Hello, I’m Nora, your AI guide from Technology Last Stop. This guide covers Manage company passwords with scoped permissions. Company Workspace customers have a separate shared credential vault with encrypted values, on-demand reveal, change history, collision protection and reversible Trash. This is separate from TLS staff vaults. Current availability: Implemented shared company vault; customer acceptance required. Before you start. An active paid Company Workspace or a TLS owner preparing its configuration. Managed Support accounts do not receive workspace vault administration. Company password view permission to reveal; company password manage permission to create, edit or move records. Company owners and administrators have these permissions. Other roles need an explicit scoped delegation. A protected platform vault key and completed company MFA. Step 1. Open Company Workspace > Passwords. Use Search credential titles and View options to choose a collection layout. The main listing never includes plaintext passwords. Step 2. Choose Add credential. Enter the title, username, password, website, optional tags, rotation date and notes, then save. Password spaces are preserved exactly. Step 3. Choose View credential to reveal a permitted item. The reveal is recorded in company activity. Copy only into a trusted destination. Read views clear after 60 seconds or when hidden. Step 4. Choose Edit credential, make changes and save. If another tab changed the record, refresh and review the latest version; a stale edit cannot overwrite it. Save drafts before refreshing or closing. Step 5. To remove an active credential, expand Move to Trash, confirm the specific removal and submit. Trashed credentials cannot be revealed. Open Trash to restore. Step 6. Open this company section in another tab for an additional monitor. It retains the selected company and section; permissions are checked again on every server action. Now verify the result. Inspect a saved database record during an authorized synthetic test: password values must be ciphertext, with secrets absent from audit entries. A regular company user without password permission, a Managed Support account and a different company cannot open or reveal the vault. Edit the same record in two tabs and confirm that the second stale save is rejected. If you get stuck. Unavailable encryption: TLS must restore the protected vault key before the vault is usable. Never replace an existing key without an approved migration. A company vault currently provides shared credentials. Personal customer vaults, native browser autofill, password-health scanning and full 1Password feature parity are not implemented. Company vault Trash has no automatic permanent purge in this release. Retention and any export or purge require the approved lifecycle process. Do not store primary-account MFA recovery secrets in the same account that they recover. Use the current written guide for exact URLs, permission names, and provider documentation. Pause before entering credentials, and keep them in protected configuration. I’m Nora, your TLS guide.