Automic Vault

Automic Vault 4.12.2 · macOS

Automic Vault manual

Install Automic Vault, understand the operator console, and find the right reference.

Automic Vault manual

This is the user and operator manual for Automic Vault 4.12.2 on macOS, checked against the source on September 25, 2026. UI screenshots show 3.16.0 and illustrate older layouts; follow the text for current behavior. Use your installed build's help and catalogs to check its command surface.

Automic Vault does more than store a Secret. It authorizes a complete operation: the Verified Launcher, Gate Client, Target, command and arguments, working directory, requested Secret Names, and selected Value sources. If allowed, it applies the Secret to the Target without displaying the stored Value.

Install and verify

brew install --cask automic-vault/isotopes/automic-vault
open /Applications/Automic\ Vault.app
av --version
av help

You may instead use the latest release or review the website installer. The menu bar app owns Approval UI and Authorization Policy. Open it before an operation that needs Approval: av open. Complete the app's attended CLI installation when prompted; installing the protected CLI requires administrator authentication.

Start here

Scan the Mac, save one Value through the hidden terminal prompt, and apply it only to the Target that needs it:

av scan --show-all
av save GH_TOKEN
av inject +GH_TOKEN gh auth status

av save defaults to hidden single-line terminal input. Since 4.6.0, --multiline accepts hidden multiline input and --stdin reads exact redirected input to EOF. See saving safely. Do not remove the old credential until the approved command succeeds. For a Tool with a supplied hardener, prefer its Tool-specific flow:

av hardeners --json | jq '.hardeners[] | select(.applicable) | {name, hardened}'
av harden gh
av doctor gh

Interface map

The main window is an operator console for exposure, authority, live use, and evidence. Global search filters the selected destination; Refresh recomputes live state. The Overview summarizes Findings, hardening, recent activity, and available updates. The sidebar separates four jobs:

Job Destinations Question answered
Discover Detectors, Doctor Where is supported insecure state, and is the protected route healthy?
Establish authority Hardened Tools, Authorization Gates, Blessed Scripts, Launcher Bundles Which exact code and operations can ask for authority?
Operate Secrets, Active Proxies Which named Values exist, and which proxy sessions are live?
Audit and configure Authorization History, Settings Why was an operation allowed or denied, and which approval routes are enabled?

Counts are live summaries, not security conclusions. A zero beside Active Proxies means no proxy session is registered now; it does not prove that no Target currently holds a Value it received earlier. A clean Doctor view means the checks implemented by that build passed; it is not a whole-machine attestation.