Organizations

Convert a vault into an organization, invite members, manage membership, and let each person work with their own identity and assigned access.

Updated today

Organizations let several people work in one SikkerKey vault while keeping every person’s identity, access, and activity separate. The organization uses the vault you already have, so its applications, projects, secrets, machines, policies, audit history, and settings remain in place.

Each member signs in with their own SikkerKey account. Their roles determine what they can manage across the vault and which applications and projects they can reach, while the audit log records actions under the person who performed them.

Organizations are available on plans that include organization management. The dashboard shows the conversion option when it is available for your vault.


#How an organization is structured

An organization has one owner and any number of invited members.

  • Owner — the account that owns the vault. The owner retains full access to the organization and its data.

  • Member — an existing SikkerKey user who accepts an invitation to the organization. A member keeps their own account and personal vault.

  • Vault role — controls vault-wide responsibilities such as viewing or managing members, machines, alerts, audit activity, and other organization features.

  • Access role — controls which applications and projects the member can enter and what they can do with secrets, machines, and policies inside those projects.

The two roles are assigned separately. See Vault Roles and Access Roles for the full permission model.


#Convert a vault to an organization

Every customer account begins with a personal vault. The vault owner can promote that vault to an organization from Settings.

  1. Open Settings while signed in as the vault owner.

  2. Find the Organization section and select Convert to organization.

  3. Enter an organization name of up to 100 characters.

  4. Confirm the change using the security methods configured for your account. SikkerKey may ask for your password, 2FA code, and a passkey verification.

  5. Select Convert to organization. The dashboard reloads with the organization features available.

Conversion is permanent. The vault remains an organization after it has been converted.

Your vault ID and existing resources do not move or change during conversion. The organization name appears in the dashboard, invitations, and vault picker so members can identify the vault they are entering.


#Invite a member

Invite people from the organization’s Members page. The recipient must already have a SikkerKey customer account registered with the email address you invite.

  1. Open OrganizationMembers.

  2. Select the add button in the Members panel.

  3. Enter the member’s SikkerKey account email address.

  4. Choose the vault role they should receive when they join. Collaborator is selected by default.

  5. Select Send invitation.

An invitation remains valid for seven days. The pending invitation shows its email address, assigned vault role, send time, and expiration. Use Revoke invite if the invitation should no longer be accepted.

The invitation assigns a vault role only. After the person accepts, assign an access role from their member row to give them the appropriate application and project access.


#Accept or decline an invitation

Pending organization invitations appear in the recipient’s dashboard sidebar. The invitation identifies the organization owner, the assigned vault role, and the areas that role can access.

  • Accept adds the recipient’s SikkerKey account to the organization with the vault role chosen by the inviter.

  • Decline closes the invitation without adding a membership.

  • Invitations opens the complete list when the recipient has more than one pending invitation.

If a custom vault role is archived or removed before the invitation is accepted, SikkerKey places the new member in the Collaborator role. This gives the member a safe starting point until an organization administrator assigns the intended role.

Once accepted, the member can enter the organization the next time they sign in and choose a vault.


#Enter an organization

A user who belongs to one or more organizations chooses which vault to enter after authentication. The picker includes their own vault and each organization where their membership is active.

  1. Sign in to SikkerKey with your usual account method.

  2. In the Vault dropdown, choose the organization by its name, vault ID, and owner.

  3. Select Enter Vault.

The selected vault remains active for that session. To work in another personal or organization vault, sign out and sign in again, then choose the other vault.

Inside an organization, the sidebar displays the organization name and vault ID. Vault-wide pages appear according to the member’s vault role, while applications and projects appear according to their access role.


#Manage organization members

The Members page provides the current roster and pending invitations. You can search by username or email, sort members by username, email, or join date, and filter the table to active or suspended memberships.

Assign roles

Use the role controls on a member row to select a vault role and an access role. Role selections remain staged until you select Save, allowing several member changes to be reviewed and applied together.

Role changes are enforced on the member’s subsequent requests. The member does not need to accept another invitation.

Review member activity

Open the row menu and select History to review that member’s activity within the current organization. The history can be filtered and searched, and remains scoped to actions the member performed in this vault.

Organization-wide events also appear in the vault’s audit log, including invitations, invitation revocations, accepted invitations, role changes, suspensions, restorations, removals, and voluntary departures.


#Suspend, restore, or remove a member

Action

Result

Use it when

Suspend

The member immediately stops receiving access from their vault and access roles. Their membership and assigned roles remain saved.

Access should be paused and restored later.

Restore

The suspended membership becomes active again and its saved roles apply on subsequent requests.

The member should regain their previous organization access.

Remove

The membership is deleted and organization access ends. The person needs a new invitation to rejoin.

The person should no longer belong to the organization.

Use the overflow menu on a member row to select Suspend, Restore, or Remove. SikkerKey asks for confirmation before suspension or removal.

Suspending or removing someone affects their access to the organization. Their SikkerKey account, personal vault, and memberships in other organizations remain available to them.


#Leave an organization

A member can end their own membership from Settings while they are inside the organization.

  1. Open Settings.

  2. In Leave organization, select Leave organization.

  3. Type the displayed organization name exactly to confirm.

  4. Confirm the departure.

The membership and its role assignments are removed immediately, and the current session returns to the member’s personal vault. A new invitation is required to join the organization again.

The vault owner manages the organization as its owner and does not use the member departure flow.


#Use single sign-on

Organizations on an eligible plan can connect a SAML identity provider and control how members authenticate for the organization. SSO changes the sign-in path while the same organization memberships, vault roles, access roles, and audit attribution continue to apply.

See Single Sign-On (SSO) for setup, domain verification, enforcement, and member sign-in instructions.


#Organization access and machine access

Organization membership governs people using the SikkerKey dashboard. Machines continue to authenticate to the vault with their own machine identities and receive secret access through project membership and secret grants.

This keeps human access and workload access independently controllable. Adding a person to an organization does not give their applications a machine identity, and changing a member’s roles does not change the credentials used by existing machines.


  1. Convert the vault and choose a recognizable organization name.

  2. Create the vault roles and access roles your team needs.

  3. Invite members with the lowest suitable vault role.

  4. After each member joins, assign an access role for the applications and projects they need.

  5. Review member activity and pending invitations regularly.

  6. Suspend access when it is temporarily unnecessary and remove memberships when they are no longer required.

  7. Configure Single Sign-On when centralized authentication is part of your organization’s sign-in policy.