Preparing Digital Access in Advance
The instinct is to write the passwords down, which is both insecure and legally awkward. The arrangements that actually work are the providers' own legacy tools, a password manager with an emergency contact, and copies of the things that matter kept somewhere a family can reach.

The rule in short
Digital access is best arranged through the tools providers themselves offer for naming somebody, supported by a password manager with an emergency access feature, an inventory of accounts kept separately from credentials, express provisions in a power of attorney and a will, and copies of irreplaceable material stored outside any account. A written password list is insecure, quickly out of date and may breach terms of service.
Everybody who has thought about this at all has considered writing the passwords in a notebook, and it is the one solution that is both insecure and ineffective. Four other arrangements work considerably better and take an afternoon between them.
The provider tools, which come first
Several major providers offer them. Under various names, allowing an account holder to nominate somebody to receive access or to have the account dealt with.
They take priority. Over a will or any other instrument, on the hierarchy set out in who may reach a digital account.
They take minutes to configure. Which makes them by a wide margin the highest-value time anybody spends on this subject.
They should be reviewed. Since a nomination made years ago may name somebody no longer appropriate and will still govern.
And they do not cover everything. So the remaining accounts need one of the other arrangements described below.
The password manager with emergency access
It removes the need for a list. Since credentials live in one encrypted place rather than in a notebook or in somebody's memory.
Emergency access is the key feature. Allowing a nominated person to request entry, with a waiting period during which the holder may refuse.
It covers everything at once. Rather than requiring a separate arrangement for each account, which is why it scales where lists do not.
It stays current. Since passwords updated in the manager are immediately available through the same access arrangement.
And it is secure. Which a notebook is not, and which matters given how much a set of credentials would allow somebody to do.
| Arrangement | What it solves |
|---|---|
| Provider legacy tools | Access, with priority over other documents |
| Password manager emergency access | Credentials, securely and currently |
| Account inventory | Knowing what exists |
| Express document provisions | Authority where no tool exists |
| Copies of what matters | The material itself, whatever else fails |
The inventory, which is not a list of passwords
A list of accounts. What exists and with whom, without credentials, which is a document that can safely sit with a will.
It solves the identification problem. Since an executor's first difficulty is not access but knowing which accounts exist at all.
It should include financial accounts. Where statements arrive only online and nothing on paper would reveal the account's existence.
And subscriptions. Which continue indefinitely and are surprisingly hard to identify from a bank statement alone.
Kept with the other records. On the approach in the review nobody schedules.
Everything in this subject is directed at getting somebody into an account, and the thing families actually want is what is inside it. Photographs downloaded to a drive, documents saved locally, contacts exported: those survive whatever happens to an account, whoever the provider decides may have access, and however long any process takes. It is the least legal step available here and it addresses the loss families feel most.
The documents, which should say so expressly
A power of attorney addressing digital assets. Expressly, since providers apply their own terms and a general document may not satisfy them.
A will addressing them too. Which governs where no provider tool exists and is the fallback in the hierarchy set out in when the plan and the paperwork disagree.
Consent to disclosure of content. Which matters because privacy restrictions on communications are what most often defeat a fiduciary.
Naming who should have access. Specifically, since a general authority over digital assets does not identify a person.
And checking they agree with the tools. Since a tool setting takes priority and may say something different from the documents.
The copies, which matter most of all
Photographs downloaded. Somewhere outside any account, which is the single most valuable step for the thing families actually grieve losing.
Important documents saved. Locally or in a place the family can reach, since a document that exists only in an inbox is at risk.
Financial statements retained. At least periodically, so that an executor can identify accounts without needing access to anything.
Contacts exported. Which sounds trivial and matters enormously when a family is trying to inform people of a death.
And somebody told it exists. Since a perfectly organized backup nobody knows about is no better than no backup at all.
This is a problem with good solutions that almost nobody implements, largely because it does not feel like estate planning and because the obvious approach is the wrong one.
Writing the passwords down is insecure, goes stale within months and may breach terms of service in a way that complicates a fiduciary's position rather than helping it.
Provider legacy tools are the highest-value step, because they take priority over everything else in the hierarchy and take minutes to configure.
