Custodian View vs. Admin View

Custodians and Admins both have legitimate reasons to enter the vault, but their permissions are different. The split exists so a custodian can confirm what's on file without being able to extract Authoritative Copies.

What both roles can do

  1. Unlock the vault with their personal PIN.

  2. Open a vaulted envelope and view every document inside it.

  3. See the Authoritative Copy (green badge) and the Copy (blue badge).

  4. View the Audit Log for any envelope.

Admin-only actions

  • Vault in: push a completed envelope into the vault.

  • Vault out: release an envelope from the vault (e.g. for assignment).

  • Download the Copy and print the Copy.

  • Download / print the Audit Log.

Custodian restrictions

  • Custodians cannot download or print the Authoritative Copy. (Nobody can, see the viewing rules article.)

  • Custodians cannot download or print the Copy either. View-only access to both.

  • Custodians cannot vault in or vault out.

Why this split?

Custodians are typically assigned to confirm the existence and condition of contracts on behalf of a lender or trustee. They need to see, not to extract. Admins manage the lifecycle (vault in, vault out, operational copies). Combined with per-user PINs and the audit log, this gives you a clean chain of custody.

Note: Custodian access to a customer's vaulted documents is granted automatically when the custodian is assigned to that customer.