Browse
On this page

When you decide who gets to see a shared credential

The client vault: passwords and secrets clients can see, and ones they cannot

Bluebird Dental's Password Vault holds three kinds of credential, and each one gets a different answer to who can see it. MSP Only keeps a credential for your own techs alone, Visible to all client users hands it to the whole company, and Visible to specific users names one person instead of either extreme. The same three controls decide what shows up in a client's own Password Vault the moment they sign in.

What you will have

  • Turn on MSP Only for a credential meant only for your own techs, never the client.
  • Turn on Visible to all client users for a credential the whole company should be able to read.
  • Leave a credential hidden and see Visible to specific users, the third option, for naming one person instead of everyone.
  • Read the lock icon and the Shared chip on the vault list itself, without opening a single entry.
  • Sign in as a client contact and see their own Password Vault hold only what was actually shared.

Why it works this way

MSP Only always wins. Turning it on immediately clears Visible to all client users and removes anyone already named under Visible to specific users, and it greys out the sharing toggle underneath it so it cannot be switched back on by accident.

Visible to specific users does not need Visible to all client users turned on. Naming someone there shares with that person alone, even while the toggle above still reads Hidden from client portal.

The lock icon and the Shared chip live on the vault list itself. A busy tech can read every row's exposure without opening a single entry.

Steps

  1. Open Microsoft 365 Global Admin and turn on MSP Only.

    The panel reads MSP Only: never shared with the client, and the Visible to all client users toggle below it greys out - it cannot be turned on while MSP Only stays on.

    Note: Turning MSP Only on clears Visible to all client users and removes anyone already named under Visible to specific users.
    Open Microsoft 365 Global Admin and turn on MSP Only.
  2. Open Guest WiFi and turn on Visible to all client users.

    The eye icon turns from grey to green, and the hint underneath changes to All client users can see this item. Add specific users for targeted visibility.

    Open Guest WiFi and turn on Visible to all client users.
  3. Open Practice Owner Personal Banking and leave it hidden.

    Both toggles stay off, and Visible to specific users sits ready underneath with its own Add User button - the third option, for one named person instead of the whole company or nobody.

    Open Practice Owner Personal Banking and leave it hidden.
  4. Back on the vault list, read the lock icon and the Shared chip on each row.

    An amber closed lock is MSP Only, an open grey lock with no chip is hidden, and an open grey lock with a Shared chip is visible to all client users - all three without opening a row.

    Back on the vault list, read the lock icon and the Shared chip on each row.
  5. Sign in as a client contact and open Documentation.

    Priya Shah signs in to Bluebird Dental's own portal, where Documentation sits under Resources in the client sidebar.

    Sign in as a client contact and open Documentation.
  6. Open Password Vault and see only what was actually shared.

    Guest WiFi is the only entry listed - Microsoft 365 Global Admin (MSP Only) and Practice Owner Personal Banking (hidden, nobody named) never appear here.

    Open Password Vault and see only what was actually shared.

The pages behind each click

Other ways to do this

Any documentation type, not only the vault

The same Client Visibility panel - MSP Only, the sharing toggle, and Visible to specific users - sits on Knowledge Base articles, Procedures, Network records, Domains, and Expirations on the same client's Documentation tab.

Use it any time a document, not just a password, should reach only some of a client's people.

If it did not work

  • If Visible to specific users finds nobody when you search a name, this client's Microsoft directory has not synced any accounts yet - Add User only searches synced Microsoft 365 users, not the names on the client's Portal Access list.
  • If an entry still will not show for a client, open it and check MSP Only first - it is the one control that always wins over the other two.

Questions this page answers

What is on this page?

These are the notes your IT provider keeps with you and for you. They can be how-to articles, passwords held on your behalf, steps to follow, or network and domain records. You only see what your provider marked as visible to your company, or linked to you. Your own private space is My Vault. Nothing you put there is shared with your provider.

Was this helpful?

Last validated 2026-09-18