Operator responsibilities: product controls and your team's part
VaultPilot runs on your own server. Your team looks after identities, endpoints, HTTPS, certificates, backups, updates, agents, recovery material, and support information.
- Identity
- Roles, sessions, and authenticators
- Infrastructure
- Server, HTTPS, certificates, backups
- Rhythm
- Daily, weekly, and monthly checks

Protect the people and devices that unlock secrets
A user working with a secret sees plaintext. That puts browser profiles and paired extension devices inside the area you protect.
- Give each person only the role and vault access they need
- Protect master passwords and authenticator devices
- Lock unattended sessions
- Revoke stale extension devices
Run the server and its backups
Patch the host according to your organization's policy and use the correct HTTPS certificate. Before a risky change, take a full backup and store it off the server disk. Test the restore in a controlled environment.
A daily, weekly, and monthly rhythm
Split routine checks by frequency. Keep each check small and give it an owner instead of relying on broad manual inspection.
Plan changes and escalate with redacted details
Put MSI upgrades, certificate changes, and DC Agent changes in a planned change window. Verify an update before you install it, then check health and audit state. Revoke or renew agent and device tokens when needed. For support, write to support@vaultpilot.io with only the redacted details from the support checklist.
Limits to know
- VaultPilot cannot stop an administrator who deliberately exports or exposes plaintext they are allowed to see.
- Self-hosting brings no patching, monitoring, backup retention, or disaster recovery with it; you provide them.
- Incident response and evidence policy belong to your organization; audit history is one input to them.
Check step by step
- 01
Name an owner for identity, server, certificate, backup, and update work.
- 02
Review privileged users, paired devices, and agent state on a schedule.
- 03
- 04
Escalate with redacted details through the right private path.
Read more in the guides: Operator runbook, Security and trust model, Support evidence pack