Security
Using the credential vault
Storing shared client credentials with controlled, recorded access.
Last updated
The vault stores shared operational credentials per client — the account for a client's firewall, the service credential for a line-of-business application, the things a technician needs occasionally and that otherwise end up in a shared note.
Retrieval is an explicit reveal action rather than a passive display, and reveals are captured in the audit log. The behavioural effect is the point: an operator has to decide to look at a credential, and that decision has their name on it. Ambient access to a credential list produces no record and no deterrent.
Store credentials here rather than in ticket comments, chat history or a document nobody remembers sharing. Those locations have no expiry, no access record and no revocation story, and they outlive the people who created them by years.
Keep entries current. A vault full of credentials that no longer work is worse than an empty one, because a technician under pressure will try each stale entry in turn, sometimes locking the account out in the process. When you rotate a credential, rotate it here in the same change rather than as a follow-up task.
Review reveal activity occasionally. You are not looking for wrongdoing so much as for pattern: a credential revealed constantly probably indicates a process that should not require it, and a credential never revealed in a year may be documenting a system nobody supports any more.
When an operator leaves, revoking their account ends their access to the vault, but any credential they revealed should be considered known to them. Rotate the ones that matter as part of the leaver process rather than deciding case by case under time pressure.