Everyone on record. Few sign in.

A People directory, with accounts only where needed.

A person sheet with what that person holds and the actions on them, sample data.

A Person holds assets. A Member signs in.

Every Member is a Person. Few People are Members.

  1. A Person holds

    Holds assets and licence seats, and can use a Request Link. No account.

    A Person and their holdings, sample data.
    Mateo AlvarezHolding
    • AST-0142MacBook Air 13″
    • AST-0150Design suite licence
    Cannot archive while holding assets
  2. A Member signs in

    An invited Person sets a password and second factor, and gets one role. Deactivation ends every session at once.

    Roles with two-factor, and ended sessions, sample data.
    AdminOperatorViewerTwo-factor on
    Mateo AlvarezMember deactivatedEvery session endedBefore the call returns

Nobody is archived while holding assets.

A leaver's assets and seats are returned or transferred first.

Ida BergHolding
  • AST-0142MacBook Air 13″
  • AST-0150Design suite licence
Cannot archive while holding assets

Three roles. Two flags. Fixed in the product.

Admin runs settings, Operator the daily work, Viewer reads. Flags only narrow.

AdminOperatorViewerApproverRequires approval
Approval policyApproverResolves toYara Mansour

Flags narrow a role. They never grant.

  • Owner cannot be removed

    The owner is an identity, not a role; it moves only by transfer.

  • No peer Admin actions

    An Admin cannot act on another Admin.

  • No promotion above your rank

    Nobody grants a role above their own.

  • History keeps every name

    A Member with recorded actions is deactivated, never deleted.

See roles and invitations in the demo.

See a Person invited, given a role and deactivated.

Yara Mansour · Confirmed receiving it03 Sep 2026
For your home: the Vaultable app