Getting Started with VaultIQ - Vault Admin

Getting started: three steps to open your vault

A vault is only as safe as what's in it and who has the key

Work through these steps in order — each one sets up the next. Don't invite a single user until Step 1 is done.


1
Before you invite anyone

Audit what's inside your business

Walk through the documents and folders you plan to bring into VaultIQ, and sort each into one of three classifications — before you touch the portal. It's far easier to grade documents once than to re-grade them after they've already been read by the wrong person.

Business areaExample documentsClassificationWhere it can be accessed
MarketingBrochures, website copy, case studiesPUBLICAnyone in the firm, and shared externally
Firm operationsTemplates, style guides, internal wikisPRIVATEAll employees, not shared outside the firm
HR & payrollContracts, salary bands, reviewsRESTRICTEDHR and leadership only
Client mattersClient files, correspondence, filingsRESTRICTEDAssigned matter team only
FinanceStatements, tax filings, forecastsRESTRICTEDFinance and leadership only

What the three classifications mean in VaultIQ

  • Public — safe for anyone with a login to read or chat against. No client names, no financials, no internal decisions.
  • Private — internal to the firm. Fine for staff to see, but never leaves the organization.
  • Restricted — need-to-know only. Client files, HR records, anything tied to a person or a legal obligation.
If you're unsure: mark it Restricted. You can widen access to a document later — you can't undo the fact that someone already read it.

2
One vault, three kinds of hands

Assign the right hands to the right data

Your worksheet from Step 1 tells you what exists. This step decides who touches it. Create one user per person — never a shared login — and give each one exactly the role their job needs, on exactly the vaults their job touches.

Vault roles
Role

Vault Admin

Owns a vault end to end. Usually a partner, practice lead, or IT owner.

  • Adds and removes vault members
  • Sets classification on any document
  • Turns chat on or off for the vault
Role

Vault Contributor

Feeds the vault. Usually the staff who create or handle documents day to day.

  • Uploads and updates documents
  • Sets classification on what they add
  • Chats against anything they're permitted to see
Role

Vault Viewer

Reads and asks. Usually broader staff, or clients on a limited portal.

  • Reads documents they're permitted to see
  • Chats against those same documents
  • Cannot upload, edit, or reclassify

How roles line up with your classifications

RolePublicPrivateRestricted
Vault AdminFull accessFull accessFull access
Vault ContributorView & contributeView & contributeOnly if named on the matter
Vault ViewerView & chatView & chat, if invitedOnly if named on the matter
In the portal: go to Settings → Users, invite each person, and assign them to specific vaults rather than the whole account. A client-facing viewer should belong to that client's vault alone.

3
Chat inherits everything above it

Design who can chat, and about what

Chat isn't a separate permission — it's a lens on the access you've already set up. A person can only ever ask about documents their role and vault membership already let them see. This step is about deciding, vault by vault, when that lens is ready to turn on.

What each role can ask

  • Vault Admin chats across the entire vault, including Restricted material. Reserve this for people who'd already have that access on paper.
  • Vault Contributor chats against Public and Private material, plus any Restricted document they were personally granted.
  • Vault Viewer chats against whatever they can read — nothing more. Answers are filtered to their permitted documents automatically.

Before you flip chat on for a vault

QuestionWhy it matters
Is classification finished for every document?An unclassified document defaults to the widest access in the vault until graded — leave chat off until Step 1 is done here.
Are viewers scoped to the right vault?Chat can only be as narrow as the vault membership behind it.
Does this vault need chat logs reviewed periodically?Every chat query is recorded against the asking user, so audits stay possible.

Rule of thumb

Turn chat on vault by vault, not all at once. A vault with unfinished classification stays chat-off until it's graded — better a slower rollout than an answer pulled from a document nobody meant to expose.

Your vault, in three steps.

Audit what you have, hand it to the right people, then decide what they can ask. Once all three are set, your vault is ready for daily use.