AYA CoVault is the secure home for our files, folders, projects and the conversations around them. The documents sit on storage the organization owns. The permissions and the audit trail sit in a database the organization runs. Nothing leaves infrastructure we control, and nothing happens without a name against it.
Designed, built and run in-house by AYA Collective · Self-hosted on storage the organization owns, with its own database holding every permission and audit record
Three minutes, from signing in to the audit log: how a document is stored, shared, reviewed and accounted for, and how the work around it is run.
AYA CoVault walkthrough
Ask where a document lives and the honest answer, in most organizations, is: in an email, somewhere.
It was attached once, replied to four times, and forwarded to somebody who needed it. There are now five copies of it and no reliable way to tell which one is current. Nobody decided to work this way. It is simply what happens when the tool everyone already has is a messaging system, and the job in front of them is filing.
The arrangement fails quietly, and in four directions at once. Version drift: the copy someone works from is the one that reached them, not the one that is right. No revocation: an attachment sent is an attachment kept, readable long after the recipient has moved on. No audit trail: when it genuinely matters who saw a document and when, an inbox cannot answer the question. And departure risk: whatever a colleague held in their mailbox leaves when they do.
CoVault replaces the arrangement rather than policing it. A document has one location. Access is granted to people rather than copied to them, which means it can also be taken back. Every open, download, share and deletion is written down with a name and a timestamp against it. The answer to who has this? becomes a screen, not a guess.
CoVault stores nothing itself. The bytes of every document sit in file storage AYA owns and administers. What CoVault owns is everything else: who may see a file, who did see it, which version was approved, what the folder is called, when it falls due for clean-up. That lives in the organization’s own database, on infrastructure it runs.
The separation is deliberate. A file store that also owns permissions is a file store you have to trust twice: once with your documents, and again with your rules about them. Splitting the two means the storage layer holds bytes and nothing else. It has no opinion about who you are.
Authority sits in a database AYA can query, back up, audit and reason about, and it answers identically whether the request arrived from the web app, an administrator, or a shared link.
It also means nothing has to leave. There is no vendor in the middle keeping a copy of the organization’s documents on terms it sets and can change. The storage is AYA’s, the database is AYA’s, and the audit log that ties them together is AYA’s.
The storage layer never decides anything. Ask it for a file directly and it has no idea whether you should have it, which is exactly why CoVault, not the store, is the thing that answers.
One application, nine modules, and a single gate every request passes through. The live parts (presence, chat, voice and co-editing) sit alongside it rather than outside it, and everything inside the boundary runs on infrastructure the organization controls.
Scroll the diagram sideways to see the whole system.
Most organizations assemble this out of four subscriptions that do not know about each other, and a fifth for the audit trail. CoVault is one application, so a permission means the same thing everywhere in it.
List and grid views with real thumbnails, a column chooser, multi-select move, streamed zip download, starring, and a details panel with versions.
Share with people or groups, stage a batch before committing it, or issue a link with its own restrictions. Every grant is visible and reversible.
Send a document to named reviewers. The decision is recorded against the exact version approved, and shows beside the filename thereafter.
By name, and inside the documents themselves, including optical character recognition over scanned material, with the matched extract shown in context.
Portfolio health, board, list with saved views, timeline with dependencies, calendar, whiteboards, allocations and a workload view across everyone.
An organizational wall with urgency levels, a chosen audience, acknowledgement receipts and a record of exactly who has read what.
Word, Excel and PowerPoint edited in the browser, several people at once, with PDF viewing alongside. The vault keeps the versions.
Talk beside the document you are both in: text, emoji, reactions, voice notes, and a peer-to-peer audio huddle when typing is too slow.
Users, invitations, groups, capability templates, per-person overrides, retention settings, and an audit log filterable by user, action and date.
Nobody should need training to find a document. CoVault borrows the patterns people already know from Drive and Dropbox, and then tells the truth about access, which those tools mostly do not.
