One of Vault's core features is the ability to grant access to resources securely, without ever exposing the actual password. This guide explains how to share access to a registered resource and define what actions the user can perform.
Selecting the Resource to Share
Locate the resource (server, database, or website) you wish to share:
- Log in to the Vault platform.
- Navigate to the appropriate tab (e.g., Servers, Websites, Databases).
- On the list of available resources such as Servers, Websites, or Databases, select a specific resource. The Edit page is displayed.
Adding a user or group
Grant access to the intended person or team:
- In the resource's configuration screen, click the Sharing Preferences tab.
- Click the Add button to open the user/group selection window.
- Select the user or group you want to share the resource with.
Defining Access Permissions
After selecting a user, define their level of access. This ensures they only have the permissions they need:
- Connect: Allows the user to initiate a connection to the resource or use its credential for login
- View Details: Allows the user to see session recordings, view connection logs, and, if permitted, see the credential's password
- Manage: Grants full administrative rights over the resource, including the ability to edit its settings or even delete it
Check the boxes for the permissions you want to grant and click OK.
Assigning Credentials and Save
Specify which credentials the user can use for this connection:
- After setting permissions, select the user's name in the list.
- A credential selection area will appear. Choose the credential(s) the user is allowed to use.
- Click Save to apply all changes.
The resource will now appear in the new user's vault with the exact permissions you defined.