FAQ & troubleshooting
Can an admin read my employees' passwords?
No. Veridenti is zero-knowledge — the server holds only ciphertext, and no admin (or Veridenti) can decrypt a user's vault.
What happens if a user loses their device?
They re-authenticate through your IdP on a new device; their vault syncs from ciphertext. Personal-account recovery uses a recovery key held by the user.
Is there an SSO tax?
No. SSO and SCIM are included at every tier.
Do you phone home?
No phone-home by default. Telemetry, where offered, is opt-in.
A feature disappeared or is greyed out
It's either governed off (Policies) or not included in your plan (contact your account team).
We have a strict in-country / sovereign requirement
See Data residency — most countries are available on request, and zero-knowledge covers the sovereignty gap that cloud region choice alone can't.
How do I bring back an offboarded employee?
Offboarded members stay visible in Members with an Offboarded state. Click Re-invite — it re-enables the account, restores their previous role, and sends a fresh enrollment code. Note that re-enrolling does not restore shared-vault access; see the next question. Details: Deprovisioning & offboarding.
Why can't I re-grant a shared vault from the console?
Because the console can't — shared vaults are zero-knowledge, and the server never holds the shared key, so there is nothing server-side to re-grant. A current member who holds the vault re-shares it from their extension, which wraps the key to the returning member's new device key on-device. See Re-granting shared-vault access.
Can employees close their own support tickets?
Yes. Anyone on a ticket can Mark as Resolved and later Reopen it — and simply replying to a resolved ticket reopens it and notifies support. Idle tickets auto-close after 7 days (with a warning around day 4) and remain reopenable. See Support & incident notifications.
How do we get help?
Open a ticket from the Support area of the admin console (see Support & incident notifications), or email your account team or sales@veridenti.com. Include your organization name and, if it's a sign-in problem, whether SSO is connected.