Join our Newsletter — 33% off our NHI Course

Access Vault

An access vault is a controlled container for storing and sharing credentials with defined membership and permissions. It helps turn ad hoc credential distribution into a governed process that can be reviewed, revoked, and audited over time.

What an access vault is for

An access vault is not just a password store. Its purpose is to centralise credential custody so access can be granted deliberately, tracked, and removed without leaving secrets scattered across teams, systems, or chat threads.

That difference matters because the vault changes credential handling from informal sharing to governed access. In practice, it gives organisations a place to define who can retrieve what, under which conditions, and with what audit trail.

How an access vault changes credential handling

A vault introduces membership and permission boundaries around secrets, rather than treating every credential as a copyable asset. That makes it easier to separate custodianship from usage, especially when many people or systems depend on the same credential set.

Used well, the vault becomes part of the control plane for credential distribution. It can support rotation, revocation, review, and expiry, which are essential when access needs to change faster than the underlying systems do.

NHIMG’s Guide to the Secret Sprawl Challenge explains why uncontrolled credential copies create exposure and why vaulting exists in the first place.

NHIMG’s Guide to NHI Rotation Challenges shows why vault-backed rotation is often difficult at scale, even when the policy is straightforward.

Where access vaults fit in a security program

An access vault sits between secret creation and secret use. It is most valuable when credentials must be shared across teams, environments, applications, or automations without losing control over ownership and lifecycle.

In mature environments, the vault supports governance questions as much as storage questions: who owns the secret, who can request access, how long access lasts, and what evidence exists when auditors ask how access was controlled over time.

That is why vaults are often discussed alongside credential hygiene, least privilege, and lifecycle management. The vault does not eliminate those concerns, but it gives them a place to be enforced consistently.

NHIMG’s NHI Lifecycle Management Guide connects vaulting to provisioning, rotation, offboarding, and access review as one lifecycle rather than separate tasks.

NHIMG’s Ultimate Guide to NHIs, Static vs Dynamic Secrets is useful for understanding why short-lived credentials usually reduce exposure compared with static ones.

Common failure modes of access vaults

An access vault can become a weak point if it is treated as a storage product rather than a governed access service. Poor membership design, weak separation between administrative and read permissions, and overly broad policy grants can all undermine the intended control.

Another failure mode is credential accumulation. If old secrets remain in the vault after they are no longer needed, the vault may preserve convenience while also preserving stale access paths that should already have been revoked.

NHIMG’s Azure Key Vault Contributor escalation 2024 illustrates how excessive platform permissions can turn a vault into an exposure multiplier instead of a protection layer.

NHIMG’s Hugging Face Spaces breach 2024 is a reminder that stored tokens and shared secrets still need lifecycle control after they are placed in a repository or platform.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 IA-5 — Authenticator Management Covers lifecycle control of credentials stored and shared in a vault.
AC-6 — Least Privilege Applies when vault membership and retrieval rights must stay narrowly scoped.
Recommendation — Manage secret issuance, rotation, and revocation under IA-5. Limit vault access to the minimum set of authorized users and processes under AC-6.
CIS Controls v8 CIS-5 — Account Management Supports governed access, review, and removal of credential access paths.
Recommendation — Inventory vault users and remove unnecessary access paths under CIS-5.
ISO/IEC 27001:2022 A.5.15 — Access control Directly addresses controlled access to secrets held in an access vault.
A.8.5 — Secure authentication Relevant where vault access depends on strong authentication before secret retrieval.
Recommendation — Define and enforce access rules for vault-held credentials under A.5.15. Require strong authentication before vault retrieval under A.8.5.

Practitioner Guidance

Governance implication: Treat the vault as a policy boundary, not a convenience layer. The useful question is not only whether a secret is inside the vault, but whether access to that secret is meaningfully constrained, reviewable, and revocable.

What to watch for: Broad membership, long-lived credentials, and manual ad hoc sharing usually indicate that the vault is being used as a safe place to keep secrets rather than as a control to manage who may use them. That is where review discipline and ownership matter most.

Practitioner takeaway: A strong access vault reduces credential sprawl only when its permissions, rotation behaviour, and offboarding process are managed as part of one lifecycle.