Vault

Sharing a vault with somebody

There is no link. You add a person, from your own device, and their browser gets its own copy of the key.

On this page

A vault cannot go out on a share link, and that is not a missing feature. A link hands somebody bytes, and bytes with no key are something nobody can open. Access to a vault is given per person, one at a time, from the device of somebody who is already in it.

What the other person needs first#

  • A Nemi account.
  • Membership of the same workspace the vault is in.
  • Their own vault key, set up under Settings, Security, on their own device. Until they have one there is nothing to encrypt the key to, so they cannot be added by anybody, including us.
  1. 1

    Open the vault and unlock it

    Giving access uses the key you are holding in that tab, so it cannot be done from a locked vault.

  2. 2

    Press Members

    The panel is headed "Who can open this vault" and lists the current members, then everybody else in the workspace underneath.

  3. 3

    Press Give access next to their name

    If the button is greyed out, the line under their name says why: no vault key yet.

Who can open this vault

Sanne de VriesOwner
Mark JansenMember
Everybody else in this workspace

Listed with a Give access button each.

Ilse Bakker

No vault key yet. They have to set one up in Settings before anyone can give them a vault.

Give access
People without a vault key are listed rather than hidden, because "why can I not add Ilse" needs an answer on the screen.

What happens when you press the button is worth knowing, because it explains every rule on this page. Your browser takes the vault key it is already holding and encrypts it again, this time so that only their key can open it. We store that result and route it to them. We cannot open it, and there is no step anywhere in the process where we could add ourselves.

What a workspace member who is not in the vault sees#

They see that the folder exists and that it is a vault. They do not see the file names, the contents, the file count, the sizes, or who else is a member. Opening it tells them so, and tells them the only way in is somebody who is already a member doing it from their device. Support cannot do it for them, and neither can a workspace owner who is not in the vault.

Who can do what#

ActionWho
Open the vault and read everything in itAny vault member
Add filesAny vault member who can also edit the workspace
Give somebody else accessAny vault member who can edit the workspace, from a tab where the vault is unlocked
Remove another memberThe vault owner
Remove yourselfYou, whenever you like
Turn the vault back into an ordinary folderThe vault owner, and only while it is empty

Your workspace role still applies on top of this: a viewer in the workspace can open a vault they are a member of, but cannot add to it.

Removing somebody#

Removing a member stops them opening anything in the vault from that point on. It does not undo what they already saw. If they unlocked the vault even once, they had the key, and any file they downloaded is on their machine. No software reaches into somebody's laptop, and we will not pretend otherwise.

The last member of a vault cannot be removed, and the screen refuses rather than asking twice. Their key is the only copy there is, so removing them would turn the files into bytes nobody on earth can open. Empty the vault first if that is what you actually want.

Things that will not work, and what to do instead#

Can a client without an account open one file from my vault?

No. Download the file, put the copy in an ordinary folder, and send that as a normal share link with a password and an expiry.

Can somebody send files into my vault through an upload link, a form or a room?

No. A guest has no vault key, so anything they sent would arrive unencrypted in a folder that claims to be unreadable. Those uploads are refused, with a message asking them to go back to whoever sent the link. See Upload links.

Can I move a file out of the vault into a shared folder?

Not directly, because outside the vault nothing holds the key to it. Download it, upload the copy where you want it, then delete it from the vault.

Can I copy or duplicate a vault file?

Not on our side. The copy would be bytes with no key attached, which nothing could ever open. Download it and add it again.

Related

Still stuck? Email support@nemilab.com and tell us what you were trying to do.