Zoho Vault is Zoho's enterprise password manager, and as part of Zoho One it provides your organisation with a secure, centralised place to store, share, and manage passwords for business accounts and services. Accessed through the Zoho One app launcher with a single login, Vault helps teams move away from insecure practices such as sharing passwords over email or storing them in spreadsheets.
Zoho Vault stores passwords in an encrypted vault, applying AES-256 encryption with a master password known only to the account holder. Users can create individual vaults for personal passwords and shared chambers for team passwords, allowing controlled access to shared credentials without revealing the underlying password itself. The browser extension allows users to auto-fill login credentials on any website directly from the vault.
Administrators enable Zoho Vault for users from the Zoho One Admin Panel. Once provisioned, users access Vault through the app launcher using their existing Zoho credentials. Conditional assignment rules can grant Vault access to specific teams or all users across the organisation. The administrator can also manage which secrets are shared with which groups, ensuring that passwords for shared services are accessible only to the people who need them.
Zoho Vault allows administrators to share passwords with individuals, groups, or the entire organisation. Shared passwords can be accessed by the recipient without ever being viewed in plain text, which means team members can log in to a shared service without knowing the actual password. This is particularly useful for social media accounts, shared email addresses, or third-party tools where a single shared login is necessary.
Every access and change event in Zoho Vault is logged in a detailed audit trail. Administrators can see who accessed which credentials, when, and from which device. This level of visibility is valuable for security reviews and compliance, providing evidence that access to sensitive accounts is controlled and monitored. Password health reports identify weak, reused, or ageing passwords that need to be updated.
When an employee leaves your organisation, their Zoho One account is deactivated and their access to Zoho Vault is revoked immediately. Any shared passwords they had access to remain in the vault and accessible to other authorised team members. Administrators can run a report of which secrets were accessible to a departing user, making it straightforward to identify which credentials should be rotated as part of offboarding.