Vault Access Permissions

Who can see, vault, view, and download Authoritative Copies — and how to grant access safely.

How the vault is protected

  • Every user needs a personal Vault PIN to unlock the vault (set under Settings → Compliance).

  • After 5 failed PIN attempts, the vault is locked for 15 minutes for that user.

  • PINs are stored hashed (bcrypt) per user, there is no shared org-wide PIN.

  • All vault views and downloads are written to an immutable Audit Log.

What each role can do

  • Admin: can view AND download Authoritative Copies for any client.

  • Custodian: can view Authoritative Copies for clients they're assigned to, but cannot download or print them (UCC § 9-105 requires the Authoritative Copy be unique).

  • Sales: no vault access. They see proposals and standard documents, never vaulted originals.

Granting access to a Custodian

  • Assign the Custodian to the client (see Assigning team members to clients).

  • Custodian permissions for that client's vault are granted automatically on assignment.

  • Have the Custodian set their personal Vault PIN under Settings → Compliance if they haven't already.

Revoking vault access

  • Remove the Custodian from the client's Team tab.

  • To fully off-board, deactivate or remove the user (see Removing or deactivating users).

  • For an emergency, an Admin can reset that user's Vault PIN under Settings → Compliance → Team PINs, which locks them out until they set a new one.

Authoritative Copy rules

  • There is exactly one Authoritative Copy per signed contract (marked with a green badge).

  • A separate Copy (blue badge) is available for everyday reference. It can be downloaded freely.

  • The vault excludes Authoritative Copies from general document views to prevent accidental sharing.


Frequently asked questions

"Vault locked" message.
Too many wrong PIN attempts. Wait 15 minutes or have an Admin reset the user's PIN.

Custodian can't download an Authoritative Copy.
This is by design. Download the Copy (blue badge) instead, or ask an Admin if a true download is needed.

Forgot Vault PIN.
An Admin can reset it under Settings → Compliance → Team PINs. The user then sets a new PIN on next vault entry.

New Custodian doesn't see the vault.
Confirm they're assigned to at least one client and have set their personal Vault PIN.