Creating roles in VaultOne is a fundamental step for efficient permission management and robust security organization within your company's digital vault. Roles streamline the process of assigning and controlling user permissions, eliminating the need to modify individual user access settings one by one.
Roles simplify security administration by:
- Centralizing Permissions: Define a set of permissions once and apply them to multiple users
- Ensuring Consistency: All users assigned to a specific role will have the exact same access level, reducing errors
- Simplifying Onboarding/Offboarding: Easily grant or revoke a complete set of permissions when users join or leave teams
- Enhancing Security Posture: A clear, role-based structure helps enforce the principle of least privilege
Default Roles
Upon the creation of your VaultOne instance, three default Static roles are automatically included:
- Admin: Typically has full administrative control
- Guest: Often has very limited viewing permissions
- User: A standard role with general access
These static roles cannot be deleted, but you can modify their permissions to fit your needs. The role labeled "Default" is particularly important; any new user added to the platform will automatically be assigned this role unless a different one is specified during their creation.
Creating Custom Roles
Beyond the static roles, you can create custom roles tailored to your company's specific security and organizational structure. The criteria for creating these new roles should align with how you group people or functions (e.g., by department, project team, or level of responsibility).
- Login in to VaultOne.
- Go to Administration.
- Click the Functions menu (this might be labeled "Roles" in some interfaces).
- Click +Create new role.
- Name your new role.
- Choose a name that clearly identifies its purpose such as "Team Leader," "IT Support," "Finance Team".
- Once the role is created, click the name to edit.
- Go to the Permissions tab.
- Define the permissions: In this section, you'll see various folders, each representing a menu or a set of functionalities within VaultOne.
- Click each folder to expand it and reveal specific permissions (e.g., "View Credentials," "Manage Computers," "Create Users").
- Select and grant the specific permissions that users assigned to this role should have.
- After selecting all the desired permissions, click Save to apply your changes.