But for an enterprise team (or just a team), you need to be able to share passwords with various team members.
Without a system, you're left with each of those people having to use their own (often insecure) personal methodology. Without a password manager, people resort to very simple passwords, or reusing passwords across multiple systems, or writing passwords down on PostIt notes next to their monitors.
Without the convenience of a cloud-based system, you don't have an easy way to back up your passwords -- what happens if someone gets hit by a bus? And you can't easily have someone run compliance to verify when the last time was you updated your password, or how complex your passwords are -- at least not without showing them the raw passwords in all systems.
I get paranoia... but any team that runs a password manager service consistently for all users will be much more secure than any team that doesn't.
* Most Private And Secure Password Managers - Secured.fyi - Alpha || https://secured.fyi/password.html
* Best Password Manager 2018 - Lastpass vs. Dashlane vs. 1Password || https://www.tomsguide.com/us/best-password-managers,review-3...
There is a wide spectrum between password-on-PostIt and cloud-based third-party service.
A password-manager accessing a version-controlled master file on the LAN, for example. Which can not only be firewalled nice and tight but is also resilient to xloud-provider going out of business or changing their ToS.
I don't think I can trust a password manager that isn't open source. Cloud or not.
Can you trust the manufacturer of your personal devices?
Sooner or later you're trusting somebody, unless you literally smelted your own machine starting from ore and a bucket of sand, and then wrote every line of code for it, including the compiler, yourself.
Maybe you should inventory all the entities you're trusting already.
The only major vuln are the updates, and that would have to be a backdoor delivered to everyone, otherwise the mismatched hashes would be noticeable. The surface area is smaller with the client side encrypted version.
It was really difficult in the beginning to earn the trust but 1Password is now over 13 years old and there are over 15 million users.
We started 1Password Teams project in 2015 and since then we had several external audits: https://support.1password.com/security-assessments/
We are currently in the process of completing the SOC 2 compliance audit.
We also have the highest paid bug bounty program in BugCrowd: https://bugcrowd.com/agilebits
Details are here: https://1password.com/security/ Whitepaper (PDF): https://1password.com/teams/white-paper/