clientst0r vault in depth: access rules, approvals and break-glass
For administrators and senior technicians who protect client credentials in clientst0r: the layers that stand between a click and a secret (role, access rules by country, IP and time, per-entry reveal approval and break-glass), who can approve what, how approvals expire, what the audit log records, and the vault hygiene features (breach scanning, Bitwarden import, exports, personal vault) that keep the vault trustworthy.
- Level
- Intermediate
- Length
- About 45 minutes
- Contents
- 3 lessons · 1 video · final exam
- Status
- Published · updated 2 Oct 2026
- clientst0r · open source
- clientst0r · open source
Skills you'll practise
- Explain how role permissions, access rules, reveal approval and break-glass combine before a password is shown
- Design access rules with the right scope, effect and priority, knowing that deny wins and an empty rule set allows
- Request, approve and use a reveal approval, including who may approve and how long an approval lasts
- Use break-glass correctly in a genuine emergency and review break-glass events afterwards in the audit log
- Handle imports, exports and breach flags without leaving plaintext copies behind
Course outline
- 1.clientst0r vault in depthVideo · 2 min
- 2.Layers of control on one credentialLesson · 15 min
- 3.Reveal approval and break-glassLesson · 15 min
- 4.Audit, review and vault hygieneLesson · 15 min
- 5.clientst0r vault in depth: access rules, approvals and break-glass: knowledge checkKnowledge check · 17 questions
- 6.A clinic offline at dawn and an approval-gated firewall passwordScenario
- 7.Final exam9 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
- clientst0r README: positioning, security summary, updating and backups, limitations
- clientst0r FEATURES.md: vault, native PSA (SLA engine, workflow rules, contracts, quotes, invoices, approvals), integrations, data import
- clientst0r CHANGELOG.md: release history (vault access rules v3.17.163, approvals and break-glass v3.17.241/247, SLA pause and breach recording v3.17.563, billing fixes v3.17.561 to v3.17.581, multi-organization API v3.17.496)
- clientst0r docs/ROADMAP.md: phases 18 (multi-location hierarchy), 31 (vault access rules) and 37 (vault approval and break-glass)
- clientst0r ORGANIZATIONS.md: organizations, user types, roles, role templates, API access control
- clientst0r user guide: password vault (generator, TOTP, import and export, access log)
- clientst0r SECURITY.md: security policy, audit logging, API keys
- clientst0r psa/INTEGRATION_MAP.md: native PSA versus PSA integrations, feature flags, vault rule
- MSP Zero: clientst0r tool page
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.