Adding people is staged rather than applied one at a time: gather everyone the document needs, see the whole list, then commit it in one action. Because access is a grant and not a copy, the same screen that gave it can withdraw it.
Records are the output of work, so the work lives in the same system. Projects carry a board, a filterable list, a timeline with real dependencies, a calendar, whiteboards, and a portfolio view whose health is calculated rather than self-reported.
A notice board with urgency levels, a chosen audience, and the part that usually goes missing: an acknowledgement receipt. “It went out in an email” is not the same as knowing who read it.
Users, invitations, groups, capability templates, per-person overrides, sign-in domains, retention and upload limits. Underneath all of it, a log of every action taken against every item, filterable by who, what and when.
A vault the organization runs itself is usually where collaboration stops: you keep control, and everyone goes back to email to talk about the file. CoVault keeps the conversation attached to the document. Several people edit it at once, chat sits beside it, and when typing is too slow a voice huddle connects them directly.
Presence, chat and the huddle are all scoped to the item you are in, so what you can see of a session is exactly what your access to the file already allowed.
CoVault starts from no. Every capability (uploading, deleting, sharing, approving a document, reading the audit log) is denied to everyone until something grants it. There is no implicit permission anywhere in the system, and no role that quietly means everything.
Grants arrive by three routes. A role carries a default set: a Member works with their own content, a Manager also approves documents and browses the whole folder tree, an Admin also runs users, groups and settings. A template is a reusable bundle applied to many people at once. An override adjusts one person, in either direction, on top of whatever their role gave them.
What people actually meet is quieter than that. CoVault hides what you cannot use rather than showing you a control that will refuse you. A Member never sees an Administration menu that would only turn them away. The exception is deliberate: when a Manager reaches a folder they cannot open, it is marked locked rather than hidden, and the page offers to ask the owner. That request is approved or declined on a screen of its own, and both outcomes are notified.
Audit-grade is a specific claim, not a mood. It means every action against every item is recorded with who did it, what they did, when, and to which file, and that the record is produced by the system rather than by the person being recorded.
It has consequences you can see. A document sent for review carries its decision against the exact version that was approved, so “we signed this off” names a file rather than a filename. Deleted items go to a recycle bin that shows the countdown to permanent purge, so deletion stays reversible until it is deliberately not. Retention rules clean up on a stated schedule rather than an assumed one. Shared links list themselves: every link anyone has issued, what it permits, and how often it has been used.
And the log is not a privileged back door. Reading it is a capability like any other: granted to named people, and recorded when they do.
A self-hosted vault is usually a compromise: you keep control and give up the conveniences. These are the two that most often decide it.
Text is extracted and indexed on upload, and scanned pages go through optical character recognition, so a PDF nobody could search before becomes findable by what it says.
Boards, a filterable list with saved views, a timeline that understands dependencies, a calendar and a whiteboard, all against the same permissions, and linked to the same files.
Passwordless by default, restricted to approved organization domains.
Upload, organize, edit online, and run the projects the documents belong to.
Grant access to named people, groups or a restricted link, and see it listed.
Send for review; the decision binds to the exact version that was approved.
Every action is in the log, filterable by who, what and when.
Nothing exotic, and nothing that cannot be run by the organization that owns it.
These are starting points. Any capability can be granted or removed per role, per template or per person, so a given deployment may look nothing like this table.
Upload, download, edit online, rename, move and delete their own content; create folders; share with people and links. The role every new account is created with.
Everything a Member has, plus approving documents, browsing the whole folder tree, and managing folder templates. Sees locked folders, and can ask for access from there.
Everything a Manager has, plus users, invitations, groups, permissions, the audit log and settings. Cannot create other administrators.
Everything, always. The system account that ships with the deployment. It is the only one that can create administrators, and it is not listed on the permissions screens.
AYA built CoVault because the alternatives asked us to keep our records somewhere we did not control, under terms we did not set. If that is your problem as well, we are glad to talk about how it was done, and what it would take for you.