Divan Talk to us
All documentation

Vault

The credentials the organisation keeps: saved once, used without being seen, given for a time. The Vault hands a secret out as work done - a session opened, a request signed - and never as text on a screen.

The platform underneath About Vault

What it is for

Saved once, write-only
A secret goes straight from the browser to the keeper, or the keeper makes it. After that there is no screen, and no door in the keeper, that returns it.
Safes with four levels
In a safe a person sees, uses, manages or owns. Seeing that a credential exists is not being able to use it.
Access with an end
A grant has a last day. People ask for access; whoever answers for the safe approves it from their cartable.
Sessions inside the platform
RDP and SSH open in the browser, already signed in. The person never learns the password. A session can be watched live, ended, and replayed afterwards.
A browser that is already signed in
Web systems open in a contained browser that the Vault signed in. An agent may drive it for the organisation - on a portal, on a supplier's site - without holding the login.
Bound to where it belongs
A credential is tied to the system it is for. Used in a web request, it goes only there, and its value is scrubbed from what comes back.
Rotation
Passwords and keys of servers are changed by the Vault itself, so the value in use is one nobody ever saw.
A record of every use
Who used what, when, for what - and one switch that stops every use at once.

Getting started

  1. Open Vault and make a safe for your team.
  2. Add an item: type the secret once, or let the Vault make one.
  3. Give people use of it, with an end date.

Tasks

Open a server without knowing its password

  1. Open the item in the Vault.
  2. Press Connect.
  3. The session opens in the platform, already signed in; it is recorded.

Ask for access

  1. Find the item you need.
  2. Ask for it and say why, and for how long.
  3. Whoever answers for the safe gets your request in their cartable.

Watch or end a session

  1. Open Sessions.
  2. Choose a live session to watch it, read-only.
  3. End it if it should not go on.

Questions

Can an administrator read a password?

No. Nobody reads a value back - not the person who saved it, and not an administrator. It can be used, replaced, or rotated.

Where are the values kept?

In a dedicated secret store on a network of its own, behind a keeper that only acts on one-use tickets the platform signs.

How do agents use credentials?

Like people: by grant, for a time, for a purpose - and without ever reading the value.

Workstation
A Linux desktop of your own, inside the platform.
Agent Studio
AI agents that work as staff - and wait for people.
Orchestration Studio
Connect the systems of the organisation.
Security and audit
Who can see what, and why. Who did what, and when.