Configure vaults and access grants

Understand storage settings and the effect of the first and last access grant.

Understand storage settings and the effect of the first and last access grant.

Configure a vault

Product location: /document-vault/vaults/{vaultId} (fallback: /document-vault/vaults). Open the vault configuration and access controls.

Create or edit the vault's name, storage location, supported document types and related options. If no storage location is available, ask the administrator to configure one. Deactivating a vault makes it inaccessible while retaining its documents.

Field

What to decide

Name

A readable purpose, such as Engineering evidence.

Code

A permanent reference of 2–20 uppercase letters or digits. Choose it before creating the vault.

Description

What belongs in the vault and who maintains it.

Storage location

The configured storage destination for its documents.

Document types

Which document categories this vault should accept. Only the types you select are created.

Audit log visibility

Whether records are available to administrators, the vault owner, document-level users or all users.

Default and maximum lock duration

How long a normal edit lock lasts and the upper limit available to users.

After Create Vault, reopen the vault and inspect its name, code, status and document count. The code is fixed once the vault exists and prefixes its controlled-copy identifiers. Configure capabilities and access before adding sensitive working records.

Review outgoing-reference rules, change-request requirements, audit visibility and the default maximum lock duration. Audit visibility offers scopes such as administrators, vault owner, document-level access or all users; choose the scope needed for the vault's records.

The vault has a readable name, permanent code, purpose and selected storage location.The retained example is active and ready for document upload; its document count is still zero.

Understand the access baseline

Product location: /document-vault/vaults/{vaultId} (fallback: /document-vault/vaults). Open the vault configuration and access controls.

A vault with no access grants is open to signed-in users in the organisation. Adding the first grant restricts access to the granted users and organisation administrators. Removing the last grant reopens access to the organisation.

This behaviour makes an empty grant list materially different from a deny-all policy. Inspect the resulting access summary after every grant change.

No access grants exist for this vault. The page explicitly states that signed-in organisation users can read it until access is restricted through grants.

Add a grant

Product location: /document-vault/vaults/{vaultId} (fallback: /document-vault/vaults). Open the vault configuration and access controls.

Choose a person, role or all-users grant. Role access includes qualifying group-inherited membership. Select the access level and, if needed, an expiry and reason.

Level

Intended access

Admin

Full vault administration, including deletion.

Member

Read and write, without deletion.

Viewer

Read-only access.

Auditor

Read-only oversight.

Review active, expired and revoked entries separately. An expired grant remains visible as a record but should not be counted as an active entitlement. Organisation administrator access remains relevant when evaluating the restricted vault.

Configure available features with vault capabilities, and document eligibility for AI/search with knowledge indexing policies. These settings are distinct from access grants.

Did this answer your question?
😞
😐
😁