Collections are shared access controls. They let an organisation grant multiple users access to specific vault items based on role or team need. Folders are personal organisation tools that help one user sort the items they already have access to. In practice, collections govern who can use a secret, while folders help an individual keep their vault tidy.
Why collections and folders solve different problems
In a password sharing workflow, the key distinction is that collections are about permission, while folders are about organisation. A collection is the sharing boundary, so it determines who can reach a secret and under what team or role context. A folder is only a personal filing structure, so it changes how one user groups items without changing access to them.
This difference matters because access should be deliberate and auditable. If a user can see a password, that should be because they were granted access through the shared control model, not because they happened to place it in a convenient folder.
That boundary is reinforced by the fact that password workflows often involve secrets that should be tightly governed, especially when teams share vault items across roles. For broader context on why shared secrets need controlled handling, see Ultimate Guide to NHIs.
How the two structures behave in practice
Collections are the mechanism you use when multiple people need the same item. They support team-based access, shared ownership patterns, and central control over who can use a secret. If someone is added or removed from a collection, their access changes with it, which makes collections suitable for collaborative workflows.
Folders behave differently. They help an individual organise items they already have access to, often by application, project, or personal preference. Moving an item into a folder does not grant access to anyone else, and it should not be treated as a control for delegation, approval, or entitlement management.
That is why folder design should be kept subordinate to access design. Good workflow hygiene starts by deciding the access boundary first, then using folders only to improve navigation inside that boundary. If teams blur those functions, they create a false sense of control that can hide who actually has access.
Risk and Threat Considerations
Misunderstanding the distinction can lead to overexposure of secrets. The usual failure mode is treating a folder like a permission boundary, then assuming that tidy organisation equals controlled access. In practice, that can leave sensitive items reachable by more people than intended, especially when vault items are shared across teams.
Failure mechanism: Access is granted through the shared structure, but operators rely on folder placement as if it enforced least privilege. The result is weak access review, accidental broad sharing, and difficulty proving who can actually use a secret.
Impact: Unintended access to passwords or tokens can widen blast radius, complicate offboarding, and increase the likelihood of misuse or compromise when shared secrets are not kept separate from personal filing conventions.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC — Identity Management, Authentication and Access Control | Collections are the access boundary, so access control and entitlement management materially apply. |
| Recommendation — Define collection membership as the authoritative access boundary and review it regularly. | ||
| CIS Controls v8 | 6 — Access Control Management | The question hinges on controlling who can use shared secrets versus personal organisation. |
| Recommendation — Use access control processes to separate shared access from local item organisation. | ||
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Secret Storage and Exposure | Password sharing workflows govern secret exposure, sharing boundaries and misuse risk. |
| NHI-03 — Overprivileged Non-Human Identities | Shared secret workflows can broaden access beyond need if collection membership is not tightly scoped. | |
| Recommendation — Keep shared secrets in governed collections and avoid using folders as an access control substitute. Scope collection access to the minimum set of users who genuinely need the secret. | ||
Practitioner Guidance
What to verify: Confirm that every shared secret lives in a collection with an explicit access rule, and that folders are used only for personal or team navigation. If access changes when a folder changes, the workflow is misconfigured.
Common mistake: Teams often create a folder structure that looks like a governance model, then rely on manual judgment to remember who should have access. That works until the team grows, the item changes hands, or offboarding becomes urgent.
What good looks like: Collection membership reflects real business need, folder naming is purely organisational, and access reviews can be completed without interpreting folder structure as a proxy for entitlement.
Practitioner takeaway: Treat collections as the control plane and folders as the user experience layer, because only the former should determine who can use a secret.
Related resources from NHI Mgmt Group
- What is the difference between attack surface management and NHI governance?
- What is the difference between reviewing human access and reviewing NHIs?
- What is the difference between role-based access and API key governance for NHI security?
- What is the difference between human IAM controls and NHI governance?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 18, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org