Vault Admin guide
Admin scope: Admin authority is limited to the current vault, except password and MFA resets, which operate on the target person's global account.
Branding
- Choose Settings > Branding.
- Edit Display name (maximum 60 characters).
- Choose a six-digit hex Accent color.
- Choose Save. The name and accent update immediately in vault chrome, the sign-in page, and emails.
Locations
- Choose Settings > Locations.
- Add a location with Name, optional emoji Icon, and Description.
- Use the up/down controls to change display order.
- For a custom location, expand Edit to update it or choose Deactivate.
- Choose Show inactive locations to reactivate one.
Protected defaults: Bank, Home, and Other are seeded at normal vault creation and cannot be renamed or deactivated. A custom location in use by items or transactions must be cleared before deactivation.
Item types & subtypes
- Choose Settings > Item types.
- Add a type with Name, optional Icon, Description, and Kind (Item or Document).
- Use up/down controls to reorder types.
- Add subtypes under an active parent; edit, reorder, deactivate, or reactivate as needed.
- Use Show inactive types to restore a parent type. Reactivate a parent type before reactivating any subtype beneath it.
Protected defaults: Jewelry, Watch, Art, Document, and Other are seeded at normal vault creation as protected fallback categories. This applies to types only — no subtypes are seeded, so every subtype in your vault is one you created and none of them are protected.
Vault security
- MFA overview: enrolled vs not enrolled for every member. MFA is mandatory.
- Password policy: display-only platform default, currently 8–256 characters.
- Inactivity timeout: editable 5–240 minutes. Lower values can shorten sessions across the user's other vaults.
- Absolute lifetime: display-only 30-day platform default.
- Default currency: sets the initial currency on future add-item forms; existing items are unchanged and users can override per item.
Users & invitations
Invite a Member or Admin
- Choose Settings > Users.
- Under Invite a user, enter Email and choose Member or Admin.
- Choose Send invitation. The email link expires in 30 days.
- Copy/show the generated security code or QR and deliver it separately from the invitation email.
- Monitor Pending invitations. "Pending send" indicates a send issue; "Sent" indicates email dispatch succeeded.
Resend, revoke, and history
- Resend issues a new invitation link and security code; any older link stops working.
- Revoke stops the current invitation immediately.
- Show past invitations displays accepted, revoked, and expired invitations. Terminal records have no resend/revoke controls.
Manage an existing member
- Promote to admin or demote to member. The last active Admin cannot be demoted.
- Reset password emails a temporary password, rotates the global credential, forces change on next login, and signs the person out everywhere.
- Clear 2FA removes the global MFA enrollment. The person must enroll again before any vault can be accessed.
- Deactivate blocks this vault and signs the person out on the next request; Reactivate restores this membership.
- Delete permanently removes only the membership in this vault. Other vault access and the global account remain. Historical attribution is retained in anonymized form.
- Admins cannot reset, deactivate, or delete themselves. The vault must retain at least one active Admin.
Admin item recovery
- Choose Inventory and set Status to Deleted.
- Open the item.
- Choose Restore to return it, or Purge for permanent removal.
- Confirm purge only after verifying the item and required retention needs; purge cannot be undone.