Growth plan and above. Off by default — enable under Settings → Modules.
Client credentials end up somewhere. The vault means that somewhere isn’t a
chat message or a spreadsheet.
Storing a credential
Add it against the project it belongs to. Values are encrypted at rest and only
decrypted when someone with access views them.
Access is logged
Every view is recorded — who opened which credential and when. That log is
visible on the credential itself.
Viewing a credential can require a one-time code sent to you, so a borrowed
session isn’t enough to read secrets.
Vault contents are deliberately never reachable by connected AI
assistants or third-party integrations, whatever access they’ve been granted.
That restriction can’t be configured away.
Leaving
When someone leaves, remove their project access — vault access follows project
access, so there’s no separate list to forget.