Run your organization from one console
Invite and confirm members, organize groups and collections, set policies and read the event logs, all without access to anyone's personal vault.
| Name | Role |
|---|---|
| AMAlex Morgan[email protected] | Owner |
| SNSam Naidoo[email protected] | Admin |
| JKJo Kruger[email protected] | Custom |
| LPLee Pillay[email protected] | User |
| RDRobin Dube[email protected] | User |
Owners and admins manage access. They never get the keys to anyone's personal vault.
Also in the Admin Console
Account recovery
Set a new master password for an enrolled member who forgot theirs (Enterprise).
Import and export
Import shared credentials into collections, and export the organization's vault.
Reports
Find weak, reused and exposed passwords in shared collections.
Public API
Manage members, groups, collections and policies, and read event logs (Teams and Enterprise).
Billing
Seats, the card on file and receipts, or the license on a self-hosted server.
Fingerprint phrases
Compare a phrase over the phone before confirming someone, to rule out a man in the middle.
How it works
Members
Invite, confirm, revoke
Invite people by email with a role and their collections or groups. Confirm them after comparing fingerprint phrases, which hands them the organization's key. Revoke access to suspend someone, and remove people who leave.
- Roles: Owner, Admin, User and custom roles (Enterprise)
- Bulk-confirm several people at once
- Members keep their own account and personal vault
| Name | Role |
|---|---|
| AMAlex Morgan[email protected] | Owner |
| SNSam Naidoo[email protected] | Admin |
| JKJo Kruger[email protected] | Custom |
| LPLee Pillay[email protected] | User |
| RDRobin Dube[email protected] | User |
Policies (Enterprise)
The same rules for everyone
Require two-step login, set master password requirements and password generator rules, keep members in a single organization, enable account recovery, centralize item ownership, and limit Send, cards or unlock with PIN.
Policies in the help centerEvent logs (Teams and Enterprise)
A trail for every change
The event log records item views and changes, collection and group changes, invitations, policy edits and sign-ins, each with a time and an IP address.
The public APIFrequently asked questions
Can an admin read a member's personal vault?
No. The organization's keys only open its collections. Account recovery lets an admin set a new master password for an enrolled member; it does not reveal the old one.
Where do I find the Admin Console?
Sign in to the web vault and choose Admin Console from the product switcher or your organization's menu.
Does KeyCare Pass support SSO or SCIM?
Not yet. Both are being built: single sign-on for Enterprise, SCIM provisioning for Teams and Enterprise.
Try it with your own passwords
Create your account, then choose the plan that fits.