Vault Roles
Control what organization members can view and manage across your SikkerKey vault.
Vault roles control what an organization member can view and manage across the vault. They cover shared administrative areas such as machines, AI agents, alerts, members, billing, and the Audit Log.
A vault role does not grant access to applications, projects, or secrets. Assign an access role separately when the member needs project access.
#How vault roles work
Every organization member has exactly one vault role.
The vault owner always has complete vault-wide authority and does not need an assigned role.
New members default to Collaborator unless a different assignable role is selected with the invitation.
View and manage permissions are evaluated on each protected request, not only when the dashboard page loads.
Manage permissions include the related view permission. Removing view also removes its dependent manage permission.
Role changes take effect for the member’s next request and refresh their dashboard access.
Vault roles and access roles are independent. A member may have broad vault-management authority but no project access, or extensive project access without permission to manage organization settings.
#Built-in vault roles
Role | Designed for | Vault-wide access |
|---|---|---|
Owner | The person who owns the vault | Complete control, including billing and role administration. Owner cannot be assigned to a member. |
Admin | Day-to-day vault administration | Machines, AI agents, enrollment tokens, projects, Trash, alerts, IP allowlist, integrations, members, support, and the wider Audit Log. Excludes billing and access-role administration. |
Developer | People who operate workloads and integrations | Machines, AI agents, enrollment tokens, integrations, their own Trash, the member roster, the vault overview, and their own audit activity. |
Collaborator | Members who need a minimal starting point | The vault overview and their own audit activity. This is the default for new members. |
Use Collaborator as the safe starting point, then add only the vault-wide responsibilities the member needs. Project access remains controlled separately.
#Vault-wide capability areas
A vault role can grant access in the following areas:
Area | View permission | Manage permission |
|---|---|---|
Overview | Open the vault overview | View only |
Machines | See machines and their status | Bootstrap, approve, disable, and revoke machines |
AI agents | See agents and their scopes | Provision, scope, and revoke agents within the user’s authority |
Enrollment tokens | See enrollment tokens | Create and revoke enrollment tokens |
Audit Log | Review the member’s own activity | Expand visibility to activity from other vault actors |
Alerts | See email and webhook configuration | Configure email alerts and outbound webhooks |
IP allowlist | See the vault allowlist | Enable the allowlist and add or remove entries |
Integrations | See connected integrations | Install and configure integrations and provisioning workflows |
Projects | — | Create and delete applications or projects and unfreeze projects |
Trash | See and manage the member’s own trashed secrets | See and manage trashed secrets across members |
Members | See the organization roster | Invite, suspend, remove, and assign permitted vault roles |
Access roles | See access-role definitions | Create and edit access roles |
Support | See support tickets | Open, reply to, and close tickets |
Billing | See subscription and billing state | Manage plans, subscriptions, and payment methods |
The dashboard shows only the vault-wide areas available to the signed-in member. The backend applies the same checks when an action is submitted.
#Custom vault roles
Enterprise vaults can create custom vault roles when the built-in tiers are broader than a team member’s responsibilities. A custom role has a name, description, and selected vault-wide capabilities.
For example, a Security Operations role could review the full Audit Log, configure Alerts, and manage the IP allowlist without gaining billing, member-management, or machine-management authority.
Create a custom vault role
Open Organization → Roles.
Select the plus button to create a new custom vault role.
Enter a clear name and description that identify the role’s purpose.
Enable the required capabilities in each vault-wide category.
Review the capability count and save the role.
Open Organization → Members and assign the role to the appropriate members.
Only the vault owner can open the role editor and create or change custom vault roles. Built-in roles are fixed and can be inspected but not edited.
Capability dependencies
Where an area has both View and Manage permissions, enabling Manage also enables View. Disabling View removes the related Manage permission. This prevents a custom role from managing a feature it cannot see.
Authority boundaries
A member who can manage organization members cannot assign authority equal to or greater than their own.
Built-in roles must be strictly below the assigning member’s tier.
Admin can assign Developer or Collaborator, but not Admin or Owner.
A custom role is assignable only when all of its capabilities are already held by the person making the assignment.
Owner is structural and never appears as an assignable member role.
These rules apply both when sending an invitation and when changing an existing member’s role.
#Assign a vault role
During an invitation
Open Organization → Members.
Select the plus button to invite a member.
Enter the member’s email address.
Choose one of the vault roles you are permitted to assign.
Send the invitation.
The invitation pre-assigns the selected vault role. If a referenced custom role is archived before the invitation is accepted, the joining member receives the Collaborator role instead.
For an existing member
Open Organization → Members.
Find the member in the table.
Open the Vault role selector in that member’s row.
Choose an assignable built-in or custom role.
Save the member changes.
The member’s effective vault permissions refresh immediately after the change. The change is also recorded in the Audit Log.
#Archive, restore, or delete a custom role
Archive. Removes an unused custom role from active assignment while keeping it available for restoration.
Restore. Returns an archived role to active use. If another active role now has the same name, rename or remove the conflicting role first.
Delete. Permanently removes the custom role and its active capability configuration.
A role cannot be archived or deleted while it is assigned to a member. Reassign every member first. Built-in roles cannot be archived or deleted.
Deleting a custom role cannot be undone. Archive it when you may need the definition again.
#Recommended role design
Use names based on responsibility, such as Security Operations, Platform Operator, or Billing Manager.
Keep project access out of the vault-role design; use access roles for applications, projects, secrets, machines, and policies.
Prefer one reusable role for people with the same vault-wide duties.
Review roles after team or responsibility changes.
Reassign members before archiving a role and confirm that they retain the access required for their work.
Use the Audit Log to review role creation, changes, assignments, archival, restoration, and deletion.