In daily use across AYA Collective

Every document the organization owns, somewhere it actually controls

AYA CoVault is the secure home for our files, folders, projects and the conversations around them. The documents sit on storage the organization owns. The permissions and the audit trail sit in a database the organization runs. Nothing leaves infrastructure we control, and nothing happens without a name against it.

Passwordless sign-in Denied until granted Every action audited
covault · ayacollect.org
The CoVault dashboard, showing activity tiles, storage and who is in the vault
Every action recordedWho, what, when, which file
Storage you ownNo vendor holds a copy

Designed, built and run in-house by AYA Collective · Self-hosted on storage the organization owns, with its own database holding every permission and audit record

0%
Of actions written to the audit log
0
Files stored outside storage the organization owns
0
Roles, with every capability grantable per person
0
Modules in one system, not nine subscriptions
See it in action

A walkthrough of AYA CoVault

Three minutes, from signing in to the audit log: how a document is stored, shared, reviewed and accounted for, and how the work around it is run.

AYA CoVault walkthrough

Why it exists

The filing system most organizations actually use is the inbox

Ask where a document lives and the honest answer, in most organizations, is: in an email, somewhere.

It was attached once, replied to four times, and forwarded to somebody who needed it. There are now five copies of it and no reliable way to tell which one is current. Nobody decided to work this way. It is simply what happens when the tool everyone already has is a messaging system, and the job in front of them is filing.

The arrangement fails quietly, and in four directions at once. Version drift: the copy someone works from is the one that reached them, not the one that is right. No revocation: an attachment sent is an attachment kept, readable long after the recipient has moved on. No audit trail: when it genuinely matters who saw a document and when, an inbox cannot answer the question. And departure risk: whatever a colleague held in their mailbox leaves when they do.

CoVault replaces the arrangement rather than policing it. A document has one location. Access is granted to people rather than copied to them, which means it can also be taken back. Every open, download, share and deletion is written down with a name and a timestamp against it. The answer to who has this? becomes a screen, not a guess.

Documents in an inbox

  • Five copies, one truthWhichever version reached you is the one you edit.
  • Nothing can be withdrawnAccess ends only when the recipient deletes the mail, which they will not.
  • No record of who read whatThe question cannot be answered after the fact.
  • It leaves with the personA mailbox is not an organizational asset.

Documents in CoVault

  • One location, one current versionWith every earlier version kept and named.
  • Access is granted, not copiedSo it can be reviewed, narrowed, or removed.
  • Every action attributableWho, what, when, and against which item.
  • It belongs to the organizationPeople change; the record does not move.
Where your files live

The store holds bytes. The database holds authority.

CoVault stores nothing itself. The bytes of every document sit in file storage AYA owns and administers. What CoVault owns is everything else: who may see a file, who did see it, which version was approved, what the folder is called, when it falls due for clean-up. That lives in the organization’s own database, on infrastructure it runs.

The separation is deliberate. A file store that also owns permissions is a file store you have to trust twice: once with your documents, and again with your rules about them. Splitting the two means the storage layer holds bytes and nothing else. It has no opinion about who you are.

Authority sits in a database AYA can query, back up, audit and reason about, and it answers identically whether the request arrived from the web app, an administrator, or a shared link.

It also means nothing has to leave. There is no vendor in the middle keeping a copy of the organization’s documents on terms it sets and can change. The storage is AYA’s, the database is AYA’s, and the audit log that ties them together is AYA’s.

Infrastructure the organization controls Browser A member of staff CoVault ASP.NET Core decides everything Database Permissions · metadata Audit · projects File storage organization-owned bytes only, no authority

The storage layer never decides anything. Ask it for a file directly and it has no idea whether you should have it, which is exactly why CoVault, not the store, is the thing that answers.

The whole system

Every part of CoVault, and what it is allowed to touch

One application, nine modules, and a single gate every request passes through. The live parts (presence, chat, voice and co-editing) sit alongside it rather than outside it, and everything inside the boundary runs on infrastructure the organization controls.

