Vaults
This group covers the customer side: the vault, sovereign data, connections and consent, the Memory Bank, connectors, members, and how your own apps build on a vault.
A vault is a customer’s own store for their own data. Your agents and workflows work inside it; your apps read and write it through the Vault SDK. The customer owns it, not you and not the platform.
Who owns a vault
A vault is owned by a wallet. One wallet owns exactly one vault, and claiming
it is idempotent: sdk.vault.ensure() returns the caller’s vault, creating it on
first use.
A vault can belong to:
- A person. One owner, no other members.
- An organization. The owner adds members and grants each of them access to scopes. A vault becomes an organization’s vault by having a second member; its name is the vault’s display name.
What a vault holds
| Part | What it is |
|---|---|
| Scopes | Named partitions. Events, objects, and connections are all per scope. |
| Events | Typed messages published into a scope, grouped into streams by context. See Runs and events. |
| Objects | Files stored in a scope at a path you choose. |
| Memory Bank | Records and relations its agents and workflows filed, each with a privacy class. |
| Connectors | Configured accounts on outside systems, with their secrets sealed in the vault. |
| Agent connections | The agents and workflows the owner connected, with their agreements, settings, and pinned bundles. |
| Cubbies | The databases of each connected Agent Service. See Cubbies. |
| Members | Who else may use the vault, and at what level. |
The vault’s storage is a bucket the owner’s wallet controls.
Scopes
A scope is the unit every grant is made in. A customer can connect a fitness
agent to health without exposing finance.
| Rule | Value |
|---|---|
| Name pattern | ^[a-z][a-z0-9-]*$, at most 63 characters |
| Always present | default |
| Reserved | default, shared |
| Optional fields | displayName, streamLabel, metadata (a free-form map; updates shallow-merge per top-level key) |
In ROC, a vault’s scopes are shown as Domains on the Members page.
await vault.scopes.create({ name: "health", displayName: "Health" });const scopes = await vault.scopes.list();Credential status
A vault’s storage credential refreshes in the background. vault.status is
active, refreshing, or disconnected; vault.isDisconnected() is true when
the credential can no longer be refreshed and the owner has to act.