> For the complete documentation index, see [llms.txt](https://docs.termius.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.termius.com/team-collaboration/team-vaults.md).

# Team vaults

## Overview

Team vaults are the top-level organizational unit in Termius. A vault stores data and controls which team members can access it.

Each vault is encrypted with a unique key. Members can access a vault only after the owner grants them permissions.

To start collaborating in Termius invite your team members. Learn more in [Team Management](/team-collaboration/team-management.md).

Termius includes one non-shared **Personal vault** per user, and one default **Team vault** shared with all team members. Additional **custom team vaults** can be created and shared with specific team members.

Members can have different permissions in different vaults:

* **Can edit:** Allows creating, updating, and deleting data within the vault; adding or removing members.
* **Can view:** Allows viewing data, initiating connections to hosts, and running snippets. Data cannot be modified.

## Create vaults

### Define the vault structure

Whether you separate access by projects, clients, environments, departments, or other criteria, vaults can be configured for that use case.

A few examples of how different teams organize their data using vaults:

{% tabs %}
{% tab title="Small startup" %}

<figure><img src="/files/IzIpODmocHdAGJ0dMlzh" alt=""><figcaption></figcaption></figure>

The team structure is flat, with a small number of members and a high level of trust.

* **Vaults:** A single Team vault shared with all members
* **Groups:** Prod, Staging, and Development
  {% endtab %}

{% tab title="Consulting company" %}

<figure><img src="/files/rE9EEYMArMMq4m2eNiyV" alt=""><figcaption></figcaption></figure>

The team structure is client-based, where small teams or individuals work with several clients.

* **Vaults:** Each client has a separate vault. Team members are added and removed from vaults depending on the projects and clients they work with
* **Groups** are used to separate environments within the client's vault
  {% endtab %}

{% tab title="Mid-size Business" %}

<figure><img src="/files/XtuvBMkqPHCIClYbU2bE" alt=""><figcaption></figcaption></figure>

The team structure is functional-based, with dedicated DevOps, Developers, and QA teams.

* **Vaults**: Vaults separate **Production**, **Development**, and **Staging** environments. DevOps has access to all three. Developers can access Staging and Dev, while QA can only access Staging
* **Groups**: Within each vault, there are groups for different resource types, such as **Database Servers (DB)**, **Web Servers**, and **Cache**
  {% endtab %}

{% tab title="Enterprise" %}

<figure><img src="/files/I2H1E8RbXLMGyR4ucOfh" alt=""><figcaption></figcaption></figure>

The team structure is functional and location-based, with infrastructure distributed across multiple regions. Access is organized by region or data center.

* **Vaults**: Organized by region and team. For example, **US-East-DevOps**, **US-East-Support**, **US-West-DevOps**, **EU-Central-DevOps**
* Each team structures groups to match their operational context. A data center team, for example, might organize by physical location: building, floor, room, and rack
  {% endtab %}
  {% endtabs %}

### Add custom team vaults

{% tabs %}
{% tab title="Desktop " %}

1. To create a new vault, you have several options:
   1. Open `Settings` > `Vaults` > `Add vault`

      <figure><img src="/files/548A7yjGjKJE7unEP7bz" alt=""><figcaption></figcaption></figure>
   2. Click the chevron on the `Vault` tab and click `Add vault`

      <figure><img src="/files/mOPMW2uKFh9byLIujUbi" alt=""><figcaption></figcaption></figure>
   3. Click the `Vault selector` on the entity edit form and click `Add vault`

      <figure><img src="/files/PcCSu7QodMV2DyZZ8m11" alt=""><figcaption></figcaption></figure>
2. Name it according to your vault structure

   <figure><img src="/files/3AwSU06fpTGOMsnkkAEJ" alt=""><figcaption></figcaption></figure>
3. Add members to this vault and set their roles

   <figure><img src="/files/MDuUmqSG41aIfX11cv75" alt=""><figcaption></figcaption></figure>
4. Click `Save changes`
   {% endtab %}
   {% endtabs %}

### Add data to vaults

{% tabs %}
{% tab title="Desktop" %}

1. To add data to a vault, you have several options:
   1. Open entity details and click the `vault selector` to choose the vault to move it to

      <figure><img src="/files/e12avvjRAn3jnCczlE4C" alt=""><figcaption></figcaption></figure>
   2. Right-click on an entity you want to move or copy, then select `Move to` or `Copy to` and select the destination vault

      <figure><img src="/files/Vkc6kunXQO3LdBdW1KwP" alt=""><figcaption></figcaption></figure>
2. Choose where you want to store credentials for hosts and groups

   <figure><img src="/files/1we6UIB9DSAVkxjZaWJ4" alt=""><figcaption></figcaption></figure>

