
Centralized vaulting, automated rotation on target systems, and governed management of privileged credentials.

Vaulting, rotation and management of privileged credentials.
| Field | Response |
|---|---|
| Coverage | Encrypted vault; scheduled and on-demand rotation across OS, AD/LDAP, DB, network targets |
| Approach | vault-service + password-rotation-service: change on target → sync vault → audit |
| Audit | Store, rotation, recovery events logged - never with secret values |
| Goal | Design Choice |
|---|---|
| Vault-first | Passwords in vault only; DB/config hold vault:// references |
| Encryption | PBKDF2 + AES-256-CBC + HMAC; master password protection |
| Target rotation | Connect to target, change password, then update vault |
| Governed recovery | Audited break-glass reveal; vault.admin permission |

All privileged passwords stored centrally - never in spreadsheets, config files, or application databases as plaintext.
Keys like ACCOUNT_{id}_PASSWORD encrypted with PBKDF2-derived keys. Session broker and rotation service retrieve via service auth - not end-user UI.
Provision, manual store, or discovery onboard.
Retrieve at connect time only.
Governed break-glass access.

RotationOrchestrator changes passwords on the target system, then updates the vault - not vault-only updates.
| Audit Event | Step |
|---|---|
| ROTATION_STARTED | Job begins |
| TARGET_PASSWORD_CHANGED | Target accepts new password |
| VAULT_UPDATED | Secret synced in vault |
| ROTATION_COMPLETED / FAILED | Outcome recorded in history |
No secrets in audit logs. Connectors and orchestrator never log passwords. Every rotation step produces identifiable, exportable evidence for regulators.

| Task | Navigation | Permission |
|---|---|---|
| Vault overview | Vault → Overview | vault.read |
| Initialize vault | Setup wizard | SuperAdmin |
| Rotate account | Rotation → Accounts | vault.write |
| Recover password | Rotation → Recover | vault.admin |
| Unvaulted accounts | Rotation workspace | vault.read |
| Method | Endpoint | Purpose |
|---|---|---|
| POST | /api/v1/vault/secrets | Store secret |
| GET | /api/v1/vault/secrets/{key} | Retrieve (gated) |
| POST | /api/v1/rotation/run-account | Rotate single account |
| GET | /api/v1/rotation/history | Rotation history |
Supporting documentation: user-guide/12-vault-and-rotation.md · SECRETS-IN-VAULT.md · PASSWORD-ROTATION-SERVICE-PLAN.md · encryption-details-26-may-26.md · ENCRYPTION-KEY-ROTATION-RUNBOOK.md

| Control | Implementation |
|---|---|
| Encryption at rest | AES-256 vault; master password / seal model |
| No secrets in logs | Rotation connectors audited without password fields |
| Least privilege | vault.read · vault.write · vault.manage |
| Compliance | SOC 2 · ISO 27001 · PCI-DSS Req. 8 rotation evidence |