Sharing and family

Shared vaults, members and seats

How Family, Business and Enterprise accounts add people, share vaults with roles, and count seats.

Updated 2026-09-29

Family, Business and Enterprise accounts can have several members. Each member has their own private vault, notes and calendar, which nobody else in the account can open while they're a member. On top of that, shared vaults hold what the group needs in common.

Adding people

The account owner invites members by email (on Business and Enterprise, admins can too). Only an address that doesn't already have an Atrium account can be invited: the person creates their account through the invitation, and it belongs to that team. Family includes 4 people. Business is priced per seat with a 10-seat minimum: the price includes ten seats, and you can add more from your billing page. Enterprise (25 seats and up) is set up on custom terms by contacting us.

Roles

Each person in the account is an Owner, Admin or Member. The owner manages seats and billing, and can hand ownership to another member who accepts it. On Family, only the owner invites and removes people. On Business and Enterprise, the owner can let admins (or a custom role) invite and remove members.

Within each shared vault, people can be a manager (manages who has access), a member (uses and adds items) or a viewer (can open items but not change them).

Removing someone

Members can't leave or delete their account on their own: the owner (or, on Business and Enterprise, an admin allowed to) removes them. When someone is removed:

  • their account is deleted and they're signed out everywhere;
  • everything they stored in the team is handed to the owner, flagged "From removed member NAME, removed on DATE", for the owner to review, keep or delete;
  • shared items get new keys, so they can't read anything added later. Anything they already opened may have been copied, so change important shared passwords afterwards.

If the owner deletes the account, the team closes and every member's account is deleted too.

The owner's sealed copy of each member's key

When you join a team, a sealed copy of your account key is kept for the owner. Our servers release it to the owner only if they remove you or close the account; until then the owner can't read your private content. This is enforced by our servers, not by encryption alone, and you're told before you join. Details: What we can and cannot see.

If a member loses both their master password and their Recovery Kit while they're still a member, their private data can't be recovered, by anyone. Keep anything the household or team must not lose in a shared vault.

Audit log

Unlocks, shares and schedule changes are recorded in the audit log, with metadata only. Family keeps it for 1 year, Business for 2 years and Enterprise for 5 years.

More: Accounts for children and Team admin, policies and ownership, including how a member can ask to have their account deleted.