Skip to content
Docs

9 results

SDK guides

Grant credentials to an employee

Seren Passwords connects encrypted fields to one employee without exposing plaintext to Seren. Core derives the request, and each required participant signs the exact policy in an unlocked browser.

Step 1

Review the employee requirements

Open the employee in Seren Desktop or Seren Employees. Review the credential fields derived from its manifest and connected services. Make sure that the active revision contains the expected requirements.

Step 2

Start the Passwords setup

Start the credential setup from the employee details. Open the Passwords launch link before it expires. Keep this link private because it carries short-lived setup access.

Step 3

Map and sign the required fields

Unlock Passwords in the browser. Map each required environment field to the correct encrypted item field. Review the destination organization, deployment, revision, access level, and participant role. Then sign the contribution locally.

Do not add a personal Seren API key. Seren gives the employee a limited managed identity for Seren services. Use Passwords for the outside credentials named by the derived requirements.

Step 4

Complete the approval policy

If the policy names more participants, send each participant only their capability link. Each participant must sign in with the named organization, user, and Passwords identity. Complete the required roles, quorum, and stages before the approval expires.

Step 5

Apply and read back the result

Return to Desktop or Employees. Select Refresh and apply.

Seren binds the exact approved mapping to the expected revision. The client reads the deployment back before it reports completion.

If the revision changed, start a new setup. A stale approval cannot attach credentials to a different deployment plan.

Step 6

Review and revoke

Review the access history. If the employee no longer needs the grant, revoke it.

Revocation stops the next material renewal without changing access for other recipients.

The approval window always expires. A deployment-bound, read-only field grant can continue after that window. Renewal still requires the original requester, deployment, revision, employee identity, and key fingerprints.