Support guide5 min readUpdated 2026-06-01

Understanding StretchVault permissions

A trust-focused overview of role-based access, vault records, and audit posture.

Vault access is never public

Private files, credentials, sensitive documents, and protected records must stay inside authenticated, role-aware workspace surfaces.

Use least privilege

Workspace operators should assign access based on the smallest set of app and record permissions needed for each role.

Evidence expectations

Permission changes, file access, and vault operations should produce audit evidence before the feature is considered production-ready.