Configure Secrets Safe in BeyondInsight Cloud

Scope of this guide

This workflow shows you how to set up and use Secrets Safe in BeyondInsight Cloud. You will assign feature access to a group, create safes and folders, add secrets, and manage sharing and permissions.

Prerequisites

  • You have a BeyondInsight Cloud account.
  • You have administrator permissions in BeyondInsight, or you are a member of a group with Full Control permissions for the Secrets Safe feature.
  • You have reviewed the Secrets Safe: Overview | BI Cloud article to understand what Secrets Safe is and how it works.

Why is this important

Secrets Safe gives your team a secure, centralized vault for storing credentials, files, and sensitive text. Controlling who can access secrets through group-based permissions reduces the risk of unauthorized access and makes it easier to audit who viewed or changed a secret.

Workflow summary

StepAction
1Assign the Secrets Safe feature to a group
2Create a safe
3Add users or groups to a safe and assign permissions
4Create folders to organize secrets
5Add secrets to a safe or folder
6View, copy, edit, or delete a secret
7Share a secret or secret link
8Move secrets and folders

Steps

Step 1: Assign the Secrets Safe feature to a group

Users get access to Secrets Safe through their group membership. Assign the feature to the group before users can see or use it.

  1. From the left menu, select Configuration.
    The Configuration page displays.
  2. Under Role Based Access, select User Management.
    The User Management page displays.
  3. Select the Groups tab.
  4. Locate the group you want to assign the Secrets Safe feature to.
  5. Select the ellipsis (...) next to the group, then select View Group Details.
    The Group Details page displays.
  6. Under Group Details, select Features.
  7. In the Features pane, locate and select the Secrets Safe feature.
    You can filter the list by All Features or Disabled Features, or search by Feature Name.
  8. Select Assign Permissions above the grid.
  9. Select the appropriate permission level:
    • Read-only — users can view safes they have been granted access to.
    • Full control — users can view and create safes.
    • Disable permissions — removes access to Secrets Safe.
  10. Save your changes.

Step 2: Create a safe

Any user with Full Control permissions for the Secrets Safe feature can create a safe. Users who create a safe are automatically granted the Manage Safe permission for that safe.

  1. From the left menu, select the Secrets Safe icon.
    The Secrets Safe page displays.
  2. Under Safes, select Create New Safe +.
  3. Enter a name for the safe.
  4. Select Create Safe.
ℹ️

By default, administrators do not automatically see all safes. To view all safes, toggle Show All Safes. Safes you do not have access to appear greyed out.

Step 3: Add users or groups to a safe and assign permissions

Users with the Manage Safe permission on a safe can control who else can access it. BeyondInsight administrators can always manage safe permissions.

  1. From the left menu, select the Secrets Safe icon.
    The Secrets Safe page displays.
  2. Locate the safe in the Safe panel.
  3. Select the ellipsis (...) next to the safe, then select Go to Advanced Details.
    The Advanced Details page displays. The Access Management grid lists users and groups already added to the safe.
  4. From the Show dropdown list, select All Users & Groups.
  5. Assign permissions:
    • For a single user or group: select the ellipsis (...) next to the user or group, then select Assign Permissions.
    • For multiple users or groups: check the boxes next to each user or group, then select Assign Permissions above the grid.
  6. In the Assign Permissions panel, check the appropriate permissions:
    • Read Secrets and Folders (required, assigned by default)
    • Create Secrets and Folders
    • Update Secrets and Folders
    • Delete Secrets and Folders
    • Share Secrets
    • Manage Safe (automatically selects all permissions)
  7. If you want permissions to expire, toggle Set an expiration date on and enter an expiry date and time. The default expiration is one week from the current date.
  8. Select Assign Permissions to save.

Step 4: Create folders to organize secrets

Folders let you organize secrets into subfolders within a safe.

  1. From the left menu, select the Secrets Safe icon.
    The Secrets Safe page displays.
  2. Select a safe or one of its subfolders.
  3. Select the ellipsis (...), then select Create Folder.
  4. Enter a name for the folder.
  5. Select Create Folder.
ℹ️

You can also rename or delete a folder using the ellipsis menu next to the folder. Deleting a folder removes all secrets inside it.

Step 5: Add secrets to a safe or folder

You need Create Secrets and Folders permission, or full control on the safe, to add secrets.

  1. From the left menu, select the Secrets Safe icon.
    The Secrets Safe page displays.
  2. Select a safe or one of its subfolders.
  3. In the Secrets pane, select + Add Secret.
  4. Select the type of secret you want to add: Add Credential, Add File, Add Text, or Import Secrets.

Add a credential

  1. Enter a Title, Description, Username, and URL (if required).
  2. Set the password:
    • Select Manual Input to type a password.
    • Select Auto Generate, choose a Password Policy from the list, then select Generate Password.
  3. Add a Note if you need to store additional information about the credential.
  4. Select Create Secret.
ℹ️

To use Auto Generate, the password policy must have the Allow use for Secrets Safe option enabled in Configuration > Privileged Access Management Policies > Password Policies.

