Organization File Vault for employees
Publish an employee File Vault that is separate from the Cloud Portal, with per-person encrypted files and optional password-protected share links.
Organization File Vault for employees
Organization File Vault lets people who must not use the Trustity Cloud Portal upload, download, and share encrypted files under your tenant. Each employee signs in on a dedicated vault login, sees only files they uploaded, and never receives TCP roles, policies, devices, or audit pages.
This article is for organization owners and administrators who already have File Vault entitled. It is not a substitute for Personal Vault, which remains a per-user area inside the Cloud Portal.
What this is for
Use Organization File Vault when:
- Employees need a simple encrypted drop for work files
- Those people should not become Cloud Portal users
- Sharing must stay short-lived and optionally password-protected
- Administrators still need a list of employee files for the organization
Do not use it as a general document-management system, as a replacement for classified collaboration platforms, or as a way to store credentials and unlock material.
Isolation model
Trustity keeps three boundaries in this feature:
| Boundary | What happens |
|---|---|
| Tenant | Employee records, files, and share links are stored against the organization that published the vault. Another customer’s administrators and employees cannot open them. |
| Employee | An employee session lists, decrypts, shares, and deletes only rows tagged with that employee id. Another employee in the same company does not see those files. |
| Cloud Portal | Vault employees are not organization members. Their login cannot open /dashboard. A work email that already belongs to a TCP user cannot be reused for the employee vault. |
Files are encrypted in the browser before upload. Share 1 stays with the file record; Share 2 and Share 3 stay in Trustity’s split-key storage. Trustity cannot reconstruct a file without those shares. A published share link is still a capability URL: anyone who has the link (and the optional password) can download that one file until the link expires or hits its download limit.
Before you start
- File Vault is entitled for the organization
- Owner or Admin access with permission to write Vault policy
- A work email for each employee that is not already a TCP owner or team member
- An approved classification for files that may enter the vault
- The employee login URL from Security Policies → Vault / PAM / IPS after you publish
Publish the employee vault
- Sign in to the Cloud Portal for the correct organization.
- Open Security Policies and select the Vault / PAM / IPS tab.
- In Publish vault to employees, turn the publish control on and wait for the success confirmation.
- Refresh the page and confirm the control stays on. If it turns off, the publish flag did not persist - do not send the login link yet.
- Copy the Employee login link. It points at
/org-vault/loginon the Cloud Portal host (trustity.io), not at trustity.co. - Optional: upload an organization logo. Employees see Trustity’s mark plus your logo. Removing the logo restores Trustity-only branding.
Unpublishing stops employee sign-in. Existing encrypted files remain in the organization until an administrator or the owning employee deletes them.
Invite employees
Leave the initial password empty to send an invitation email. The employee sets a password from the invite link and lands on the employee vault, not the Cloud Portal.
If you must create a temporary password instead:
- Enter the work email.
- Set a password of at least 10 characters.
- Create the employee.
- Send the password through an approved channel.
- Confirm they must change it on first sign-in.
Use Resend invite when the email did not arrive. Disable an employee when they leave. Disabled accounts cannot sign in; their files remain listed for administrators until deleted.
Employee workflow
- Open the employee login link your administrator provided.
- Sign in with work email and password.
- Set a new password when prompted.
- Upload an approved file and wait for the encrypted-upload confirmation.
- Use Decrypt only for files you uploaded.
- Use Share when a recipient needs a time-limited link. Add a share password when the file is sensitive.
- Send the link (and the password, separately) through approved channels.
Employees cannot open Cloud Portal navigation, other employees’ files, or another organization’s vault.
Administrator visibility
Owners and Admins can see employee file names, sizes, and owning employee in:
- Security Policies → Publish vault to employees
- Personal Vault, in the Employee vault files table
Decrypt in those views is an organization-admin action for files that belong to this tenant’s employee vault. It does not open another customer’s files, and it does not grant the employee TCP access.
Personal Vault files owned by Cloud Portal users stay on the owner’s account. They are not mixed into the employee list.
Sharing limits and expectations
Share duration and download counts follow the same Vault policy maxima used for Personal Vault. Prefer the shortest expiry and the fewest downloads that meet the business need. A password on the share is checked before the recipient can decrypt. Deleting a file or disabling an employee does not erase copies a recipient already downloaded.
Verify
- Publish stays on after a full page refresh
- The employee login shows Trustity branding and, when configured, the organization logo
- A TCP user cannot sign in at
/org-vault/login - An employee cannot open
/dashboard - Employee A cannot list or decrypt Employee B’s files
- An administrator in this tenant can see the employee file list and cannot see another tenant’s vault
- A share link without the password fails when a password was set
- An expired or exhausted link no longer downloads
Roll back
Turn Publish vault to employees off to close the employee login. Disable individual employees to revoke their sign-in. Delete files only after retention review. Invite emails and share links already sent remain a business risk until they expire - treat that as an incident if the audience was wrong.
Troubleshooting
| Symptom | Likely cause | What to do |
|---|---|---|
| Employee sees “organization vault is not published” | Publish flag off or not persisted | Publish again, refresh, then retry sign-in |
| Invite email missing | Mail delivery or existing Auth user | Resend invite; confirm the address is not a TCP user |
| Employee bounced to Cloud Portal login | Wrong URL or TCP account | Use /org-vault/login; do not reuse a TCP email |
| Logo does not appear | SQL for vault_portal_logo_url not applied, or unpublished vault | Confirm publish, re-upload the logo, hard-refresh |
| Decrypt fails for an admin | Missing key shares or file not tagged as an employee file | Confirm the row is under Employee vault files, not Personal Vault |
