Hi, I want to share yet another feature request idea here to gather initial thoughts and see if others in the community find it useful:
Organizations that rely on shared credentials — for service accounts, critical infrastructure, or Business Continuity Management (BCM) purposes — require an enforced mechanism to prevent users from viewing or copying shared passwords. Instead, access should ideally be restricted to autofill or integration-based usage, which is more secure, easier to audit and better aligned with principle-of-least-privilege models
Currently, the “Hide Passwords” option must be manually set per user/group assignment to each Collection, which is error-prone (easily forgotten), operationally inefficient at scale, inconsistent with enterprise-grade access control expectations.
Allowing users to manually copy or view passwords undermines enterprise control and makes it possible to use shared credentials entirely outside the managed Bitwarden environment — such as storing them elsewhere, reusing them in personal tools, or bypassing organizational oversight mechanisms. Restricting usage to autofill or integrations helps ensure that credential access stays within monitored, policy-enforced boundaries.
Feature Request
Introduce a global organization-level policy or admin control that allows administrators to optionally:
- Enforce
"Hide Passwords"
by default for all items shared via Collections - Automatically apply the setting to all new user/group assignments
- Lock the setting so only Admins can override it