Skip to content
SkyKeephelp

Delegated compartment administration

A client's own administrator can organise the vault's compartments —

creating them, naming them, putting people in them, and merging two into

one — without ever being able to read a document inside any of them.

That pairing is the whole design. Merging two compartments widens reach:

everyone who was in the source can afterwards see everything that was

already in the target. In an account that could also read documents,

that would not be an organising power at all — it would be a way to

reach any document in the vault by merging its compartment into your

own. So the vault gives this administrator no compartment of its own,

and refuses to give it one even when asked.

Putting a person into a compartment and taking them back out are the

same authority, deliberately. Widening someone's reach is the act that

needs guarding; narrowing it again is a correction, and an administrator

who could only ever add people would be one whose every mistake had to

be escalated to somebody else.

A client administrator organises compartmentsstack

A merge carries the people across, not just the documents

A client administrator cannot be given a compartment

A compartment cannot be merged into itself

An assignment can be taken back by whoever made it

Taking someone out of a compartment needs the same authority as putting them in

A name already in use is refused, and nothing is renamed

Someone with no administrative authority can change nothing