Vault Roles

Control what organization members can view and manage across your SikkerKey vault.

Updated 2 days ago

Vault roles control what an organization member can view and manage across the vault. They cover shared administrative areas such as machines, AI agents, alerts, members, billing, and the Audit Log.

A vault role does not grant access to applications, projects, or secrets. Assign an access role separately when the member needs project access.


#How vault roles work

  • Every organization member has exactly one vault role.

  • The vault owner always has complete vault-wide authority and does not need an assigned role.

  • New members default to Collaborator unless a different assignable role is selected with the invitation.

  • View and manage permissions are evaluated on each protected request, not only when the dashboard page loads.

  • Manage permissions include the related view permission. Removing view also removes its dependent manage permission.

  • Role changes take effect for the member’s next request and refresh their dashboard access.

Vault roles and access roles are independent. A member may have broad vault-management authority but no project access, or extensive project access without permission to manage organization settings.


#Built-in vault roles

Role

Designed for

Vault-wide access

Owner

The person who owns the vault

Complete control, including billing and role administration. Owner cannot be assigned to a member.

Admin

Day-to-day vault administration

Machines, AI agents, enrollment tokens, projects, Trash, alerts, IP allowlist, integrations, members, support, and the wider Audit Log. Excludes billing and access-role administration.

Developer

People who operate workloads and integrations

Machines, AI agents, enrollment tokens, integrations, their own Trash, the member roster, the vault overview, and their own audit activity.

Collaborator

Members who need a minimal starting point

The vault overview and their own audit activity. This is the default for new members.

Use Collaborator as the safe starting point, then add only the vault-wide responsibilities the member needs. Project access remains controlled separately.


#Vault-wide capability areas

A vault role can grant access in the following areas:

Area

View permission

Manage permission

Overview

Open the vault overview

View only

Machines

See machines and their status

Bootstrap, approve, disable, and revoke machines

AI agents

See agents and their scopes

Provision, scope, and revoke agents within the user’s authority

Enrollment tokens

See enrollment tokens

Create and revoke enrollment tokens

Audit Log

Review the member’s own activity

Expand visibility to activity from other vault actors

Alerts

See email and webhook configuration

Configure email alerts and outbound webhooks

IP allowlist

See the vault allowlist

Enable the allowlist and add or remove entries

Integrations

See connected integrations

Install and configure integrations and provisioning workflows

Projects

Create and delete applications or projects and unfreeze projects

Trash

See and manage the member’s own trashed secrets

See and manage trashed secrets across members

Members

See the organization roster

Invite, suspend, remove, and assign permitted vault roles

Access roles

See access-role definitions

Create and edit access roles

Support

See support tickets

Open, reply to, and close tickets

Billing

See subscription and billing state

Manage plans, subscriptions, and payment methods

The dashboard shows only the vault-wide areas available to the signed-in member. The backend applies the same checks when an action is submitted.


#Custom vault roles

Enterprise vaults can create custom vault roles when the built-in tiers are broader than a team member’s responsibilities. A custom role has a name, description, and selected vault-wide capabilities.

For example, a Security Operations role could review the full Audit Log, configure Alerts, and manage the IP allowlist without gaining billing, member-management, or machine-management authority.

Create a custom vault role

Open Organization → Roles.

Select the plus button to create a new custom vault role.

Enter a clear name and description that identify the role’s purpose.

Enable the required capabilities in each vault-wide category.

Review the capability count and save the role.

Open Organization → Members and assign the role to the appropriate members.

Only the vault owner can open the role editor and create or change custom vault roles. Built-in roles are fixed and can be inspected but not edited.

Capability dependencies

Where an area has both View and Manage permissions, enabling Manage also enables View. Disabling View removes the related Manage permission. This prevents a custom role from managing a feature it cannot see.

Authority boundaries

A member who can manage organization members cannot assign authority equal to or greater than their own.

  • Built-in roles must be strictly below the assigning member’s tier.

  • Admin can assign Developer or Collaborator, but not Admin or Owner.

  • A custom role is assignable only when all of its capabilities are already held by the person making the assignment.

  • Owner is structural and never appears as an assignable member role.

These rules apply both when sending an invitation and when changing an existing member’s role.


#Assign a vault role

During an invitation

Open Organization → Members.

Select the plus button to invite a member.

Enter the member’s email address.

Choose one of the vault roles you are permitted to assign.

Send the invitation.

The invitation pre-assigns the selected vault role. If a referenced custom role is archived before the invitation is accepted, the joining member receives the Collaborator role instead.

For an existing member

Open Organization → Members.

Find the member in the table.

Open the Vault role selector in that member’s row.

Choose an assignable built-in or custom role.

Save the member changes.

The member’s effective vault permissions refresh immediately after the change. The change is also recorded in the Audit Log.


#Archive, restore, or delete a custom role

  • Archive. Removes an unused custom role from active assignment while keeping it available for restoration.

  • Restore. Returns an archived role to active use. If another active role now has the same name, rename or remove the conflicting role first.

  • Delete. Permanently removes the custom role and its active capability configuration.

A role cannot be archived or deleted while it is assigned to a member. Reassign every member first. Built-in roles cannot be archived or deleted.

Deleting a custom role cannot be undone. Archive it when you may need the definition again.


  • Use names based on responsibility, such as Security Operations, Platform Operator, or Billing Manager.

  • Keep project access out of the vault-role design; use access roles for applications, projects, secrets, machines, and policies.

  • Prefer one reusable role for people with the same vault-wide duties.

  • Review roles after team or responsibility changes.

  • Reassign members before archiving a role and confirm that they retain the access required for their work.

  • Use the Audit Log to review role creation, changes, assignments, archival, restoration, and deletion.