* **Personal vault** — the host or group will be added to a vault **without credentials**. Each member will need to use their own set of credentials saved in their Personal vault
* **Selected vault —** the host will be added to a vault **with credentials**. Each member will connect using the same **shared credentials**. Once the entity is saved to this vault, it is instantly accessible by all team members with access

3. Once an entity is moved or copied, it is immediately available to all members of the selected vault

If the selected entities have linked entities, choose how to handle them:

* **Copy** — all linked entities are copied to the selected vault and also remain in the original vault
* **Move** — all linked entities are moved to the selected vault, removed from the original vault, and unlinked from all other entities in the original vault

<figure><img src="/files/N8205IDjOwFdE58eANMw" alt=""><figcaption></figcaption></figure>
{% endtab %}
{% endtabs %}

## Edit vaults

### Change vault name

{% tabs %}
{% tab title="Desktop" %}

1. Open `Settings` > `Vaults` , or click the chevron on the `Vault` tab and click `Manage vaults`

   <figure><img src="/files/6MCCYEE4TnsA1MXmcJey" alt=""><figcaption></figcaption></figure>
2. Select a `vault` you want to edit. Personal and Team vaults have default names that can't be changed

   <figure><img src="/files/3EH96TwG4fGUsULihbxf" alt=""><figcaption></figcaption></figure>
3. Click on the vault name and change it
4. Click `Save changes`
   {% endtab %}
   {% endtabs %}

### Add members

{% tabs %}
{% tab title="Desktop" %}

1. Open `Settings` > `Vaults` , or click the chevron on the `Vault` tab and click `Manage vaults`

   <figure><img src="/files/6MCCYEE4TnsA1MXmcJey" alt=""><figcaption></figcaption></figure>
2. Select a `vault` you want to edit

   <figure><img src="/files/3EH96TwG4fGUsULihbxf" alt=""><figcaption></figcaption></figure>
3. Add team members to this vault from your team and set their roles

   <figure><img src="/files/YDHtLfvtyHCjJIH12Z1C" alt=""><figcaption></figcaption></figure>
4. Click `Save changes`
   {% endtab %}
   {% endtabs %}

### Change member permissions

{% tabs %}
{% tab title="Desktop" %}

1. Open `Settings` > `Vaults` , or click the chevron on the `Vault` tab and click `Manage vaults`

   <figure><img src="/files/6MCCYEE4TnsA1MXmcJey" alt=""><figcaption></figcaption></figure>
2. Select a `vault` you want to edit

   <figure><img src="/files/3EH96TwG4fGUsULihbxf" alt=""><figcaption></figcaption></figure>
3. Click the `permission picker` for the member you want to edit:

   1. **Can edit** allows the member to edit entities in the vault
   2. **Can view** allows the member to connect and run snippets, but not edit them
   3. **Remove access** allows removing a member from the vault

   <figure><img src="/files/0sUP8sYFkTXxzECcVDWW" alt=""><figcaption></figcaption></figure>
4. Click `Save changes`
   {% endtab %}

{% tab title="Account management portal" %}

1. Open the `Vaults` page on the [account management portal](https://account.termius.com/vaults)
2. Select a vault where you want to change a permission

   <figure><img src="/files/8OQhzZQk6AXEs7zkgUTR" alt=""><figcaption></figcaption></figure>
3. Click the `permission picker` for the member you want to edit:

   <figure><img src="/files/5sHEFyl8gytQIWsc1YPf" alt=""><figcaption></figcaption></figure>

   1. **Can edit** allows the member to edit entities in the vault
   2. **Can view** allows the member to connect and run snippets, but not edit them
4. Save changes
   {% endtab %}
   {% endtabs %}

### Remove member from vault

{% tabs %}
{% tab title="Desktop" %}

1. Open `Settings` > `Vaults` , or click the chevron on the `Vault` tab and click `Manage vaults`

   <figure><img src="/files/6MCCYEE4TnsA1MXmcJey" alt=""><figcaption></figcaption></figure>
2. Select a `vault` you want to edit

   <figure><img src="/files/3EH96TwG4fGUsULihbxf" alt=""><figcaption></figcaption></figure>
3. Click the `permission picker` for the member you want to remove and select `remove access`

   <figure><img src="/files/tviDHFqUeKaib2T0wjMf" alt=""><figcaption></figcaption></figure>
4. Save changes
   {% endtab %}
   {% endtabs %}

## Security

Vaults are the most secure way to share sensitive information across the team. Each vault is encrypted with a unique key, so only you and your team members with access to that vault can see and use its data.

New members cannot access a vault until the owner grants access and sets their permissions.

For more information about encryption and security, see [Encryption overview](/security/encryption-overview.md).


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.termius.com/team-collaboration/team-vaults.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
