Q1. What is the problem that you are trying to solve?
In the current Passbolt permission model, users with sufficient privileges (e.g. Owner or Can Update) can move passwords from a shared folder into another folder or their personal workspace.
This can result in passwords effectively disappearing for the original owner or other team members. While the password still exists, it is no longer visible in the original shared location and may not be discoverable through normal folder navigation. From an operational perspective, this creates the impression that the credential has vanished.
A typical scenario:
- User A creates a password in a shared folder.
- User A shares the folder with User B.
- User B moves the password into another folder or their personal workspace.
- User A can no longer find the password in the shared folder and may lose practical access to it.
The problem would be solved if shared passwords could not unintentionally become inaccessible to the people or teams that originally owned and managed them.
Q2. Who is impacted?
This affects any organization using Passbolt for collaborative password management, particularly:
- IT Operations teams
- Security teams
- Development teams
- Infrastructure and cloud teams
- Organizations managing shared service accounts, API credentials, or emergency accounts
The larger the organization and the more shared credentials are used, the greater the operational risk becomes.
Q3. Why is it important and/or urgent?
This issue can directly impact business continuity and incident response.
Shared credentials are often required during:
- Production outages
- Security incidents
- Emergency maintenance
- Vendor integrations
- Service account troubleshooting
If a credential has been moved by another user and is no longer accessible to the original owners, recovery efforts may depend on a single individual who could be:
- On vacation
- Sick
- No longer employed
- Simply unavailable when the credential is urgently needed
From a risk perspective, this creates a potential single point of failure for critical business credentials.
The question is not whether this situation will occur, but when.
Q4. What is your proposed solution? (optional)
Any of the following approaches would significantly reduce the risk:
Option 1: Folder Protection
Allow administrators to configure shared folders where passwords cannot be moved outside of the folder structure.
Option 2: Preserve Existing Sharing
When a password is moved, all existing sharing relationships and permissions remain intact by default.
Option 3: Ownership Retention
Ensure that the original creator or designated folder owner always retains visibility to passwords created within their managed shared folders.
Option 4: Administrative Policies
Introduce configurable settings such as:
- Prevent moving passwords from shared folders
- Prevent moving passwords into personal workspaces
- Require additional approval before ownership changes
- Lock passwords to a shared workspace