Zoho Vault works on the principle of zero-knowledge architecture. Whenever a user adds a password, they are considered its owner by default. Passwords added by users are only visible to them by default. Users must share the passwords with others (including administrators) to provide access to them.
Pre-requisite
Users can only share passwords and folders after the approval of their admins
Share passwords
(Available in Standard, Professional, and Enterprise Editions)
- Click the share icon next to the passwords from the Passwords tab to share individual passwords.
- Select multiple passwords, then click Share passwords from More actions to share passwords in bulk.
- Select one of the following privileges to share passwords with users, user groups, or trusted third parties:
- Auto Login Only - Prevents users from viewing the passwords in plain-text. Users with this access can only auto log in to the websites.
- View - Allows users to view the password in plain-text
- Modify - Allows users to view and edit the password
- Manage - Gives complete control over the password to the user. Users with this permission can share the password with others, or even delete it.
Revoking access to shared passwords
Consider this example: Peter shares a password with Steve with complete (manage) access. Steve then shares the password with Joan, and Joan shares it with many more people. Peter wishes to stop unauthorized people from accessing his password, and removes all access privileges for Steve. However, the people who Steve had shared the password with (Joan and others) still have access to it. Zoho Vault instantly helps you remove everyone's access to your password in such situations.
Note:
When you share passwords with One-click login only privilege, users will not be able to see the password in plain-text in Zoho Vault. However, if the user is tech-savvy, they may be able to exploit the browser capabilities and see the password in plain-text using advanced techniques during the login process. This represents an inherent limitation of web browsers, which Zoho Vault does not have any control over.
Revoking access
- Select the passwords from the Passwords tab.
- Select More, click Revoke access from the drop down and click OK.
Note: Only the password owner can exercise this option. Users other than the password owner will lose access to the password. This removes the passwords from the users' folders as well. All actions are audited.
Share folders
(Available only in Professional and Enterprise Editions)
- Select the folder from the Folders tab and click the share icon to share with users or user groups
- Select one of the following privileges for the corresponding users and user groups:
- One-click Login Only - Prevents users from viewing the passwords in plain-text. Users with this access can only auto log in to the websites.
- View - Allows users to view the password in plain-text
- Modify - Allows users to view and edit the password
- Manage - Gives complete control over the password to the user. Users with this permission can share the password with others, or even delete it.
Sharing and deleting subfolders:
When you share a folder that contains subfolders, only the parent folder is shared by default. To share a folder and its subfolders, select Include subfolders from the Share Folder window. Similarly, when you delete a parent folder, the subfolders or the passwords present in the parent folder are not deleted.