Administer in Obsidian
Manage users, vault access, the basic audit trail, recovery, and organization settings without a web admin panel.
Self-Hosted Community Edition: administration in Obsidian
Community Edition has no hosted web admin panel. Administrators manage the organization from the VaultGuard Sync plugin connected to their own server.
Open organization administration
- Open the Obsidian vault bound to the Community Edition server.
- Sign in with an organization owner or administrator account.
- Open the command palette.
- Run VaultGuard Sync: Manage organization.
The modal provides the Community administration surfaces supported by the connected server:
- Users
- Vault access
- Audit Log
- Recovery
- Org settings
If the command is missing, confirm the plugin is connected and the signed-in account has an administrator role.
Invite and manage users
Use Users to invite a member through the SES sender configured by your operator. Give the narrowest organization role needed. Then use Vault access to add the person to specific vaults and assign a vault role.
The AWS operator owns mail delivery. If an invitation does not arrive, they must inspect SES configuration and service logs; there is no managed Cloud support console for the deployment.
Manage vault access and path rules
- Set a conservative default role for the vault.
- Add only the intended members.
- Choose Viewer, Editor, or Admin for each member.
- Add path rules for genuine folder or file exceptions.
- Test with a disposable note and a non-admin account.
Right-click a file or folder to view, explain, or—when authorized—set its permissions. The desktop permissions graph can help explain how rules combine.
Review the basic audit trail
Community Edition records the basic audit events supplied by its server. Use the Audit Log tab for authentication, file, sync, permission, and administrative review.
Hosted advanced-audit dashboards, anomaly alerts, broad reports, and CSV export are Cloud features and are not available. Retention and storage remain the self-hoster's operational responsibility.
Redact IP addresses, device strings, IDs, and file paths before sharing logs or screenshots.
Recovery and offboarding
Use Recovery to perform supported version/deletion recovery and re-encryption workflows. Remove departing users from vaults, revoke their organization access when appropriate, and confirm subsequent denied events.
Revocation does not retract a copy that was legitimately exported while the person had access. Your operator must also maintain and test AWS backups; the plugin recovery UI is not a replacement for infrastructure disaster recovery.
Organization settings
Use Org settings for policies exposed by Community Edition. Coordinate changes that affect retention, keys, email, domains, availability, or service resources with the AWS operator. Do not change infrastructure assumptions in the plugin without updating the server deployment.
Feature differences to expect
| Surface | Community Edition behavior |
|---|---|
| Hosted web admin | Not available. Use the Obsidian modal. |
| Share links | Not available. Collaborate through vault membership and permissions. |
| Billing | Not present; your organization pays its AWS costs directly. |
| Advanced audit | Not available; use the basic audit trail. |
| Backups and uptime | Operated and tested by your organization. |
| Updates | Planned and applied by your infrastructure operator. |
Administrator checklist
- Require strong, unique accounts and two-factor authentication.
- Keep recovery material outside the vault it protects.
- Verify SES before inviting production users.
- Use narrow roles and test permission changes.
- Review denied audit events.
- Test state, data, key, and recovery procedures before production use.
- Apply server and plugin security updates through a reviewed change process.
- Never send Terraform state, AWS credentials, secrets, or protected content to a public support channel.