Skip to main content
Cedros

Sharing Vault access with teammates or the assistant

Choose who can read a Vault credential, manage team and assistant access, and remove access when it is no longer needed.

Use Vault sharing to let teammates or the site assistant access a saved credential without putting its value in chat or ordinary notes. You choose access for each shared item.

Open Tools → Vault and select the credential. You need permission to manage shared credentials, normally as an administrator. If you have not saved an item yet, start with Storing credentials in Cedros Vault.

Check who already has access

The Vault list's Who can read it column gives you a quick view of each completed credential:

  • Only you: a Personal item belonging to your signed-in identity.
  • Admins: a shared item available to administrators.
  • Team: a shared item that team members with Vault access can read, subject to any additional restrictions on that item.
  • Assistant: assistant access is also enabled. Open the item to review which assistant identities are allowed.

Open Who can read it on the credential to review its controls. Your team and The site assistant are independent: enabling one does not enable the other. Administrators can always read shared items, even when both switches are off.

Personal items cannot be shared while they remain in Personal. An administrator can move their own item to another collection in Details and select Save. That move makes it a shared item available to administrators; review its access before proceeding. If you cannot manage shared items, ask an administrator to arrange the shared credential without sending its secret in a message.

The Team and Assistant collection names help organize items. The names alone do not grant access.

Share a credential with your team

  1. Open the intended shared credential and check its name and purpose.
  2. Find Who can read it and turn on Your team.
  3. Wait for the switch to become available again. If an error appears and the switch returns to its previous position, the change did not save.
  4. Return to Vault and check the item's Team label. Reopen it to confirm that the switch remains on.
  5. Ask the intended teammate to open Vault using their own account and confirm that the item is available. They do not need to send you its value as proof.

Team sharing grants reading access. A teammate may be able to Reveal and Copy the secret while still being unable to replace it, change its details, or manage sharing.

The Your team switch does not choose one named teammate. If only one person should receive a credential, ask your administrator about the access restrictions available for your site before enabling team sharing.

Allow the site assistant to access a credential

  1. Open a shared credential and find Who can read it.
  2. Turn on The site assistant. If the item has no previously allowed assistant identities, Cedros selects the site assistant automatically.
  3. Wait for the change to finish and check for an error. Open Advanced to review the Allowed assistants summary, especially if the item was previously shared with a different assistant.
  4. Return to Vault and confirm the Assistant label. Reopen the credential to verify its saved access settings.

You can leave Your team off when only administrators and the allowed assistant should have access.

Credential access and the assistant's tool permissions are separate. Sharing an item does not enable every integration, authorize every action, or guarantee that a particular workflow can use it. Review Controlling what the assistant can do if the assistant lacks the tools needed for your intended work.

The assistant's Vault grants tool lists the credentials granted to its identity without revealing their values. A listing confirms that the item is discoverable to that assistant; it does not test the credential with the original service. Do not ask the assistant to print the secret as a connection check.

Review allowed assistant identities

For an item with assistant access enabled, Advanced → Assistant ids specifies which assistant identities may access it. For ordinary site-assistant use, keep the default unless your administrator has provided a different identity.

If you need to change the list, enter the exact IDs supplied by your administrator, separated by commas, and select Save ids. Wait for the change to finish and check the Allowed assistants summary. Display names and guessed IDs may not identify the assistant that actually runs your workflow.

At least one identity is required while assistant access is on. To remove all assistant access, turn off The site assistant instead of trying to save an empty list. Adding another ID broadens access to that assistant, so include only the identities you intend to authorize.

Remove access when it is no longer needed

Open the credential and turn off the relevant switch in Who can read it:

  • Turn off Your team to remove team reading access. Administrators retain access to the shared item.
  • Turn off The site assistant to remove assistant access and clear its allowed-assistant list. Team access remains as it was.
  • Turn off both when the shared item should be available only to administrators.

Wait for each change to finish, then return to the list and reopen the item to verify the saved settings. The switches save immediately; the Save button in Details is not required for these changes. Discarding unsaved detail edits does not undo a saved sharing change.

Removing Vault access does not revoke the password or API key at its original service, or erase copies someone already obtained. If a former recipient must no longer be able to use it, change or revoke it at that service and update the stored Vault value as appropriate.

Review sharing when someone's role changes, an integration is retired, or a credential is replaced. Check both the team switch and the assistant identity list rather than assuming a new secret changes the audience.

Resolve common sharing problems

There are no sharing switches. A Personal item shows Only you. It must become a shared item before team or assistant sharing is available. That move requires permission to manage shared credentials.

The switches are disabled. You may have view-only access, or a change may still be saving. Wait for the current action to finish. Ask an administrator to change a shared item's access if you cannot manage it.

A switch turns back off or reports a conflict. Read the error. Your permission may have changed, or another update may have reached the item first. Reload the current item, review its settings, and retry only the change you still intend to make.

A teammate cannot find the item. Confirm that team access saved, the teammate is using the correct site and account, and they have access to Vault. Clear their search filter. An administrator should also check any additional restrictions on the item. See Understanding feature access for missing tools or permissions.

The assistant cannot find or use the item. Confirm that it is shared, The site assistant is on, and the allowed IDs include the assistant being used. Check its tool permissions separately. If the item says Needs setup, complete its stored secret first. Access to a credential does not make an expired, revoked, or otherwise invalid value work.