An organization is run from the web vault, in its console. Its keys live only on its admins’ devices, and everything an admin decides is signed with them, so our server can’t add a member, change a role or relax a policy.
Make one
In the web vault, make an organization. You’re its first owner. It starts with 14 days of everything; after that it needs a plan.
Roles
| Role | Can |
|---|---|
| Owner | Everything an admin can, and make or remove admins and owners |
| Admin | Invite and remove people, make groups and vaults, grant access, set policies |
| Member | Use the vaults granted to them, or to their groups |
Keep more than one owner. The last owner can’t leave or be removed.
Invite people
Under Members, invite someone by the email address of their Vautir account. Your device checks their key against the public key log before it signs the invitation. They join by accepting.
Groups and vaults
Make groups, such as Engineering or Support, and put members in them. Make a vault, then grant it to a group or to one person:
- Edit: see, fill, add and change.
- View: see and fill.
- Fill only: fill, and never see the password. It’s kept by the apps, not by the encryption: use it to keep secrets out of sight, not out of reach.
People get their vaults the next time an admin’s device syncs.
Policies
Under Policies: a minimum master password strength, the longest a vault may stay unlocked, leaving the organization’s items out of exports, single sign-on, whether its vaults may travel in Travel Mode, and letting admins approve members’ new devices. Keeping exports out and the Travel Mode rule take Business.
Policies are kept by the apps. They protect a company from mistakes, not from someone determined to get around their own app.
Let a member’s new device in
With Admins can let members’ new devices in turned on, a member who lost every device can ask on a new one. Under Members, Members’ new devices, type the request code they read out to you, on a call, and choose Let it in.
Turning this on gives the organization’s admins a way into every member’s own vaults, and every member’s app says so. It’s off unless you turn it on.
Remove someone
Remove them under Members. Each vault they had gets a new key, with every item encrypted again. Then see when someone leaves for what they may have seen.
What to know
Admins can open every vault of the organization: that’s what lets them grant access. The phone and desktop apps and the browser extension show an organization’s vaults and keep its policies, without the console.
Last updated October 4, 2026