SkyKeep vault portal
Sign in?
Set a new password?
Before you can use the vault you need to choose your own password. It must be at least 8 characters long and different from the one you just typed. If your account asks for a one-time code at sign-in, that code needs an address — so if we do not have one for you yet, add it below.
Upload a document??
Upload disabled for this account.
What this means, and what changes it?
This account holds no compartment. A document uploaded from here would belong to nowhere, and this account could never read it back — so the page offers no form rather than a form that could only fail. The upload API refuses the same request for the same reason and records the attempt: this page is stating the vault's answer, not inventing one.
You do not belong to any compartment yet. A document uploaded from here would belong to nowhere, and you could never read it back, so there is no form to fill in — not because of what kind of account this is, but because it has not been given a compartment. Ask an administrator to assign you one; the form appears here when they do. The upload API refuses the same request for the same reason and records the attempt.
Read Only users do not have upload abilities.
The vault could not read which compartments you may upload into, so no upload form is offered. Reload to try again; the upload API decides for itself either way.
Content the scan gates hold is quarantined for review rather than stored.?
Held for review
The vault stopped these before they were stored, so they are not searchable and nobody else can reach them. An administrator can release or reject one; you can delete your own. Deleting is final — the file never entered the vault, and the vault keeps only the record that it was held and withdrawn.?
Your documents?
Every document in the compartments you can reach, and what the vault knows about each one: its version number, its summary, the metadata found inside it, when it was uploaded and how big it is. Nothing you cannot reach appears here: the list is bounded by the engine, not by this page.
Two of these need reading carefully. A summary is written by reading the document — if the vault could not read it, the row says no summary rather than showing you the first line of the file dressed up as one. And a date the document claims about itself comes out of the file, which the person who sent it chose the contents of; the row always says whether it is showing you the document's own date or the moment the vault received it. Anything the vault does not know shows as unknown rather than as a made-up default.
Sorting by a date the document claims arranges the list by something the file says about itself, not by anything the vault established. Documents that claim no date, or whose claim was refused, come last.
| Filename | Metadata | Summary | Keywords |
|---|
Doc Keep?
Listing of documents available to you. Click column headers to sort. File dates are those recorded in the file metadata or the file itself.
Keyword Mind Map
Folders?
|
Not loaded yet.
|
||||||||
|---|---|---|---|---|---|---|---|---|
Tree?
Your documents arranged by the folder they are filed in. A folder decides nothing about who may read a document — the compartment does that, and every route re-checks it.
Needs Help?
These documents are in the vault and are safe, but the vault could not read all of their text — so searching will not find what is inside them. Nothing here is lost, and nothing here is an error you caused.
How you can help
- Add a readable copy. Upload the same document as Markdown, plain text, or a Word file, into the same compartment. The vault reads that copy and searching finds it; the original stays exactly where it is.
- Tell us what is in it. If the document matters and you cannot produce a readable copy, say so to whoever administers this vault — a scanned page that nobody can search is worth knowing about.
- Or leave it. A document listed here is still stored, still retrievable and still purgeable. If its contents do not need to be searchable, nothing needs doing at all.
| File | What the vault could not read | Type | Compartments | Received |
|---|
Documents that look alike?
When a document you stored reads almost the same as one already in a compartment you can reach, the vault writes the pair down and tells you. It does not act on it — nothing here has been merged, moved, hidden or deleted. Say what the pair is, and the answer is recorded with your name on it. Throwing a copy out asks an administrator — you say which copy, the request is recorded, and they either throw it out or tell you why they will not. Nothing is destroyed until they act.
| This document | Looks like | How alike? | Your answer |
|---|
DOCUMENTS BEING PROCESSED?
Shift-click a second column to sort within a sort.
Search?
Think?
Stack diagnostics?
Invite new users?
Email addresses separated by commas, spaces, or semicolons — mixed is fine. Up to 100 per submission. Each person is mailed a temporary password and must choose their own at first sign-in.
Emails sent?
