TL;DR: A generator creates a secret you will not remember, so the next step is a password manager, not a notes file named “passwords.” Save the new login before you submit the site’s form, confirm the entry, and let the manager fill it later. The generator is the mint. The manager is the wallet. Create the string here, then paste it into the manager’s new-login form rather than into a chat with yourself.
The tab that disappeared
A designer I worked with generated a twenty-character password for a client billing tool, pasted it into the signup form, and felt finished. The browser crashed while the success page was loading. The site had created the account. The generator tab was gone. She spent a Monday on a reset flow that demanded the old password she no longer had, then a support queue, then a second mailbox because the first was tied to the same mess. The string had been excellent for the four seconds it existed on screen.
Generation without storage is a magic trick. The secret is real, and then it is not. The fix is an order of operations, not a better memory.
Save first, submit second
When you change or create a password, open the manager entry before you touch the website’s save button. Paste the generated value into the manager, name the entry with the real site, and include the username. Then paste the same value into the site. Submit. Only after the site says the change worked should you close the generator. If the site rejects the password, you still have it in the manager and can edit once, on purpose.
- Title the entry with the domain, not “work stuff.”
- Store the username in the same record so a future you is not guessing which email you used.
- Keep the previous password in a note on that entry until the new one has succeeded once.
- Refuse screenshots of the generator result in a camera roll.
That sequence feels fussy the first time and obvious the third time. The designer’s Monday is what the fussy version prevents.
Managers are not all the same shape
Browser-built password stores are convenient and better than reuse. A dedicated manager adds a master password, clearer sharing for a household, and a vault you can open on a machine that is not already logged into your browser profile. Either is a valid place for generated passwords. A spreadsheet on the desktop, a sticky note in a synced notes app with no passphrase, and a thread in a messaging app are not. Sync makes those copies travel to every signed-in phone, including the one you will eventually sell.
If you already have a pile of reused passwords, do not wait for a free weekend to migrate forty sites. Each time you log into an important one, replace that password with a generated value and save the manager entry in the same sitting. The pile shrinks because you touched the account anyway.
The master password is the exception
Do not generate the manager’s master password and then store that master password inside the same vault. You would be locking the key in the box. The master can be a long passphrase you can type. The generated site passwords live underneath it. Write the master down once and keep the paper somewhere you control, separate from your everyday bag, until you are sure you can recall it.
Shared work accounts need an owner
Teams sometimes generate a strong password for a social inbox or a hosting panel and paste it into a group chat. The generator did its job. The distribution undid it. A manager that supports a shared vault, or a break-glass envelope held by one admin, keeps the random string intact. When someone leaves, you rotate the password, update the vault, and you do not have to wonder which laptops still have the chat history.
Personal accounts should not live in the team vault “just in case.” The point of per-site random passwords is that a leak stops at one door. Mixing personal and shared records builds a hallway.
Emergency access is a setting, not a shared master password
Some managers let you name a spouse or a partner who can request the vault if you are in the hospital. That is a better plan than telling them the master password “just in case,” which means two people can open every account on a normal Tuesday. If your tool has a waiting period on emergency requests, turn it on and tell the person what to expect. If it does not, a sealed paper copy of the master password in a drawer they can reach is the blunt version. Either way, the generated site passwords stay inside the vault. You are sharing a recovery path, not emailing twenty strings “so you have them too.”
Leave the generator tab up until the vault agrees
Next change you make, keep the generated password visible until the manager shows the same value and a test login succeeds. Then close it. You do not need to admire the string, and you should not email it to yourself as a backup. The manager is the backup. The generator is ready the next time a site asks for something you refuse to invent.