Getting started: three steps to open your vault
A vault is only as safe as what's in it and who has the key
Work through these steps in order — each one sets up the next. Don't invite a single user until Step 1 is done.
Audit what's inside your business
Walk through the documents and folders you plan to bring into VaultIQ, and sort each into one of three classifications — before you touch the portal. It's far easier to grade documents once than to re-grade them after they've already been read by the wrong person.
| Business area | Example documents | Classification | Where it can be accessed |
|---|---|---|---|
| Marketing | Brochures, website copy, case studies | PUBLIC | Anyone in the firm, and shared externally |
| Firm operations | Templates, style guides, internal wikis | PRIVATE | All employees, not shared outside the firm |
| HR & payroll | Contracts, salary bands, reviews | RESTRICTED | HR and leadership only |
| Client matters | Client files, correspondence, filings | RESTRICTED | Assigned matter team only |
| Finance | Statements, tax filings, forecasts | RESTRICTED | Finance and leadership only |
What the three classifications mean in VaultIQ
- Public — safe for anyone with a login to read or chat against. No client names, no financials, no internal decisions.
- Private — internal to the firm. Fine for staff to see, but never leaves the organization.
- Restricted — need-to-know only. Client files, HR records, anything tied to a person or a legal obligation.
Assign the right hands to the right data
Your worksheet from Step 1 tells you what exists. This step decides who touches it. Create one user per person — never a shared login — and give each one exactly the role their job needs, on exactly the vaults their job touches.
Vault Admin
Owns a vault end to end. Usually a partner, practice lead, or IT owner.
- Adds and removes vault members
- Sets classification on any document
- Turns chat on or off for the vault
Vault Contributor
Feeds the vault. Usually the staff who create or handle documents day to day.
- Uploads and updates documents
- Sets classification on what they add
- Chats against anything they're permitted to see
Vault Viewer
Reads and asks. Usually broader staff, or clients on a limited portal.
- Reads documents they're permitted to see
- Chats against those same documents
- Cannot upload, edit, or reclassify
How roles line up with your classifications
| Role | Public | Private | Restricted |
|---|---|---|---|
| Vault Admin | Full access | Full access | Full access |
| Vault Contributor | View & contribute | View & contribute | Only if named on the matter |
| Vault Viewer | View & chat | View & chat, if invited | Only if named on the matter |
Design who can chat, and about what
Chat isn't a separate permission — it's a lens on the access you've already set up. A person can only ever ask about documents their role and vault membership already let them see. This step is about deciding, vault by vault, when that lens is ready to turn on.
What each role can ask
- Vault Admin chats across the entire vault, including Restricted material. Reserve this for people who'd already have that access on paper.
- Vault Contributor chats against Public and Private material, plus any Restricted document they were personally granted.
- Vault Viewer chats against whatever they can read — nothing more. Answers are filtered to their permitted documents automatically.
Before you flip chat on for a vault
| Question | Why it matters |
|---|---|
| Is classification finished for every document? | An unclassified document defaults to the widest access in the vault until graded — leave chat off until Step 1 is done here. |
| Are viewers scoped to the right vault? | Chat can only be as narrow as the vault membership behind it. |
| Does this vault need chat logs reviewed periodically? | Every chat query is recorded against the asking user, so audits stay possible. |
Rule of thumb
Turn chat on vault by vault, not all at once. A vault with unfinished classification stays chat-off until it's graded — better a slower rollout than an answer pulled from a document nobody meant to expose.
Your vault, in three steps.
Audit what you have, hand it to the right people, then decide what they can ask. Once all three are set, your vault is ready for daily use.