Log inGet Vallkey

Search the help center, features, guides and more.

Organizations and the admin console

Admin control, without access for anyone else.

An organization has keys of its own, held only by its admins' devices. Who's in it, in which group, with which vault and under which policies is signed with those keys, and every member's device checks the signature before it acts on anything.

A company's members in the Vallkey admin console, each with a role and their key's fingerprint.

How it works

Organizations and the admin console, step by step.

  1. Make the organization

    In the web vault. You're its first owner, and it starts with 14 days of everything. Invite people by email address: each invitation shows the organization's fingerprint.

  2. Make groups, and grant vaults

    Give a vault to a group or a person, to edit, to view, or only to fill. People get their vaults as soon as an admin's device next syncs.

  3. Set the rules

    Policies for master password strength, locking, exports, single sign-on and Travel Mode. They're signed like everything else, so the server can't relax them.

The details

What careful people ask.

Three roles

Owners do everything, and make or remove admins. Admins invite and remove people, make groups and vaults, grant access and set policies. Members use the vaults they're given.

Fill only

Someone with fill-only access can sign in with a login and never see, copy or export its password. It's kept by the apps, not by the encryption: use it to keep secrets out of sight, not out of reach.

Removing someone

Each vault they had gets a new key, with every item encrypted again. Removing an admin also gives the organization itself a new root key.

Never shared outside

An organization's vault names only the organization's own members, which both the apps and the server check. It can't be shared the way a person's vault can.

The server holds no say

In 2026, researchers showed a malicious server changing who was in an organization at several password managers. Here the server stores and passes along a signed roster, and can't write one.

What to know

Admins can open every vault of the organization: that's what lets them grant access. Policies are kept by the apps, so they protect a company from mistakes, not from a member determined to get around their own app.

Availability

Where you get it.

Plans
Teams and Business
Platforms
Console in the web vault; organization vaults in every app

Questions

Where do admins run it?

In the web vault's console. The phone, Mac and desktop apps and the browser extension show an organization's vaults and keep its policies.

What happens when a trial or a plan ends?

Nothing is taken away. Everyone keeps the vaults they have, and the organization can't invite people or make vaults until an owner buys a plan.

Can an owner be locked out?

The last owner can't leave or be removed, and neither single sign-on nor your identity provider can take an owner away.

Your passwords. Your keys. Your price.

Free forever for unlimited passwords and devices. No card needed.