Share Vault entries and revoke shares

Sharing gives selected people a separately encrypted copy of an entry. Recipients open it in their own Vault under Shared items. A share covers the whole content including password, websites, and note; individual fields can't be excluded from a share.

Prerequisites
  • You're signed in to Project Manager and have access to the Vault module.
  • Your Vault is unlocked. Recipients belong to the current organization and have set up their own Vault.

Share an entry

Open one of your own entries so its content is decrypted.

  1. Choose Share from the entry menu or the detail pane.
  2. Search for the members you want and select one or more people.
  3. Check the recipient list and confirm the selection.
  4. Note any mention of skipped recipients. Without set-up sharing keys, that person can't receive a copy.
  5. Check under Shared items who the entry was shared with.
Screenshot coming: Share dialog with member search and selected sample people

Open a received share

Unlock your own Vault and switch to Shared items. Open the entry shared with you, check the sender, and copy the values you need. The view shows received shares and entries you've shared together. Received shares have no edit or delete action here; the sender manages access.

Screenshot coming: Shared items with a received share and detail pane; password hidden

Manage recipients

Under Shared items, open an entry you've shared. Manage recipients shows the existing people; you can select more or deselect existing ones. To add someone, Vault still needs the decryptable original entry. The Revoke access action removes the share for a single person after confirmation. Revoke all shares removes this entry's shares for every recipient shown.

Screenshot coming: An entry you shared, with recipient list, Manage recipients, and revoke actions

Re-share after a change

A share is a copy of the content at the time of sharing. Editing the original doesn't automatically update existing shares. After a relevant change, revoke the affected shares and re-share the updated original entry. Re-confirming already-selected recipients unchanged doesn't send a new version.

Understand the limits of revoking

Revoking removes the stored share, but it can't retrieve credentials that were already read, copied, or saved elsewhere. It also doesn't change the password at the actual service. If an account should no longer be usable, change its password there too. Moving or deleting the original entry is not a substitute for revoking.

What information is shared?

The entry's content is encrypted in the browser for each recipient. Password and note live inside that encrypted content. Name, login, and first website are additionally stored as readable share metadata, as are sender, recipient, and timestamp. Folders aren't shared as a shared folder. Recipient selection offers members of the current organization; existing shares are tied to user accounts.

Common pitfalls

  • A person is skipped

    Have that person set up and unlock their own Vault. Try sharing again afterward and check the recipient list. A skipped recipient hasn't gained access from that attempt.

  • Original deleted, share still there

    Shared copies persist even after the original is permanently deleted. You can still revoke existing shares; new recipients can't be added without a decryptable original.

Frequently asked questions

Do recipients automatically get later password changes?

No. Revoke the old share and re-share the updated entry.

Can I share just the password without the note?

The dialog shares the entire entry content and offers no field selection. Check the note before sharing, or create a separate entry with just what's needed.

Can I share an entire folder?

The existing sharing flow applies to individual entries. Folder assignment doesn't set up a shared grant.

Keep reading

Couldn't find your answer, or still stuck?

Go to support

Last reviewed on 2026-09-27