Users and roles: global and vault roles decide who sees what

Every VaultPilot account has one global role for the console and, in each vault it can reach, a separate vault role. Only the Owner and Admin open the Users screen. That screen assigns Admin, Auditor or User and never creates another Owner.

Global roles
Owner, Admin, Auditor, User
Vault roles
Viewer, Editor, Manager
Users screen
Owner and Admin
Illustration of global roles above vault roles, each vault granting its own access

What each global role covers

The global role decides what a person can do in the console. The level they hold inside a particular vault is a separate grant that the global role does not show.

Vault roles inside each vault

A Viewer can read, reveal and copy the records in that vault. Editor and Manager can also create, edit and delete them while the license is writable. A new local user gets a personal vault with Manager access to it. Only a Manager can create an external share package.

Creating and disabling accounts

Owner or Admin creates a local user with a username, a role and a temporary master password of at least 14 characters. The browser derives the keys from that password, so the plaintext never reaches the server. Disabling a user closes their sessions and keeps the record. Only an already disabled user can be deleted, and deletion cannot be undone.

Active Directory sign-in access

An Owner grants VaultPilot sign-in from the related Active Directory record, not from a Users row. Enabling it derives a local verifier from the current encrypted AD credential. VaultPilot does not query LDAP at each sign-in, so a later AD password change is not picked up automatically.

Tools of the founding Owner

Only the founding Owner can set a temporary password or reset 2FA for another user who is not an Owner. Setting a password replaces that user's keys and creates a new personal-vault key. Older personal-vault content and shares that were not re-wrapped can become unreadable.