Preliminary requirements would be:
- shared secrets and passwords
- 2FA support (both for login and OTP codes)
- individual / team level access controls
- browser plugin support for Safari / Chrome
Would appreciate any suggestions, both for the replacement and for the list of requirements.
edit: formatting
I really like being able to add One-Time Passwords to any record, so we're not dealing with additional auth apps. The browser based UI makes it easy to add or update logins as you go. In addition, having controls to recover an account for someone that's locked out and has lost their Emergency Recovery Kit gives the execs some peace of mind. The secret key changes, so the old ERK is invalid should it be found later.
Individual and team level controls are available. We have some shared accounts, but you can create as many Groups and Vaults as you need. You can set access rights at multiple levels. So one group/person may be able to edit records, but another group/person can only read them to log in.
https://support.1password.com/create-share-vaults-teams/
Brian already mentioned the free family account. It's brilliant.
Using 1Password for 2FA reduces it to 1FA (owning a single developer's machine gains access to both the password and the second factor). Bite the bullet and go for Okta or any other corporate SSO platform (and all the associated costs - the "SSO tax" - from all the vendors you use SSO with) if you want proper MFA in a corporate environment.
This is the right path to plan for anyway -- as a small company in view of the SSO tax, shared passwords are a requirement. But you should be planning to gradually move away from that into proper SSO in order of system risk and as finances permit.
The addition of the secret key that is generated locally on your machine and not stored at 1Password + your master password + 2FA like a Yubico Yubikey is quite nice and adds significant security over LastPass.
The teams based accounts also include free family plans, it's wonderful. My wife's work pays for her premium 1Password which includes free premium family vault plans for me and her at no cost to us. These are entirely separate and cannot be accessed by her work - but are included for us to use.
https://blog.1password.com/how-1password-protects-your-data/
BitWarden, on the other hand, was almost too bare bones.
Maybe with training, 1Password will be viable for us.