Skip to content
Vault & Access

Secrets your agents can use — safely.

An encrypted vault for passwords, OTP codes and tokens. Share a credential with an agent only when it needs one, for only as long as it needs it — with every access logged and revocable in one click.

hq.plantel.ai
Plantel Vault — least-privilege access, fully audited.
Least privilege

The power of shared credentials, without the risk.

Two worlds, never mixed

What the company gave you, and what is yours.

The vault splits cleanly into two first-class worlds: "Granted to you" — every credential and card the company has assigned you — and "Your vault," your own private secrets. They never blend into one list, and a single search reaches across both. No other password manager separates company-assigned from personal this way.

  • "Granted to you" vs "Your vault" as separate worlds
  • One search spans both, with cross-world hints
  • Different capabilities per world — assigned items stay the company’s
hq.plantel.ai
Time-bound shares

Grant access for a task, not forever.

Share a credential with a specific agent or person, scoped to a purpose and a time window. When the window closes, access auto-revokes — no stale grants, no forgotten keys.

  • Per-agent, per-purpose grants
  • Time-bound shares with auto-revoke
  • Revoke everything in one click
hq.plantel.ai
Card grants, no number shown

Hand someone a card without handing over the number.

Assign a company card to a person or agent and they can pay with it — but the card number is never transmitted to their screen at all. It is fill-only and audited per use, with the owner notified on every charge. Revoke or rotate at any moment as the remedy. Other managers show the recipient the full card; we structurally never reveal it.

  • PAN never transmitted to the grantee
  • Fill-only, audited and owner-notified per use
  • Revoke + rotate as the documented remedy
hq.plantel.ai
OTP + autofill

Authenticator codes that fill themselves in.

OTP codes live in the vault and autofill at the OS layer through the Plantel Browser — a native autofill provider, not a fragile extension — or approve on your phone with biometric push-approval. Agents and humans get through 2FA without copy-pasting.

  • OTP codes in the vault
  • Native OS-layer browser autofill
  • Biometric push-approval on your phone for high-risk actions (Face ID / Touch ID)
hq.plantel.ai
Fully audited

Every access leaves a trail you can prove.

Each time a credential is used, it is logged to a tamper-evident, tenant-scoped audit trail — who, what, when, and why — alongside the rest of Plantel. And on every granted fill, the credential owner gets a per-use notification, so no secret is ever used silently.

  • Per-access audit log, scoped to your tenant
  • Per-use owner notification on every granted fill
  • Policy enforcement per agent
hq.plantel.ai
Built for an org where humans and agents share one tenant

The safety details that make shared secrets safe.

Least privilege is only real if revoke has teeth and a share can’t be mis-addressed. Here is how the vault enforces that.

You can only share with your own people

There is no free-text email field. Every recipient is resolved from your tenant’s member roster, so a secret can’t be mis-addressed to an outside address — ever. All three major password managers let you share to an arbitrary email; we don’t allow it by design.

Grants are references, not copies

A grant points at the credential; it never duplicates or discloses it. Revoke instantly kills the recipient’s ability to decrypt — there’s no stray copy left behind in a shared folder to clean up.

Revoke with database-level teeth

Grant lifetime is tied to org membership at the database layer: a foreign-key cascade, an owner-edge integrity check, and a membership-deletion trigger as a backstop. When someone leaves the company, their access is gone — not pending a cleanup job.

The owner sees every use

Each granted credential or card fires a notification to its owner on every use — a bell with a deep link to the exact item. No password manager we benchmark notifies the sharer per use.

Health checks with no calls home

Credential health — weak, reused, stale — is evaluated locally, with no external lookups. Other managers’ dashboards phone out to do this; ours never leaves your tenant.

Encrypted, with the right boundaries stated

Passwords, OTP codes, tokens and cards are encrypted at rest with AES-256-GCM. We’re plain about where convenience crypto ends and end-to-end begins, rather than over-claiming — security you can audit, not just trust.

Let agents act — without handing over the keys.

Encrypted, least-privilege, auto-revoking, fully audited — in every seat.