VeridentiDocs
ChangelogFor BusinessContact
Docs Admin guide Shared & team vaults

Shared & team vaults

Give a team a shared set of credentials without anyone handling plaintext.

How it works (zero-knowledge)

Each shared vault has its own key (an SVK). When you share a vault with a member, their copy of the SVK is wrapped to their personal public key on-device — the server never sees an unwrapped key. Members decrypt locally. Remove a member and their access ends; sensitive rotations re-key the vault.

Roles

Access is role-based and least-privilege. Owners and delegated admins manage membership; members use the vault. A scoped admin only sees and manages their slice (e.g., a region or department).

Re-granting shared-vault access

When a member is offboarded, their wrapped copy of the shared key is deleted and the vault is re-keyed. If that person later returns (see Deprovisioning & offboarding), re-enrolling does not restore their shared-vault access — and that's zero-knowledge working as intended: the server never holds an unwrapped shared key, so the admin console cannot re-grant access with a button. Access is re-granted the same way it was granted the first time — a current member who holds the vault re-shares it from their extension, which wraps the shared key to the returning member's new device key on-device.

To re-grant access:

  1. Re-invite the member so they're an active org member again (Members → Re-invite restores their account and role and issues a fresh enrollment code).
  2. Have them connect the Veridenti extension and enroll with the new code (or via SSO).
  3. A current key-holder of that vault shares it with them from their extension — the share is wrapped to the returning member's new key, entirely on-device.
NoteThis applies to shared/team vaults. A returning member's own Work vault is different: re-enrolling gives them a fresh, empty Work vault. If they were the sole holder of an old Work vault with data you need back, recovering it requires the organization recovery-key (ORK) ceremony — see your recovery controls under Roles & Policies.

What if…

Last updated August 26, 2026 · Docs v1.3
Enter to open · Esc to close
Veridenti