Skip to content

Members

A vault has one owner and any number of members. A vault with members is an organization’s vault; everything below applies to it.

Owner

The owner is the wallet that owns the vault. The owner holds every scope by virtue of the key and signs every member’s grant. The owner is never a member row; rosters show the owner first, marked as owner.

Members

Each member has:

Field Values
Role admin or member. Admins can manage the vault’s settings, such as its connectors.
Scope grants One level per scope (below). A member sees only scopes they are granted.
Privacy ceiling Optional: the most sensitive Memory Bank class they may read: Public, Internal, Private, or Restricted.
State active or suspended.
Expiry Optional.

Scope levels

Level ROC label Allows
member Write Read, write, and run in the scope.
reader Read Read only.
audit Audit Knowing the scope exists, never its contents. An audit-only member’s requests are refused.

ROC shows a vault’s scopes as Domains.

Grants are signed

The owner’s wallet signs each member’s grant: their role, scope levels, expiry, and privacy ceiling. A party that does not trust the vault service can fetch the signed roster and verify every grant against the owner’s key.

In ROC

Open Members under Organization. The Members tab lists people, their roles, and their access; the Domains tab lists scopes and who can reach each.

From code

const mine = await sdk.memberships.mine(); // vaults I am a member of
const org = await sdk.vault.byId(mine[0].vaultId); // open one
const roster = await sdk.memberships.list(org.id); // its members
// Owner only: add a member and grant them scopes.
await sdk.memberships.put(org.id, memberPubkey, "member");
await sdk.memberships.putScopes(org.id, memberPubkey, { sales: "member", support: "reader" });

put and putScopes sign the grant, so they need the owner’s signer on the VaultSDK. sdk.vault.current() is always your own vault; mine() does not include it.