Every mail the vault has sent. Sent means the relay accepted the message — the vault cannot confirm delivery beyond that. Bounced means the recipient was refused; failed means the mail never left. Invitations that did not reach the relay can be resent, at a corrected address if the original was a typo; sign-in codes cannot — they are single-use, and the person signs in again to get a new one. An invitation the relay accepted gets no checkbox and the vault refuses to resend it: a resend issues a fresh temporary password, which would lock out the person still holding the first one. Re-inviting a delivered address is a deliberate act, asked for one message at a time, and it is recorded as such.
| Select | Recipient | Kind | When | Status |
|---|
Document stats?
How many documents the vault holds — metadata only (document names, compartment names, counts; never content), bounded to what you can see, and every access is audited.
Stats disabled for this account.
Stats count the documents in the compartments you can reach, and this account reaches none — a clientadmin holds zero compartment grants by design, because it hands out reach and holds none itself. A count of 0 here would not be a small answer, it would be a false one: it would read as a fact about the vault when it is a fact about this account. The stats API refuses the same request for the same reason and records the attempt.
Stats count the documents in the compartments you can reach, and you do not belong to any compartment yet. A count of 0 here would not be a small answer, it would be a false one: it would read as a fact about the vault when it is a fact about this account. Ask an administrator to assign you a compartment. The stats API refuses the same request for the same reason and records the attempt.
Whole-vault figures (administrators)
Vault-wide numbers with no compartment axis: the vault serves them only to an administrator, and this page shows the refusal rather than hiding the buttons.
| Figure | Value | Notes |
|---|
Compartment view of docs
Every document in this compartment, by name. This page replaces the in-page popup once a compartment holds too many documents to pop up.?
Query?
Ask the vault a question. It first retrieves the document chunks your compartments admit, then asks the local model to answer over exactly those chunks — the model never sees anything the retrieval did not admit. That is true whichever mode you pick below; the modes differ only in whether you stop and look in between.
Query disabled for this account.
A query searches the compartments you belong to, and this account belongs to none — an administrator and a clientadmin each hold zero compartment grants by design, so there is nothing here for a query to be admitted to. Search, Think, and both stages of this page are refused server-side for the same reason, and every refusal is audited.
A query searches the compartments you belong to, and you do not belong to any yet — so there is nothing for a query to be admitted to, and the stages are not offered rather than offered and refused. Ask an administrator to assign you a compartment. Search, Think, and both stages of this page are refused server-side for the same reason, and every refusal is audited.
Ask
Narrow this search
These only ever NARROW what you could already find — none of them widens your reach, and a compartment you do not belong to simply matches nothing. Dates are the document's OWN date, the one it claims about itself, not the day the vault received it; a document that claims no date is in no date range. Select no compartment to search all the ones you belong to. Clearing every box searches everything you can reach.
Keyword Mind Map
Words drawn from the documents you can reach. Clicking one adds it to your question — it does not narrow anything by itself.
What these two counts mean?
Show the chunks retrieved for this question
These are the chunks the retrieval matched. Before the question reached the model each may have been widened to the section around it, so the model can have read more of a document than appears here; and if they did not all fit the model's context window it was shown fewer of them, which the answer states when it happens.
Answer
Earlier question, still being answered
The vault's model cannot be interrupted once it has started writing, so aborting the earlier question throws its answer away but does not make the new one arrive sooner — the new answer starts when the model is free.
Approve an agent?
An agent that has no screen of its own — something running on a server, or in a terminal — can ask to act as you. When it does, it shows you a short code. Type that code here to say yes.
Approving one does not widen anything. The agent gets what you and it both already have, and nothing else: a compartment you cannot read stays unreadable through the agent, and a compartment the agent was never granted stays out of reach even though you can read it. The approval is short-lived and cannot be renewed — an agent that needs more time asks you again. Only approve a code an agent has just shown you; if a code arrives any other way, do not type it.
Users?
Every account the vault holds — its kind, its sign-in name, the address its codes go to, whether that address falls inside the allowed-domain list, whether it is disabled, and the compartments it can reach. Click any column heading to sort by it; click it again to reverse. Read-only here: accounts and grants are changed in the admin console, and this list is served by the same admin-checked route, so it shows nothing an admin could not already ask for.
