It doesn't rest my concern at all, it massively heightens it.
Sorry, but your head IT developer is dangerously inept and unqualified.
Under NO CIRCUMSTANCES should a raw password EVER be accessible to you , password-protected or not. They should be hashed with a unique salt. Honestly, this is ...