Vault
The credentials the organisation keeps: saved once, used without being seen, given for a time. The Vault hands a secret out as work done - a session opened, a request signed - and never as text on a screen.
What it is for
- Saved once, write-only
- A secret goes straight from the browser to the keeper, or the keeper makes it. After that there is no screen, and no door in the keeper, that returns it.
- Safes with four levels
- In a safe a person sees, uses, manages or owns. Seeing that a credential exists is not being able to use it.
- Access with an end
- A grant has a last day. People ask for access; whoever answers for the safe approves it from their cartable.
- Sessions inside the platform
- RDP and SSH open in the browser, already signed in. The person never learns the password. A session can be watched live, ended, and replayed afterwards.
- A browser that is already signed in
- Web systems open in a contained browser that the Vault signed in. An agent may drive it for the organisation - on a portal, on a supplier's site - without holding the login.
- Bound to where it belongs
- A credential is tied to the system it is for. Used in a web request, it goes only there, and its value is scrubbed from what comes back.
- Rotation
- Passwords and keys of servers are changed by the Vault itself, so the value in use is one nobody ever saw.
- A record of every use
- Who used what, when, for what - and one switch that stops every use at once.
Getting started
- Open Vault and make a safe for your team.
- Add an item: type the secret once, or let the Vault make one.
- Give people use of it, with an end date.
Tasks
Open a server without knowing its password
- Open the item in the Vault.
- Press Connect.
- The session opens in the platform, already signed in; it is recorded.
Ask for access
- Find the item you need.
- Ask for it and say why, and for how long.
- Whoever answers for the safe gets your request in their cartable.
Watch or end a session
- Open Sessions.
- Choose a live session to watch it, read-only.
- End it if it should not go on.
Questions
Can an administrator read a password?
No. Nobody reads a value back - not the person who saved it, and not an administrator. It can be used, replaced, or rotated.
Where are the values kept?
In a dedicated secret store on a network of its own, behind a keeper that only acts on one-use tickets the platform signs.
How do agents use credentials?
Like people: by grant, for a time, for a purpose - and without ever reading the value.
Related
- Workstation
- A Linux desktop of your own, inside the platform.
- Agent Studio
- AI agents that work as staff - and wait for people.
- Orchestration Studio
- Connect the systems of the organisation.
- Security and audit
- Who can see what, and why. Who did what, and when.