Docs
Team vaults
Members, roles, groups, reviews and skill access control.
A Team Vault adds membership and governance on top of the same skill model. An account can belong to one organization vault (plus its own Personal Vault, which every user keeps).
Members and roles
Owners and admins invite members by email from Team. Each member has a role:
| Role | What it adds |
|---|---|
| Member | Uses accessible skills, manages their own drafts and handles reviews assigned to them. |
| Admin | Manages members, groups, reviews, access, activity and vault content; sees seat capacity but not financial details. |
| Owner | Everything, including ownership, workspace settings, licenses, subscriptions and invoices. |
The Team administration page and organization Activity log are private to owners and admins. Admins can also see used and available capacity. Only owners can buy, change or cancel licenses and see prices, invoices or payment details. Members see a short guidance message instead of those administrative surfaces. This does not remove a member's access to their own skills, drafts, access requests, groups, keys or assigned reviews.
Owners and admins can assign member or admin. Only an existing owner can
promote, demote or remove another owner, and the vault must always retain at
least one owner. Promoting an owner requires typing the recipient's exact email
after a privilege warning; the change is audited and all owners are notified.
SSO group mappings can never grant the owner role.
Invitations are accepted automatically when the invitee signs in with the invited email. A pending invitation reserves one licensed seat for 14 days; revoking or expiring it releases the seat. See Billing & seats for Team Free capacity, paid seats, proration and cancellation.
Groups
Groups organize members for access control. Owners/admins create them from Team → Groups and use them as the subject of skill access grants, so access follows the group instead of individual people.
In Enterprise Vaults, groups can also be managed externally by your identity provider: when Enterprise SSO is enabled, the groups asserted by your IdP appear in the vault automatically and stay in sync at every sign-in.
Reviewer assignments
Reviewers approve submitted versions before they become Ready. Owners/admins assign a reviewer to the whole vault, to a collection or to a single skill.
Reviewer scope is not the same as admin. A scoped reviewer can approve or reject assigned reviews, but that scope adds no content-management rights. Every member can import skills, manage and submit their own drafts; owners/admins manage other people's content, sources, manual collections and destructive actions.
Blocked scans, failed scans and rejected Drafts appear in Reviews → Needs changes for the Draft author, owner/admin and assigned reviewers. Only the Draft author or owner/admin receives correction/retry controls; a reviewer sees Waiting for author and the exact report. Read-only items do not increase the reviewer's sidebar badge. A rejected decision also stays in Review history until the package is corrected.
Organization security criteria
Owners and admins can add vault-specific scan requirements from Settings → Security. Criteria are visible to every member and can either create a watch finding or block review submission. Each save creates an immutable revision, so pending reviews keep the exact policy snapshot used by their scan. See Security policies for effects, limits and timing.
Skill access
Who can see and install a skill is decided per skill:
- Discovery controls whether the skill is listed for the whole vault or kept private to the people who already have access.
- Grants give access to a user, a group or the whole vault.
- Access requests let members (and their agents) ask for access to a skill they can see but not use; admins decide the request from Team → Access requests.
Every member can import skills, work on their own drafts and submit them for review. Owners and admins manage the rest of the content surface: other people's skills, sources, manual collections and collection membership. Members use approved skills they can access and request access when discovery allows it.
Activity log
Settings → Activity shows what has happened in the vault as a readable feed — each entry names the skill, collection, key or member involved rather than a raw event code. It is available to Team and Enterprise owners/admins and shows who performed each action, so the log doubles as an accountability trail. Members cannot browse or export the organization audit history.
Use the filter chips to narrow the feed to Skills, Reviews, Access or Keys, the date range and actor pickers to focus on a period or a specific person, and Load more to page further back. Download CSV exports the full filtered log for external records or a SIEM. Personal Vaults show an upgrade message instead of organization audit history.