Documentation home
VaultGuard Sync (Cloud)

Cloud administration

Use the hosted web panel to manage users, vaults, permissions, audit activity, recovery, and billing.

15 min readManaged service · no deployment commandsView source

VaultGuard Sync (Cloud): administrator manual

Cloud administrators work in the hosted panel at admin.vaultguard.cloud. VaultGuard operates the service infrastructure. Your responsibility is to manage people, vaults, access, security policy, billing, and recovery—not servers.

The administration model

VaultGuard separates three decisions:

  1. Organization role controls organization-wide administration.
  2. Vault membership and vault role control entry to one vault.
  3. Path-specific permission rules control actions within that vault.

Adding somebody to the organization does not automatically grant access to every vault. Start broad decisions at the vault level, then add folder or file rules only when the vault role is not precise enough.

Invite a user

  1. Open Users in the web admin panel.
  2. Choose Invite User.
  3. Enter the member's email and display name.
  4. Give the narrowest organization role they need.
  5. Send the invitation.
  6. Open the intended vault and add the new user as a member.
  7. Assign the vault role: Viewer, Editor, or Admin as appropriate.

Use organization-admin roles sparingly. Most people need a vault role, not organization-wide control.

Create and configure a vault

  1. Open Vaults and choose Create vault.
  2. Give the vault a clear team or knowledge-domain name.
  3. Set a conservative default role. Viewer is appropriate when new members should not edit by default.
  4. Add a description explaining what belongs in the vault.
  5. Review excluded paths so device-specific workspace and cache files are not synchronized unintentionally.
  6. Allowlist only Obsidian plugins whose synced files and purpose you trust.

Every vault is an independent authorization boundary. The same path in two vaults refers to two different protected objects.

Grant file and folder access

Use this order:

  1. Set the vault's default role.
  2. Add the person as a vault member.
  3. Set their vault role.
  4. Add path-specific rules only for exceptions.
  5. Verify the result with a disposable note and a test account.

Path patterns use * for one path segment and ** recursively. A more specific path can override a broader rule. At equal specificity, a denial wins over an allowance. Organization administrators normally bypass file rules unless administrator restrictions are enabled for the organization.

For worked examples, see Permissions and share links.

Review audit activity

Open a vault, then open its Audit Log. Review:

  • successful and denied authentication;
  • file read, write, sync, history, and delete events;
  • permission and membership changes;
  • share-link actions;
  • AI or agent actions that cross the governed tool boundary; and
  • administrative and recovery actions.

Audit data covers server-observed operations. It is not a recording of every local keystroke or every local file read. Before sharing an audit screenshot, redact IP addresses, device strings, user IDs, organization IDs, file paths, and other private metadata.

Handle offboarding

  1. Remove the user from affected vaults or deactivate the organization user.
  2. Confirm their renewable sessions and key leases are revoked.
  3. Start re-encryption when the recovery/offboarding workflow calls for it.
  4. Review the audit log for the removal and subsequent denied activity.
  5. Reassign ownership of operational notes and processes.

Revocation blocks future authorized access after the relevant session or lease boundary. It cannot erase plaintext a person legitimately exported or copied before access was removed.

Recovery and deleted files

Use a vault's recovery surfaces to inspect deleted files and retained versions. Restore only after confirming the vault, path, version, and intended current state. Restores are permission-checked and audited.

Recovery depends on retained versions, available key material, permissions, and the managed backup program. It is not a guarantee that every historical state can always be recovered.

Organization security checklist

  • Require two-factor authentication for administrators.
  • Store recovery codes outside the protected vault.
  • Remove demonstration or shared passwords before real use.
  • Review pending invitations and revoke unexpected ones.
  • Use the narrowest organization and vault roles.
  • Test sensitive permission changes with a disposable note.
  • Review denied audit events and alerts regularly.
  • Keep payment, invoice, recovery, and authentication details out of public screenshots.

Billing and support

The hosted Billing page is the only normal place to manage the Cloud plan, seat quantity, payment method, invoices, and the Stripe customer portal. No local configuration or deployment command is involved.

For account or service assistance, contact support@vaultguard.cloud. Do not include a password, recovery code, private note, or raw authentication token.