Permissions and access
Viewing an item, revealing its secret, copying it and using it through Autofill are different permissions.
Core permissions
- item.view: view authorized item metadata.
- secret.reveal: display the plaintext secret.
- secret.copy: copy the secret.
- secret.autofill: use the secret without necessarily seeing it.
Vault custodian
The custodian ensures vault continuity and can manage certain access under policy. Reveal is not granted automatically.
Just-In-Time
Advanced can temporarily grant a permission for a specific duration and reason.
Dual approval
Critical operations can require two distinct approvers.