The credential vault
Store client logins securely, with categories, rotation reminders, and a record of every reveal.
Every firm holds client logins. Most hold them in a spreadsheet, a password manager somebody set up in 2019, or a partner's memory. The vault is the place they should actually live.
Where to find it
Categories are configured under Settings → Firm → Credential vault.
Store a credential
- Enter the Service name.
- Add the Login URL.
- Enter the Username.
- Add the password.
- Pick a Category.
- Set the Sensitivity.
- Add Notes if there's context worth keeping.
Two-factor seeds
The vault stores an Authenticator seed (TOTP) alongside the credential.
That solves the specific problem of a client account with two-factor enabled where the code goes to a phone nobody at your firm holds. Storing the seed means anyone with access can generate the code, rather than the work stopping until one particular person picks up.
Treat these with the same care as the password. A stored seed removes the second factor for anyone who can reveal it.
Rotation reminders
Set a Rotation reminder — Every 6 months, Every 12 months, or Off.
Rotation is the discipline nobody keeps without prompting. Twelve months is realistic. Six is better for anything with money attached.
Viewing and revealing
Viewing a credential and revealing its contents are separate permissions, and there's a further elevated level for the most sensitive entries.
Reveals are recorded. That's the point — a vault where anyone can silently read anything is a spreadsheet with extra steps. The record is what makes it defensible if a client ever asks who had access to their payroll login.
Categories
Categories are firm-defined and reorderable — payroll, banking, state portals, whatever your firm actually deals with.
Worth setting up before you start entering credentials. Recategorising two hundred entries later is a bad afternoon.
Archiving
Credentials are archived rather than deleted, so a login that's no longer current stays as a record of what existed.
Notes and limits
- Credentials belong to a client.
- The Credentials tab doesn't appear for staff without the permission.
- Reveals are logged with who and when.
- Archiving keeps the record. It doesn't keep the credential usable.
