DocsModulesVault: store, share and recover passwords securely

Vault: store, share and recover passwords securely

Vault is an encrypted password manager inside your organization — with its own master password, a recovery code, optional Windows Hello unlock, and end-to-end encrypted sharing of individual entries with teammates.

Prerequisites
  • You're signed in and your organization has the "Vault" module activated.
  • The very first time you open it, you set up your own master password — separate from your login password, and never stored anywhere unencrypted.
  1. 1

    Set up Vault (one-time)

    The first time you open it, you set a master password (with a confirmation field). Vault then shows a 12-word recovery code exactly once — you must check a box confirming you've written it down before continuing. Without the master password and the recovery code, the vault can't be unlocked later.

  2. 2

    Unlock — password, recovery code or Windows Hello

    Every time your session has expired, Vault asks for the master password. "Forgot your password? Use recovery code" accepts the 12 words from setup instead. On supported devices, you can also enable "Unlock with Windows Hello" to skip password entry going forward. After several failed attempts, a brute-force guard temporarily blocks input.

  3. 3

    Create an entry

    "New entry" opens the form: name and password are required, plus username/email, any number of websites, a folder and an encrypted note. The pencil icon next to the password field opens a password generator with a length slider, character-set options and a live entropy (bit-strength) readout; "Use" applies the generated password straight into the form.

  4. 4

    Folders, Trash and Shared items in the sidebar

    The sidebar has three fixed sections — "Vault" (all active entries), "Shared items" (both entries shared with you and entries you've shared, in one place) and "Trash" — plus your own folders below them. Deleted entries go to Trash first and can be pulled back via the restore icon there.

  5. 5

    Copy a password or login

    Both in the list view (per-row 3-dot menu) and in the detail pane on the right, you can copy username/email and password individually via an icon. Copied content is automatically wiped from the clipboard after 30 seconds — with no visible countdown or warning.

  6. 6

    Share an entry with teammates

    "Share" opens a member search with multi-select. Each share is individually re-encrypted end-to-end (ECDH P-256 + AES-256-GCM) for the chosen recipient — the detail view also states this. Recipients who haven't set up their own vault are skipped on save and reported by name as "skipped".

  7. 7

    Manage and revoke shares

    Under "Shared items", an entry you've shared shows all current recipients via "Manage recipients"; you can revoke access for one person, or use "Revoke all shares" to pull it back entirely. Shares you've received can only be revoked by the sender, not deleted by you.

Common pitfalls
  • Master password and recovery code are the only way in

    Vault encrypts client-side — without the master password and the one-time 12-word recovery code, there's no regular way back into the vault. Support cannot reset the master password.

  • Adding a new recipient requires a decrypted entry

    To grant an additional teammate access, the entry must already be decrypted (i.e. opened at least once) at the moment of sharing — otherwise the Share modal blocks the selection with a matching notice.

  • Auto-lock kicks in after 5 minutes of inactivity

    Vault locks itself automatically after 5 minutes, regardless of whether you're active in another tab. After that, the master password, recovery code or Windows Hello is needed again.

  • Copied content disappears silently after 30 seconds

    A copied password is wiped from the clipboard after 30 seconds with no warning — paste it after that window and you'll need to copy it again.

Related articles

More articles are coming soon.

Last reviewed on 2026-09-12Couldn't find your answer, or still stuck? Go to support