Skip to main content

Vault secure storage

Save shared logins for lender portals and other sites, and reveal a password when you need it.

Written by Jarrett White

Overview

The Vault is your organization's shared store for login details your team uses every day, such as lender portals, credit bureau access and software accounts. Admins add entries with a name, website, username and password. Team members with access can then look up, reveal and copy the details without passing passwords around by email or chat.

Passwords are encrypted on Broki's servers and are only shown when someone with access selects Reveal or copies them. Admins can add a master code word that must be entered before any password is revealed.

Also called: password manager.

At a glance

The Vault stores shared logins so your team can reveal a password instead of sending it in email or chat.

  • Open it from Settings > Documents & Compliance > Vault. Admins, mortgage advisors, and team members can view entries. Only admins can add, edit, delete, and set the master code word.

  • If a master code word is set, enter it before you Reveal or copy a password. After that, you can reveal passwords for 15 minutes by default, then the Vault shows "Vault re-locked".

  • Only the Password field is hidden until revealed. Don't put secrets in Notes or Password Hint.

  • The 2FA codes panel isn't available yet.

Before you begin

Before you open the Vault, confirm your role and who will hold the master code word.

  • The Vault is under Settings > Documents & Compliance > Vault. You see it if your role includes managing files, company settings or pipeline settings. See Roles and permissions.

  • Admins, mortgage advisors and team members can view entries. Anyone else sees "You do not have access to Vault."

  • Only admins can add, edit and delete entries, and set the master code word.

  • If you plan to set a master code word, decide who will hold it before you start. Non-admins can't reset it.

Step-by-step instructions

These steps add a Vault entry, use it, change it, and set the master code word.

Add a Vault entry

Add a Vault entry when you are an admin and the team needs a shared login.

  1. Go to Settings > Documents & Compliance > Vault.

  2. Select Add Entry. The Add Vault Entry window opens.

  3. Choose a category: Lender Portal, Credit Bureau, Software, Government or Other.

  4. Enter Name (for example "Example Bank Portal"), the website URL, Username and Password. Name, username and password are required.

  5. Optionally use Generate password, add a Password Hint, tick Requires Two-Factor Authentication and record the 2FA Email or 2FA Phone, and add Tags and Notes.

  6. Select Add Entry. You'll see "Entry created".

Find and use a Vault entry

Find and use a Vault entry by searching, then revealing or copying the password.

  1. Go to Settings > Documents & Compliance > Vault.

  2. Use Search vault entries... or the filters All, Lender Portals, Software and Other. Switch between grid and list view with the view buttons.

  3. On the entry, copy the Username, select Reveal to show the password, or use the copy button next to it.

  4. Select Visit site to open the login page in a new tab.

If a master code word is set, Broki asks you to "Enter master code word" before revealing or copying a password. After you enter it correctly, you can reveal passwords without entering it again for the auto-lock period (15 minutes by default). After that you'll see "Vault re-locked", and revealed passwords are hidden again.

Edit or delete a Vault entry

Edit or delete a Vault entry when you are an admin and the login has changed or is no longer used.

  1. On the entry, select edit, change the details in Edit Vault Entry, and select Update. You'll see "Entry updated".

  2. To delete an entry, select delete. Before you continue: this removes the login for everyone in your organization. Confirm "Delete this vault entry?". You'll see "Entry deleted".

Set the master code word

Set the master code word when you are an admin and you want a second check before any password is revealed. Before you continue: once set, every team member must enter the code word to reveal or copy any password, and there's no option to turn the requirement off again.

  1. Select Code Set. The Set Master Code Word window opens.

  2. Enter a code word with at least 8 characters, including an uppercase letter, a lowercase letter and a number. Enter it again to confirm.

  3. Select Set code word.

  4. To change it later, select Code Set again. Enter your Broki login password and select Verify & continue, then enter the new code word and select Update code word.

  5. Share the code word with your team in person or by phone, not in the Vault itself.

Practical examples and other ways to use it

These examples are a shared lender login, a 2FA inbox, and a master code word on sensitive entries.

