Your account and access

Open My Account from the user menu to manage your profile and understand your access.

Update your profile

  1. Open the account menu and select My Account.
  2. Update your first name, middle initial, last name, or phone number as needed.
  3. Choose the time zone RiskVault should use for displayed dates and times.
  4. Choose the light, dark, or system appearance. System follows your operating system's setting.
  5. If available, set your AI autocomplete preference.
  6. Save your changes.

Your email address is account information and is not changed through the normal profile form.

Image needed: My Account profile page with the time-zone and appearance settings highlighted.

Password and multifactor authentication

People using a local RiskVault account can change their password, request a reset link, and configure an authenticator app.

To set up authenticator-app multifactor authentication:

  1. Open My Account and find the security or multifactor section.
  2. Start authenticator setup.
  3. Scan the displayed QR code with your authenticator app.
  4. Enter the verification code generated by the app.
  5. Confirm setup and store any recovery information according to your organization's policy.

If you sign in through Microsoft, Google, Okta, or another identity provider, password and authentication-factor changes may need to be made with that provider.

Your organization can require MFA for administrators or for everyone. If it applies to you and you haven't enrolled yet, RiskVault sends you to the MFA setup page and you can't continue until you finish. People who sign in only through an external identity provider, and have no local RiskVault password, are exempt because their provider normally enforces its own MFA.

When the Terms of Use or Privacy Policy change

Your organization may occasionally revise its Terms of Use or Privacy Policy. When that happens, the next time you open RiskVault you land on an Updated Terms of Use & Privacy Policy page before you can go anywhere else.

  1. Open the linked Terms of Use and Privacy Policy. Each opens in a new tab, so you don't lose your place. The same two documents are always linked in the application footer.
  2. Check the line near the bottom of the page. It states exactly which version you're accepting and its effective date.
  3. Select Accept & Continue. RiskVault records your acceptance with the version and a timestamp, and takes you where you were going.

Selecting Sign out leaves without accepting. That's a valid choice, but you can't use RiskVault again until you return and accept. If you have questions first, the page shows your organization's legal contact address.

You only see this page when the version has actually changed. After you accept, RiskVault doesn't ask again until the next revision. If an integration or API request reaches RiskVault before you've accepted a new version, it gets a "terms acceptance required" response. Sign in through the browser once and accept to clear it for the integration too.

Check your effective claims

Open My Account > My Claims to see the capabilities currently associated with your account. Claims may come through a role or policy rather than being assigned directly.

Use this page when a menu item is missing, a button is unavailable, RiskVault displays Access Denied, or a workflow action does not appear.

Image needed: My Claims page showing claim groups and enabled claims, with no personal information visible.

If access seems wrong

  1. Confirm you are signed into the expected account.
  2. Check My Claims for the capability named in the page or error.
  3. Confirm you have access to the specific risk, asset, or business unit.
  4. Check whether the action is allowed in the record's current workflow state.
  5. Sign out and back in if an administrator recently changed your access.
  6. If the problem remains, send the administrator the page name, RR number if applicable, action attempted, and exact error message.

Do not ask for a broad administrator role just to solve one missing action. A targeted policy or per-risk permission is safer and easier to audit.

For external AI connections, see What MCP is.

Manage personal risk templates

The account page can list templates you own.

  1. Open the personal templates section.
  2. Review the template name and purpose.
  3. Delete an obsolete personal template when it should no longer appear during creation.

Shared and system templates are managed separately. Deleting your personal copy does not remove an administrator-managed template with a similar name.