Admin Control Over Private Vault Sharing
Chris Hintz
BACKGROUND
We adopted Passwork several years ago specifically for its clear security model that distinguished between private and shared vaults. This structure provided private vaults for individual user credentials and company-wide shared vaults under password administrator oversight and audit control.
ISSUE WITH VERSION 7
The introduction of private vault sharing in v7, while useful for some organizations, has created a security oversight gap. Users can now share their private vaults directly with other users, bypassing our password administrator's audit capabilities.
REQUEST
We would like to request an administrative setting that allows organizations to disable private vault sharing when centralized oversight is required, maintain the original security model where all shared credentials remain under admin supervision, and preserve existing functionality for organizations that prefer the new sharing capabilities.
BUSINESS JUSTIFICATION
Many organizations require complete audit trails for shared credentials due to compliance requirements, security policies, and risk management protocols.
PROPOSED SOLUTION
Add a configuration option in the admin panel called "Allow private vault sharing" as a toggleable setting. Default should be enabled to maintain current v7 behavior. When disabled, this would restore v6 behavior where only admin-managed shared vaults can be shared. This approach would accommodate both security models while maintaining backward compatibility.
C
CK95
Many thanks for this feature request. It reflects exactly my discomfort with the new structure of version 7.x.
A few years ago, Passwork's clear structure and distinction between organizational and private vaults was the key factor in choosing it from among its numerous competitors.
We use the password manager to distribute passwords for systems or accounts that are managed exclusively by administrators. It is therefore not desirable for users to be able to share passwords or vaults or leave the vaults assigned to them. Nor is it desirable for them to be able to create shared vaults.
Version 7.x no longer meets these requirements, so we are currently compelled to continue using the older version 6.4.5. This is very unfortunate, as we had just renewed our license shortly before the release of version 7.x. I would very much like this feature request to be taken seriously and implemented with a certain level of priority.