Users and roles: global and vault roles decide who sees what
Every VaultPilot account has one global role for the console and, in each vault it can reach, a separate vault role. Only the Owner and Admin open the Users screen. That screen assigns Admin, Auditor or User and never creates another Owner.
- Global roles
- Owner, Admin, Auditor, User
- Vault roles
- Viewer, Editor, Manager
- Users screen
- Owner and Admin

What each global role covers
The global role decides what a person can do in the console. The level they hold inside a particular vault is a separate grant that the global role does not show.
Vault roles inside each vault
A Viewer can read, reveal and copy the records in that vault. Editor and Manager can also create, edit and delete them while the license is writable. A new local user gets a personal vault with Manager access to it. Only a Manager can create an external share package.
Creating and disabling accounts
Owner or Admin creates a local user with a username, a role and a temporary master password of at least 14 characters. The browser derives the keys from that password, so the plaintext never reaches the server. Disabling a user closes their sessions and keeps the record. Only an already disabled user can be deleted, and deletion cannot be undone.
Active Directory sign-in access
An Owner grants VaultPilot sign-in from the related Active Directory record, not from a Users row. Enabling it derives a local verifier from the current encrypted AD credential. VaultPilot does not query LDAP at each sign-in, so a later AD password change is not picked up automatically.
Tools of the founding Owner
Only the founding Owner can set a temporary password or reset 2FA for another user who is not an Owner. Setting a password replaces that user's keys and creates a new personal-vault key. Older personal-vault content and shares that were not re-wrapped can become unreadable.
Limits to know
Check step by step
Read more in the guides: Users screen, Integrations screen, Active Directory records screen