Twelve missions that cover everything a customer will ever ask you to do with Keeper. Each one is checked automatically from the practice account's activity.
1 of 12 complete
Customers sign up for new services all the time. The habit to teach: never type a password at sign-up — let Keeper generate it and save the record right then.
Go to Create account (link on the sign-in page). Fill in a name and email, put the cursor in the Password box, click the Keeper icon and choose Generate. Keeper offers to save the new record. Finish the on-screen email verification step. (This mission counts if any account in the lab was created this way.)
Every customer visit starts here: the customer signs in and Keeper offers to save the record. If Keeper never asks, nothing else works.
Sign in at /login with the username and password your trainer gave you. When KeeperFill pops up, click Save. Open the Web Vault and find the new record.
The core of the Security Tune-Up: replace a weak, reused password with a long random one that only Keeper remembers.
My Account → Security → Change password. Put the cursor in the New password box, click the Keeper icon, use Generate, and let Keeper update the record. A generated password is 16+ characters — that is what this check looks for.
Proves the record was updated in Keeper. If Keeper still has the old password, the customer is locked out tomorrow.
Sign out. On the sign-in page click the Keeper icon in the password box and pick the record. Do not type the password by hand.
Two-factor stops a stolen password from being enough. Keeper can hold the 6-digit code generator so the customer never needs a separate app.
Security → Two-factor authentication → Turn on. Open the record in Keeper, edit it, add a Two-Factor Code field, and paste the secret (or scan the QR). Enter the code Keeper shows to confirm. Save the recovery codes into the record's notes.
Customers hate 2FA until they see Keeper fill the code for them. This is the moment they buy in.
Sign out and sign in again. After the password, the site asks for a 6-digit code. Click the Keeper icon in that box and fill it (Keeper also copies the code to the clipboard).
Passkeys are the future: nothing to type, nothing to phish. Keeper stores them so they work on any device the customer signs into Keeper on.
Security → Passkeys → Add a passkey. When the browser asks where to save it, Keeper (the KeeperFill window) should offer to store it. Give it a name like "Keeper passkey".
Shows the customer what passwordless feels like: no password, no code.
Sign out. On the sign-in page click Sign in with a passkey, then choose the Keeper passkey in the prompt.
Old phones, ex-employees, and unknown devices show up in passkey lists all the time. Part of a tune-up is deleting what should not be there.
Security → Passkeys. Find the passkey you did not create (your trainer planted it) and click Remove. If there is none, ask your trainer to add a stale one.
When a customer loses their phone you often have to reset 2FA. Practice the full cycle and update the Keeper record with the new secret.
Security → Two-factor → Turn off (needs your password). Then turn it on again — a new secret is generated. Replace the Two-Factor Code field in Keeper with the new secret, or the old codes will fail.
Recovery codes are the last resort when 2FA is unavailable. You need to know where they are and how they work before a customer is panicking.
Sign out. Sign in with the password, and on the 2FA screen choose Use a recovery code. Paste one of the codes you saved in Keeper's notes. Each code works once.
Customers lock themselves out constantly. Know what it looks like and what the fix is (an admin unlock, or a reset).
Sign out and enter the wrong password 8 times. Read the message. Then ask your trainer to unlock you from the Trainer Admin, or wait for them to reset your account.