A password manager with emergency access solves credentials properly: securely, currently, and for every account at once rather than one at a time.
The inventory is a different document from a list of credentials, and it solves the first problem an executor actually has, which is knowing what exists.
Documents should address digital assets expressly, since providers apply their own terms and a general authority may not satisfy them.
Consent to disclosure of communication content is the specific provision that most often makes the difference, because that is where the privacy restrictions bite.
Tool settings and documents should be checked against each other, since a nomination made years ago takes priority over a will drafted last month.
And the copies are what actually matter to families, because a photograph saved outside an account survives every one of these processes going wrong.
An afternoon covers all five, requires no professional help beyond a clause in two documents, and addresses a problem that every family administering an estate now encounters.
It is worth saying who this matters to most, because it is not the people who assume. Somebody with substantial assets and professional advisers will have this dealt with as part of a wider arrangement. Somebody with modest means, whose entire photographic record of a family sits in one account, has more at stake here and is far less likely to have thought about it.
The five steps described here cost nothing beyond time and require no professional involvement at all except a clause in two documents. That combination is unusual in this subject and it makes the failure to do any of them harder to explain than most of the other omissions described anywhere on this site.
For families helping an older relative, the practical version is simpler still: sit down together, configure the legacy tools on the two or three accounts that matter, and download the photographs. Everything else is refinement.
Points to carry away
- Provider legacy tools take priority and should be used first.
- A password manager with emergency access solves credentials properly.
- An inventory of accounts is separate from an inventory of passwords.
- Documents should address digital assets expressly.
- Copies of irreplaceable material belong outside any account.
Questions readers ask
Why not simply write the passwords down?
Because it is insecure, because it goes out of date within months as passwords change, and because sharing credentials frequently breaches a provider's terms of service, which can complicate a fiduciary's position rather than help it. A list in a drawer is also a list anybody in the house can read. The arrangements described here achieve the same objective through routes the providers themselves offer, which means they work when they are needed rather than producing a fresh problem.
What is a legacy tool?
A setting offered by the provider itself under which the account holder names somebody to be given access, or to have the account managed or closed, after death or a period of inactivity. Several of the large providers offer them under different names. Because a direction given through such a tool generally takes priority over a will, these settings are the most effective single step available, and they take a few minutes each to configure.
How does emergency access on a password manager work?
Most reputable password managers allow a user to nominate a trusted person who may request access to the vault. The request triggers a waiting period during which the account holder can decline it; if they do not — because they have died or are incapacitated — access is granted. It is a well-designed mechanism: it requires no sharing of credentials, it cannot be used without the holder having an opportunity to refuse, and it covers every account in the vault at once.
Sources
- Uniform Law Commission — Fiduciary Access to Digital Assetsuniformlaws.org
- Legal Information Institute — Fiduciary Dutylaw.cornell.edu
- 18 U.S.C. § 1030 — Fraud and related activity in connection with computerslaw.cornell.edu
- Legal Information Institute — Power of Attorneylaw.cornell.edu
- Legal Information Institute — Executorlaw.cornell.edu
- Legal Information Institute — Privacylaw.cornell.edu
Silverline Legal Notes is a publication, not a law firm. This article states general rules and cites its sources; it is not advice about any particular case, and the law differs by state and changes over time.
More in Passing Things On
Checking and Changing a Designation
A designation review involves listing every account and policy including those with former employers, requesting written confirmation of the current designation from each provider, comparing it against present intentions, submitting changes through the provider's own process, and retaining written confirmation that each change was recorded. Confirmation matters, because a submitted form that was never processed leaves the old designation in place.
Transfer-on-Death Registrations
A payable-on-death or transfer-on-death registration names somebody to receive an account, security or in many states a vehicle or a property, on the owner's death. The named person has no rights while the owner is alive, cannot access the asset, and does not expose it to their own creditors. The registration passes the asset outside probate and outside the will, is revocable at any time, and is available in most states for a wide range of assets.
When the Plan and the Paperwork Disagree
An estate is distributed by whatever combination of documents governs each asset: designations for retirement accounts and policies, the form of ownership for property, registrations where they exist, and the will for everything else. Where these have been made at different times without reference to each other, the total result frequently bears no relation to what was intended, and no document corrects the others.


