it.

Why sharing a password is the wrong mechanism

It is the default because it is the only thing that always works, and it is worth being explicit about what it costs.

A shared credential cannot be scoped — the person you gave it to sees everything, including the things you would not have chosen to share. It cannot be revoked without changing it and re-distributing it to everyone else who legitimately had it. It produces no record of who did what, which means an unexplained change has no author. It usually breaks two-factor authentication, or forces you to disable it. And it survives the relationship: people are still logged into ex-partners' accounts years later, not maliciously, just because nobody ever went through the list.

Separate accounts with granted access fix all five. Each person has their own login and their own second factor. Access is scoped to what you chose. Removing it is one action, immediately effective, with no effect on anyone else.

The test of a sharing arrangement is not how easily you can grant access. It is how easily you can withdraw it, on a bad day, without breaking anything else.

What to actually check before you set it up

The afternoon that makes it work

Concretely, for a household starting from nothing:

  1. Write the list of accounts together. Every institution, what it is for, whose name is on it. Half an hour, and it is the single highest-value artefact in this entire article. Most people discover at least one forgotten account doing this.
  2. Decide the model. Joint, separate, or hybrid — say it out loud, because a surprising number of couples have never confirmed that they are both assuming the same one.
  3. Set up scoped access rather than shared credentials. A shared household view both people can reach with their own login; private things stay private.
  4. Agree what happens if one of you is unavailable for a month. Who pays what, from where. Ten minutes, and it is the whole point of the exercise.
  5. Put fifteen minutes in the calendar, monthly. Both of you, same time, look at the same screen. Not a budget meeting — a look. The value is that neither of you is ever surprised.

Step five is the one that gets dropped and the one that does the work. Everything else is setup; the monthly fifteen minutes is what keeps two people holding the same picture.

What each arrangement actually gives you

Shared password Screenshots and updates Scoped shared access
Both can see the position Yes Only when sent Yes, any time
Private things stay private No Yes Yes
Works if one person is unreachable Yes No Yes
Two-factor authentication survives Usually not Yes Yes
Who changed what Unknowable Recorded
Removing access later Change and redistribute One click
Extends to an accountant Badly Manually Same mechanism, scoped

None of this requires a particular product — a shared folder and a written list gets you most of the redundancy. What it does require is deciding that the current arrangement, where one person is a single point of failure and the fallback is a password on a note, is a choice rather than the natural order of things.

See your own number instead of reading about someone else’s.

Import a statement, add your accounts, and get a real net-worth figure in an evening. Six months free, no card required.

Start free
6 months free · no cardStart free