The allowed-domain review loads with the account list.
| Sign-in name | Kind | Allowed domain | Status | Compartments |
|---|
Permissions?
What this engagement's access actually looks like. Rows are people, columns are compartments, and every cell is one of three levels: no access, read, or write. Read is the floor — somebody who may file a document into a compartment can always read it — so ticking write ticks read, and unticking read unticks write. Like the compartments page, this one shows no document, no title, no size and no count of them.
The grid?
Every compartment in this engagement is a column here, and the accounts arrive one page at a time: a whole grid is people times compartments, and that product is what made this page take most of a minute to draw. Every account is on exactly one page. The filters below narrow what you are looking at and change nothing about what is held — the people filter is the vault's, so it searches every account rather than only the page in front of you. A change to one cell is sent the moment you make it.
Bulk apply?
Choose any set of people and any set of compartments and give every one of those cells the same level. This is a selection, not a group: it writes each cell explicitly, each one separately revocable and separately recorded, and nobody inherits anything later. Shift-click a second box to take the whole range between it and the last one you clicked.
A bulk change is the widest single act this page offers, so Preview comes first: Apply stays switched off until a preview of this exact selection has been shown, and switches off again the moment the selection or the level changes.
Saved in this browser only. A recall pre-ticks boxes and grants nothing — Preview and Apply are still the only way anything changes.
History?
What access each person has held over time. This is a read of the audit trail rather than a second record of its own, so it cannot disagree with what happened. Each row names the level before the change and the level after it.
Every name below is the name that account or compartment has now, not the name it had when the change was made — compartments get renamed and merged, and the vault keeps no history of names. The id beside each name is the thing that does not change.
| When | Who acted | Whose access | Compartment | Change | Outcome |
|---|
Recertification?
The grants that lapse soon, soonest first, over the window this vault is configured with. A grant with no expiry is not here — it is not going to lapse, so a review that listed it would be a review of the whole vault wearing a deadline's clothes. One that has already lapsed is here and says so: it reaches nothing, and the person reading this is the person who should decide whether to renew it or take it away. Extending is an act, not a note: it is recorded by name with the date it replaced and the date it set.
| Who | Compartment | Level | Granted by | Granted | Reason | Expires | Recertify |
|---|
No grant chosen yet — press Extend… on a row above.
Performance?
The vault's query-speed dials, its measured model timings, and what a measurement says is worth changing. This page changes nothing: each recommendation names the setting, the evidence, and the surface that applies it.
| Model | Median ms | Prompt chars of that request | Samples | Did not answer |
|---|
| Agent principal | Requests | Refused | People acted for | First seen | Last seen | Credential |
|---|
| Service | Parameter | Setting | In force | Source |
|---|
Compartments?
Delegated compartment administration: create a compartment, rename one, merge two. Giving a person access happens on the Permissions view (the 🔑 entry), one surface for every grant?. This page shapes who can reach what — it shows no document and never will, because an account that could both merge compartments and read documents could merge its way into anything.
| Compartment | Id | People |
|---|
Create a compartment?
Rename a compartment?
Your profile?
Your account settings — your picture, the email address your sign-in codes go to, your password, and a short note about yourself. Everything on this page is yours alone: nobody else can see it here, and you cannot see anybody else's.
About you?
A short note about who you are and what you work on. It is yours: no other account can read it, no administrator screen shows it, and the vault only ever hands it back to you.
Email for sign-in codes?
Where a one-time code goes when your account asks for one. Whether it does is your choice, below — some accounts sign in on the password alone. Enter your current password to change this address, so nobody who borrows your screen can quietly redirect your codes.
Password?
Choose a new password of at least 8 characters. It has to be different from your current one, and you need your current password to make the change.
Sign-in codes?
When this is on, signing in asks for a one-time code emailed to you as well as your password. Your first sign-in always asks for one, whatever this says — that first code is how the vault learns the account reached the right person.
This vault's administrator requires a one-time code for every account, so this cannot be changed right now. Your own choice is remembered and comes back if that requirement is turned off.
Compartments you belong to?
These are the compartments you can work in, and what you may do in each. They are set for you by an administrator — if you need access to another one, ask them.