Skip to main content
Password Checkout enhances security by preventing more than one user from using a secret at the same time. While one user has a secret “checked out,” no one else can use it. When that user disconnects, the password is returned to the vault and “checked in” again, making the secret available to the next user. This is valuable when several people share one account: the secret can still only be used by one person at a time, and you can always identify who used it.
This works in the desktop Syteca Connection Manager and, in a similar way, directly from the Management Tool using Syteca Web Connection Manager.

Before you start

To configure Password Checkout, you need the Owner or Editor Role Type for the secret.

Configure Password Checkout

On the Security tab while adding or editing a secret, set the following options:
Security tab showing Requires check out and related Password Checkout options

The Password Checkout options on the Security tab.

To use File transfer with WinSCP, both Requires check out and Change password on check in must be selected.
Change password on check in is independent of Enable remote password rotation (on the Automation tab). Both can be active at once without affecting each other.
Check in automatically after is independent of Allow access without approval during work hours (on the Just In Time Access tab). If both are active, the user is logged off when the first period expires.
Password Checkout is independent of the access approval functionality (Just In Time Access tab). If both are active, the user must request and receive approval and check out the secret before using it.

View checkout status

You can see the checkout status of every secret in two places:
  • On the Password Management page’s secrets grid, the Details column shows the status, with more detail in the tooltip on the Checked out icon. Use the Security filter (via More Criteria) to filter by status.
  • In Syteca Connection Manager, the Details column shows the same status.
The three statuses are:

Add a secret

Configure Password Checkout while creating a secret.

Remote password rotation

Rotate passwords automatically, independently of check-in.

File transfer

Requires both checkout options to be enabled.

View and manage secrets

See checkout status across all secrets.