Add a file

  1. Enter a Title, Description, and URL (if required).
  2. Drag the file into the Upload File box, or select the box to browse for a file. Files must be 5 MB or less.
  3. Select Create Secret.

Add text

  1. Enter a Title, Description, and URL (if required).
  2. Enter the body of the text.
  3. Add a Note if needed.
  4. Select Create Secret.

Import secrets from a CSV file

  1. Select a safe or one of its subfolders.
  2. In the Secrets pane, select + Add Secret.
  3. If a confirmation dialog appears, select Import Secrets.
  4. Drag the CSV file into the Import CSV File box, or select the box to browse for the file. Files must be 200 KB or less.
  5. Select a folder or create a new folder to save the imported secrets to.
  6. Select Import Secrets.

The CSV file must include a header row and eight columns in this order: URL, Username, Password, TOTP, Extra, Name, Grouping, Fav. Only URL, Username, Password, and Name are used.

Step 6: View, copy, edit, or delete a secret

  1. From the left menu, select the Secrets Safe icon.
    The Secrets Safe page displays.
  2. Select a safe or one of its subfolders.
  3. Locate the secret in the Secrets grid.
  4. Select the ellipsis (...) to the right of the secret. The available actions depend on your permissions and the secret type:
    • Credential secrets: Copy Username, Copy Password, Copy Notes, View Details, Edit Secret, Share Secret, Remove Share, Delete Secret.
    • File secrets: Download File, Copy Notes, View Details, Edit Secret, Share Secret, Remove Share, Delete Secret.
    • Text secrets: Copy Text, Copy Notes, View Details, Edit Secret, Share Secret, Remove Share, Delete Secret.
ℹ️

To edit or delete a secret, you must be the secret owner or have the appropriate permission on the safe.

Step 7: Share a secret or secret link

Share a secret to another safe or folder

Sharing copies the secret to another safe or folder. The shared copy inherits the destination safe's permissions.

  1. From the left menu, select the Secrets Safe icon.
  2. Select a safe or subfolder, then locate the secret in the Secrets grid.
  3. Select the ellipsis (...) next to the secret, then select Share Secret.
  4. In the Share to Folders panel, select the destination safe or folder. Only safes and folders where you have the Create permission are listed.
  5. Select Share.

To remove a shared secret, select the ellipsis (...) next to the original secret and select Remove Share. This removes all shared instances while keeping the original.

Share a link to a secret

  1. From the left menu, select the Secrets Safe icon.
  2. Select a safe or subfolder, then locate the secret in the Secrets grid.
  3. Select the ellipsis (...) next to the secret, then select Copy Secret Link.
    The Distributing a Secret Link dialog box displays.
  4. Select OK. A cookie is saved and the link is copied to your clipboard.
  5. Send the link to the user.
ℹ️

The recipient must have Secrets Safe access and permissions to the secret. You cannot share a link to secrets saved in the Personal folder.

Step 8: Move secrets and folders

You can move secrets within the same safe or to a different safe. You can move up to 200 secrets at a time; for larger moves, use batches or move the containing folder.

Required permissions:

  • To move within the same safe: Update Secrets and Folders permission on the source safe, or ownership of the selected secrets.
  • To move to a different safe: Create Secrets and Folders permission on the destination safe, in addition to the permissions above.

Move secrets

  1. In the Secrets grid, check the boxes next to the secrets you want to move.
  2. Select Move Secrets. A side panel displays available destination locations.
  3. Select the destination safe or folder.
  4. Select Move. The Moving Secrets dialog box displays.
  5. Choose how to handle naming conflicts:
    • Stop the process — no secrets are moved.
    • Rename the secret — secrets with naming conflicts are renamed automatically.
    • Do nothing — secrets with naming conflicts are skipped.
  6. Select Continue.
  7. Select View Results to see how many secrets were moved, then select OK.

Move a folder

  1. In the Secrets grid, right-click the subfolder and select Move Folder.
  2. Select the destination folder from the list.
  3. Select Move. The Moving Folders dialog box displays.
  4. Choose how to handle naming conflicts: Stop the process or Rename the folder.
  5. Select Continue.
ℹ️

Safes cannot be moved or demoted to subfolders. Folders cannot be promoted to safes. Shared secrets cannot be moved to a different safe.

Verify the results

Verify that users in the group can sign in to BeyondInsight Cloud and see the Secrets Safe icon in the left menu. Confirm that users with Full Control can create safes, and that users with Read-only access can view safes they have been granted access to. Confirm that secrets appear in the correct safe or folder after creation or import.

Next steps

  • Secrets Safe: Overview | BI Cloud - Learn about Secrets Safe features and secret types before you configure.
  • Configure password policies to use with Auto Generate for credential secrets. Go to Configuration > Privileged Access Management Policies > Password Policies page.
  • Set up the Workforce Passwords browser extension to enable CSV import functionality.

Related resources

©2003-2026 BeyondTrust Corporation. All Rights Reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.