Skip to content

article

Sharing Secrets and Managing Access Grants

Share a single item with a specific person at view, reveal, or edit scope — with optional expiry — and revoke access anytime.

The safest way to give a teammate a password is never to send it — it's to grant them access to the item. StretchVault's sharing lets you give one person access to one item, at exactly the level they need, with an optional expiry, and revoke it whenever you want.

How grants work

A grant ties a specific person (by email) to a specific item at a chosen scope:

  • View — the person can see the item's metadata (title, username, URL, notes) but cannot reveal the secret.
  • Reveal — the person can see the metadata and reveal (decrypt) the secret when they need it.
  • Edit — the person can view, reveal, and change the item's details and secret.

Grants are per item, not per vault, so you can share exactly one credential without exposing everything around it. Every grant, and every later revoke, is recorded in the access log.

Sharing an item

  1. Open the item you want to share (from Items or inside its vault).
  2. Choose Share.
  3. Enter the recipient's email address. It must be a valid email.
  4. Select the scope — view, reveal, or edit.
  5. Optionally set an expiry date so access ends automatically.
  6. Confirm. The grant takes effect immediately and appears in the Sharing tab.

A realistic example

Meridian Studio brings on a freelance designer, Sam, for a six-week project. Sam needs the client's CMS login but nothing else. The owner opens that one Login item, chooses Share, enters Sam's email, sets scope to reveal, and sets the expiry six weeks out. Sam can now reveal that single password for the length of the project. When the project ends, the grant expires on its own — but if the engagement ends early, the owner opens the Sharing tab and revokes it in one click. At no point was the password emailed, and the access log shows exactly when Sam revealed it.

Managing existing grants

The Sharing tab lists active grants. You can filter by item or by vault to answer questions like "who can reveal this API key?" or "what has this vault shared out?"

To remove access:

  1. Open the Sharing tab.
  2. Find the grant (filter by item or vault if the list is long).
  3. Choose Revoke.
  4. Access ends immediately, and the revoke is logged.

Choosing the right scope

  • Give view when someone needs to know an account exists or reference its username/URL but should never see the secret.
  • Give reveal when someone needs to use the credential but shouldn't change it — the most common case for day-to-day access.
  • Give edit only to people who are responsible for maintaining the item, since edit includes reveal and the ability to change the secret.

Tips

  • Prefer granting reveal over revealing-and-forwarding. A grant keeps every future use accountable to the person who has it; a forwarded password doesn't.
  • Always set an expiry for contractors, temporary access, and anything time-boxed — it's the access you're most likely to forget to remove.
  • Use the Sharing tab during offboarding: filter by the departing person's grants and revoke them all.
  • Grant the narrowest scope that gets the job done. Most people need reveal, not edit.

Troubleshooting

"A valid recipient email is required." The email was blank or malformed. Enter a complete address (it must contain an @) and try again.

The recipient still can't reveal the secret. Confirm the grant scope is reveal or edit, not view — view scope intentionally cannot reveal.

"Grant not found" when revoking. The grant may already have been revoked or expired. Refresh the Sharing tab to see the current list.

FAQ

Does sharing copy the secret to the other person? No. Sharing grants permission; the secret stays encrypted in the vault and is decrypted only when the recipient reveals it.

Can I share with someone outside my organization? Sharing is designed for people in your workspace. Grant to their workspace email; if they aren't part of your organization, add them first.

What happens to a grant when the item is deleted? Deleting the item removes access to it. Revoke grants explicitly if you want to end sharing while keeping the item.

Was this helpful?

Help us improve this article

Use these controls to share whether this answer solved the issue. Feedback helps prioritize updates to StretchSuite Support.