# Admin can view stored passwords in organization

**URL:** <https://vaultwarden.discourse.group/t/admin-can-view-stored-passwords-in-organization/3119>\
**Category:** Help\
**Created:** [November 20, 2023, 10:40am UTC](https://vaultwarden.discourse.group/t/admin-can-view-stored-passwords-in-organization/3119 "2023-11-20T10:40:29Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![goncalo.correia](https://avatars.discourse-cdn.com/v4/letter/g/ccd318/32.png) [@goncalo.correia](https://vaultwarden.discourse.group/u/goncalo.correia)\
**Post date:** [November 20, 2023, 10:40am UTC](https://vaultwarden.discourse.group/t/admin-can-view-stored-passwords-in-organization/3119/1 "2023-11-20T10:40:29Z")

</div>

I’m creating an organization for my employees to store their passwords. What I like about it is that I can define policies regarding password strength for entries and check them for breaches and weak passwords. The problem is that if I, as an administrator, go to the web vault → organizations → vault I can see every password stored there. A solution is to let them have their own personal vault, but then I can’t enforce policies, check for breaches and weak passwords. Is there anyway to prevent the administrator from viewing certain collections within an organization, so people can have their own “personal vault” in the organization?

---

<div class="post-metadata">

**Author:** ![BlackDex](https://yyz2.discourse-cdn.com/free1/user_avatar/vaultwarden.discourse.group/blackdex/32/8_2.png) [@BlackDex](https://vaultwarden.discourse.group/u/BlackDex)\
**Post date:** [November 20, 2023, 7:06pm UTC](https://vaultwarden.discourse.group/t/admin-can-view-stored-passwords-in-organization/3119/2 "2023-11-20T19:06:38Z")

</div>

That is not how Bitwarden works.

The sentence to let people have there own personal vault within the organization just doesn’t match.

You either have a personal vault with items you can only see your self, or you put items into an organization which are shared across a bunch of people.

I would suggest to read the Bitwarden documentation [Organizations Quick Start | Bitwarden Help Center](https://bitwarden.com/help/getting-started-organizations/)

---

<div class="post-metadata">

**Author:** ![ShadowPulse](https://yyz2.discourse-cdn.com/free1/user_avatar/vaultwarden.discourse.group/shadowpulse/32/1237_2.png) [@ShadowPulse](https://vaultwarden.discourse.group/u/ShadowPulse)\
**Post date:** [November 21, 2023, 10:55am UTC](https://vaultwarden.discourse.group/t/admin-can-view-stored-passwords-in-organization/3119/3 "2023-11-21T10:55:06Z")

</div>

Many password management tools allow for role-based access control. Check if your tool lets you customize admin privileges, restricting access to certain collections. This way, employees can have their personal vaults while you maintain oversight on policy enforcement.

---

<div class="post-metadata">

**Author:** ![BlackDex](https://yyz2.discourse-cdn.com/free1/user_avatar/vaultwarden.discourse.group/blackdex/32/8_2.png) [@BlackDex](https://vaultwarden.discourse.group/u/BlackDex)\
**Post date:** [November 21, 2023, 5:04pm UTC](https://vaultwarden.discourse.group/t/admin-can-view-stored-passwords-in-organization/3119/4 "2023-11-21T17:04:33Z")

</div>

Bitwarden supports RBAC but an admin or owner has access to all items of een organization. But they never have access to the personal vaults of the users.

---

<div class="post-metadata">

**Author:** ![goncalo.correia](https://avatars.discourse-cdn.com/v4/letter/g/ccd318/32.png) [@goncalo.correia](https://vaultwarden.discourse.group/u/goncalo.correia)\
**Post date:** [January 18, 2024, 10:08am UTC](https://vaultwarden.discourse.group/t/admin-can-view-stored-passwords-in-organization/3119/5 "2024-01-18T10:08:47Z")

</div>

I was searching in the bitwarden forums and found this option - “This user can access only the selected collections”. This isn’t available in vaultwarden, but would certainly come in handy. Is there a chance that this will be implemented?

![cab28f86ff16bb274ee75ffd43a0d9fa9754a29b_2_690x364](https://global.discourse-cdn.com/free1/uploads/vaultwarden/original/2X/e/e042266cdaaa103c91376f5bb90ff6b2f325d87e.png)

> **[Ability to remove self from someone else's organization/collection](https://community.bitwarden.com/t/ability-to-remove-self-from-someone-elses-organization-collection/32993/10)**
>
> If you’re seeing all their collections in clients other than the Web Vault - you can change that setting for your user. In the Web Vault under Manage \> People, click on your user and change it to “This user can access only the selected...

---

<div class="post-metadata">

**Author:** ![gerardv514](https://avatars.discourse-cdn.com/v4/letter/g/439d5e/32.png) [@gerardv514](https://vaultwarden.discourse.group/u/gerardv514)\
**Post date:** [January 19, 2024, 1:55am UTC](https://vaultwarden.discourse.group/t/admin-can-view-stored-passwords-in-organization/3119/6 "2024-01-19T01:55:04Z")

</div>

It may not look exactly the same, but the functionality is there in Vaultwarden.

In the organization, under members, click 3 dots to right of a user and select collections. From there you can check off to allow user to have all collections even going forward, and below that you can individually add a collection and assign it view or edit or both permissions.
