Custodian View vs. Admin View
Custodians and Admins both have legitimate reasons to enter the vault, but their permissions are different. The split exists so a custodian can confirm what's on file without being able to extract Authoritative Copies.
What both roles can do
Unlock the vault with their personal PIN.
Open a vaulted envelope and view every document inside it.
See the Authoritative Copy (green badge) and the Copy (blue badge).
View the Audit Log for any envelope.
Admin-only actions
Vault in: push a completed envelope into the vault.
Vault out: release an envelope from the vault (e.g. for assignment).
Download the Copy and print the Copy.
Download / print the Audit Log.
Custodian restrictions
Custodians cannot download or print the Authoritative Copy. (Nobody can, see the viewing rules article.)
Custodians cannot download or print the Copy either. View-only access to both.
Custodians cannot vault in or vault out.
Why this split?
Custodians are typically assigned to confirm the existence and condition of contracts on behalf of a lender or trustee. They need to see, not to extract. Admins manage the lifecycle (vault in, vault out, operational copies). Combined with per-user PINs and the audit log, this gives you a clean chain of custody.
Note: Custodian access to a customer's vaulted documents is granted automatically when the custodian is assigned to that customer.