Somebody dies, and within a week the family hits a wall. The bank has a process. The county has a process. Meanwhile the photos live in iCloud, the mortgage is on autopay from an email account nobody can open, and the phone that receives every verification code is sitting on the kitchen counter behind a six-digit passcode. So the question I keep getting is a fair one: should you put passwords in your will? The short answer is no. However, the instinct behind the question is exactly right, and there is a better way to do it.
Why Passwords in Your Will Backfire
A will is not a private document. Once it goes through probate — the court process that validates the will and settles the estate — it generally becomes part of the public court record. In other words, writing passwords in your will is a bit like taping your PIN to the courthouse bulletin board. Not ideal.
There is a second problem, and honestly it is the bigger one: the list goes stale. Most people update a will maybe twice in their life. Meanwhile you rotate your bank password in March, your email password in July, and the moment you do, that carefully notarized list is wrong. As a result, your family inherits a document that is both public and useless.
That is the case against passwords in your will in one sentence. Your will is still the right place to name who gets access. It is simply the wrong place to store how.
The Law Already Beats Your Will Here
Most states have adopted some version of the Revised Uniform Fiduciary Access to Digital Assets Act, usually shortened to RUFADAA. A fiduciary is simply a person legally authorized to act on someone else’s behalf — an executor, a trustee, or an agent under a power of attorney. Tennessee’s version sits in Title 35, Chapter 8 of the state code.
Here is the part almost nobody knows. The law sets an order of authority, and your will is only in second place. If a company offers an “online tool” for naming who gets your account, that setting overrides a contrary direction in your will. Below both of those sits the terms-of-service agreement you clicked through years ago.
So the single most powerful thing you can do costs nothing and takes about half an hour. It is not a trip to the attorney. Instead, it is twenty minutes in your account settings.
Set Up the Online Tools First
Apple calls its version a Legacy Contact. You pick the person, and Apple generates an access key. After your death, that person hands over the access key plus a death certificate and gets your photos, messages, notes, files, and device backups. Keep one catch in mind, though: Apple specifically excludes anything stored in iCloud Keychain, which means your saved passwords and passkeys do not transfer. That single gap is why the rest of this article exists.
Google’s equivalent is Inactive Account Manager. You choose how long the account has to sit idle, and you can name up to ten trusted contacts to be notified and given the data you select. Most major platforms now offer something similar. Because these settings legally outrank your will, set them first.
Build the Inventory Before the Passwords
Before anyone worries about credentials, write down what actually exists. Executors do not get stuck because a password is wrong. They get stuck because they never knew the account was there in the first place. I group it into five buckets:
- Identity anchors — the primary email address and the mobile number. Nearly every reset flow runs through these two.
- Money — banking, brokerage, retirement, PayPal, Venmo, and any crypto wallet.
- Memories — photos and documents in iCloud, OneDrive, or Google Drive.
- Obligations — subscriptions, autopay bills, domain names, and web hosting.
- Access tools — the password manager, the authenticator app, printed recovery codes, and the phone passcode.
Keep that inventory somewhere your executor can find it. A sealed envelope in the fire safe works fine. After all, the inventory itself holds no secrets — it is a map, not a key.

Three Ways to Hand Off Access
Once you accept that passwords in your will are the wrong tool, three practical approaches remain. Each one trades convenience against risk.

First, the sealed sheet. Your will points to a sealed document held by your attorney or in your safe. The will stays public; the sheet stays private. It costs nothing. On the other hand, it goes stale fast and it is a single piece of paper away from disaster.
Second, a password manager with emergency access. This is my default recommendation for most families. Bitwarden’s emergency access lets you nominate a trusted contact who can request your vault; you set a waiting period, and if you do not decline in time, access is granted automatically. It requires a paid tier. 1Password takes a different route, using a second family organizer plus a saved Emergency Kit. Either way, the list can never go stale, because it is the live list.
Third, name a digital fiduciary in the will. This is the “designate the IT guy” idea, and it is legitimate. Your estate attorney adds language authorizing a named person to receive your digital assets, including the content of electronic communications. Keep in mind that this is the part I am not qualified to draft — I am a network engineer, not an attorney.
Honestly, the right answer is usually all three, layered. Online tools handle the big platforms. The password manager handles the other two hundred logins. Finally, the will handles the legal authority to act.
Do Not Forget the Phone
This is the piece that wrecks families, and it is the reason listing passwords in your will solves so little. Modern accounts do not stop at a password. They send a code, and that code lands on a phone locked behind a passcode nobody wrote down. If you have read my post on multi-factor authentication, you already know the phone has quietly become the master key to everything.
So handle it deliberately:
- Record the device passcode in the same sealed envelope as the inventory.
- Print the backup or recovery codes for your five most important accounts.
- Write down the carrier account PIN so the number itself can be transferred.
- Tell your executor not to cancel the phone line first. Killing the number breaks text-message verification on everything else, and that mistake is painful to undo.
If You Own a Business, Double the Stakes
For a small business, this stops being a family problem and becomes a continuity problem. The domain registrar, the web host, the Microsoft 365 or Google Workspace admin account, the accounting software, and the firewall login are all often tied to one person. Consequently, if that person is the only administrator, the business can be locked out of its own email while it is trying to notify customers.
The fix is unglamorous but effective. Add a second global administrator. Register the domain in the company’s name with a shared billing contact. Document a break-glass account and store its credentials the same way you would store the key to the front door.
What to Do Instead of Passwords in Your Will
You do not need a lawyer to start. You need about an hour and a pot of coffee.
- Set an Apple Legacy Contact and Google Inactive Account Manager today.
- Write the five-bucket inventory and seal it in the safe.
- Move your logins into a password manager and turn on emergency access.
- Print the recovery codes for email, banking, and your password manager.
- Tell one human being where all of this lives. A perfect plan nobody knows about is just a hobby.
- Ask your estate attorney to name a digital fiduciary — and to reference the sealed document rather than reprint it.
The last thing anyone wants during a week of mourning is a scavenger hunt through a locked phone. So skip the passwords in your will, and build the handoff instead. Fortunately, an afternoon of preparation now spares your family that entirely.
If you would rather have help mapping this out — for your household or your business — that is a normal thing to ask for. Get in touch with I am Geek and we will walk your accounts, your devices, and your network, then leave you with a plan your family could actually follow.


