Members
A vault has one owner and any number of members. A vault with members is an organization’s vault; everything below applies to it.
Owner
The owner is the wallet that owns the vault. The owner holds every scope by virtue of the key and signs every member’s grant. The owner is never a member row; rosters show the owner first, marked as owner.
Members
Each member has:
| Field | Values |
|---|---|
| Role | admin or member. Admins can manage the vault’s settings, such as its connectors. |
| Scope grants | One level per scope (below). A member sees only scopes they are granted. |
| Privacy ceiling | Optional: the most sensitive Memory Bank class they may read: Public, Internal, Private, or Restricted. |
| State | active or suspended. |
| Expiry | Optional. |
Scope levels
| Level | ROC label | Allows |
|---|---|---|
member |
Write | Read, write, and run in the scope. |
reader |
Read | Read only. |
audit |
Audit | Knowing the scope exists, never its contents. An audit-only member’s requests are refused. |
ROC shows a vault’s scopes as Domains.
Grants are signed
The owner’s wallet signs each member’s grant: their role, scope levels, expiry, and privacy ceiling. A party that does not trust the vault service can fetch the signed roster and verify every grant against the owner’s key.
In ROC
Open Members under Organization. The Members tab lists people, their roles, and their access; the Domains tab lists scopes and who can reach each.
From code
const mine = await sdk.memberships.mine(); // vaults I am a member ofconst org = await sdk.vault.byId(mine[0].vaultId); // open oneconst roster = await sdk.memberships.list(org.id); // its members
// Owner only: add a member and grant them scopes.await sdk.memberships.put(org.id, memberPubkey, "member");await sdk.memberships.putScopes(org.id, memberPubkey, { sales: "member", support: "reader" });put and putScopes sign the grant, so they need the owner’s signer on the
VaultSDK. sdk.vault.current() is always your own vault; mine() does not
include it.