  • Shared lender portal login. An admin adds "Example Bank Portal" under Lender Portal with the shared username and password. Processors find it under Lender Portals and use Visit site and copy instead of asking for the password.

  • Portal that sends a 2FA code to the office inbox. Tick Requires Two-Factor Authentication and record the 2FA Email, so whoever logs in knows where the code will arrive.

  • Extra protection for sensitive logins. One way to add a second check: set a master code word so a signed-in team member can't reveal passwords without it.

Common mistakes and how to avoid them

These mistakes are forgetting the master code word and storing secrets outside the password field.

  • Forgetting the master code word. After 3 wrong attempts, Broki shows "Too many failed attempts". Admins can select Forgot master code? Use Broki login password. Non-admins see "Contact your administrator if you don't know the code word."

  • Using the Notes field for secrets. Only the Password field is encrypted and hidden until revealed. Keep passwords, PINs and security answers out of Notes and Password Hint.

Troubleshooting

This troubleshooting section covers a locked Vault, missing access, and a password that didn't save.

"Vault locked due to inactivity."

The message "Vault locked due to inactivity." means the auto-lock time passed and revealed passwords are hidden again.

Possible causes

  • No one used the Vault page for the auto-lock time (15 minutes by default). Revealed passwords are hidden again.

To fix

  1. Select Unlock Vault.

  2. Select Reveal again on the entries you need.

"You do not have access to Vault."

The message "You do not have access to Vault." means this role can't open the Vault.

Possible causes

  • Your role isn't one of admin, mortgage advisor or team member.

To fix

  1. Ask an admin to check your role in Settings.

"Failed to reveal password"

The message "Failed to reveal password" means the password couldn't be shown.

Possible causes

  • The password couldn't be loaded, or the entry was saved without one.

To fix

  1. Reload the Vault page and select Reveal again.

  2. If it still fails, ask an admin to edit the entry and enter the password again.

Contact support if it keeps failing for several entries. Include the entry name (not the password), the exact message and the approximate time.

"Entry saved without a password -- edit it to set one" or "Entry saved, but the password could not be updated"

The message "Entry saved without a password -- edit it to set one" or "Entry saved, but the password could not be updated" means the entry details saved and the password did not.

Possible causes

  • The entry details were saved, but the password wasn't stored.

To fix

  1. Edit the entry, enter the password again, and select Update.

Confirm it worked

  • Reveal shows the password.

"Username and password are required"

The message "Username and password are required" means those fields were empty when you saved.

To fix

  1. Fill in Username and Password, then save again.

Tips and best practices

These tips make entries easier to find, stronger when new, and removed when unused.

  • Use tags such as a lender name or "underwriting" so search finds entries quickly as the list grows.

  • Use Generate password when you're creating a new account. The strength meter shows how strong the password is before you save it.

  • Delete entries for portals your organization no longer uses, so old passwords aren't left on file.

Limitations and important behavior

These limits cover who can see an entry, where categories appear, and what the Vault does not do yet.

  • Entries are shared across your whole organization. There's no way to limit a single entry to certain team members.

  • Credit Bureau and Government entries are listed under the Other filter.

  • The list view shows Name, Category, Username and Actions. To reveal a password, use the grid view.

  • The 2FA codes panel on the Vault page isn't available yet. Two-factor codes aren't collected or shown there.

  • The auto-lock time is shown at the bottom of the Vault (for example "Auto-lock in 15 min") and can't be changed.

  • Broki keeps a record each time a password is revealed.

Frequently asked questions

These answers cover whether support can see passwords and how the Vault differs from documents.

Can Broki support see our Vault passwords? Passwords are stored encrypted, and the Vault shows them only to people in your organization who have access. Never send a password to support. Refer to the entry by its name instead.

Is the Vault the same as Smart Docs or the document library? No. The Vault stores login details. Client documents are on the Documents page and each mortgage file's Documents tab.

Related articles

These articles cover Vault settings, roles, account security, and the document library.

Did this answer your question?