AYA CoVault, end to end Request path, live services, and the two places state is kept
WHO IS USING IT THE APPLICATION WHERE STATE IS KEPT Infrastructure the organization controls Staff browser work email, no password A colleague in the same document Guest a link with its own limits voice, peer to peer Every request passes through here 1 · Sign-in single-use code by email approved domains only 2 · Capability gate denied until granted role · template · override SignalR hub presence, chat boards, whiteboards voice signalling Document server Word, Excel, slides edited in the browser several at once Search index text read on upload OCR over scans shown in context AYA CoVault ASP.NET Core · one application, nine modules Files Sharing Review Search Projects Notices Co-editing Admin Audit writer · who, what, when, which file Server-rendered Razor with progressive enhancement. The same permission means the same thing in every module. Email sign-in codes, share and access notices, review requests, notice alerts Database permissions · metadata the audit log · projects notices, chat, versions all the authority File storage the bytes of every file, owned and administered by the organization no authority at all

Scroll the diagram sideways to see the whole system.

The request path. Nothing reaches a module until sign-in and the capability gate have both answered. Voice travels straight between the two browsers. Only the signalling that sets it up passes through the hub. Everything inside the boundary runs on infrastructure the organization owns and administers.
What it does

Nine things, in one system, under one set of permissions

Most organizations assemble this out of four subscriptions that do not know about each other, and a fifth for the audit trail. CoVault is one application, so a permission means the same thing everywhere in it.

Files and folders

List and grid views with real thumbnails, a column chooser, multi-select move, streamed zip download, starring, and a details panel with versions.

Sharing and access

Share with people or groups, stage a batch before committing it, or issue a link with its own restrictions. Every grant is visible and reversible.

Review and approval

Send a document to named reviewers. The decision is recorded against the exact version approved, and shows beside the filename thereafter.

Search

By name, and inside the documents themselves, including optical character recognition over scanned material, with the matched extract shown in context.

Projects

Portfolio health, board, list with saved views, timeline with dependencies, calendar, whiteboards, allocations and a workload view across everyone.

Notices

An organizational wall with urgency levels, a chosen audience, acknowledgement receipts and a record of exactly who has read what.

Co-editing

Word, Excel and PowerPoint edited in the browser, several people at once, with PDF viewing alongside. The vault keeps the versions.

Session chat and live voice

Talk beside the document you are both in: text, emoji, reactions, voice notes, and a peer-to-peer audio huddle when typing is too slow.

Administration and audit

Users, invitations, groups, capability templates, per-person overrides, retention settings, and an audit log filterable by user, action and date.

A file browser that behaves the way you already expect

Nobody should need training to find a document. CoVault borrows the patterns people already know from Drive and Dropbox, and then tells the truth about access, which those tools mostly do not.

  • Hover a row for its actions; select several for a command bar that offers only what applies to all of them
  • Every folder states its access (“Only you”, “Shared · 3”) on the row, not three clicks away
  • Details panel with versions, activity and access in one place
  • Destructive actions always name their target and their consequence
covault · my files
The CoVault file browser, showing a folder listing with per-row access states

Sharing that you can take back

Adding people is staged rather than applied one at a time: gather everyone the document needs, see the whole list, then commit it in one action. Because access is a grant and not a copy, the same screen that gave it can withdraw it.

  • People and groups in one type-ahead, with per-recipient notification
  • Links carry their own restrictions, and list themselves under My shares with usage counts
  • Manage access is a screen of its own: everyone with access, and how they got it
  • Locked folders are visible to managers, who can ask the owner, and be approved or declined on the record
covault · share
The CoVault share dialog, with link settings above named people and groups

The work around the documents, not just the documents

Records are the output of work, so the work lives in the same system. Projects carry a board, a filterable list, a timeline with real dependencies, a calendar, whiteboards, and a portfolio view whose health is calculated rather than self-reported.

  • Health is derived from overdue and blocked work; nobody types “green” into a box
  • Attach a vault file to a task and it links the file; it does not make a second copy
  • My work gathers your tasks across every project; Workload shows the same data per person
  • Project folders are group-backed, so membership and file access stay in step
covault · board
A CoVault project board with tasks in columns
covault · timeline
The CoVault project timeline, showing dated work and a dependency between two tasks

Saying something to everyone, and knowing it landed

A notice board with urgency levels, a chosen audience, and the part that usually goes missing: an acknowledgement receipt. “It went out in an email” is not the same as knowing who read it.

  • Post to everyone, or to named people and groups, with the audience stated in plain language before you send
  • Who acknowledged, and when, on the notice’s own page
  • Live presence throughout: who is in the vault, and who is in this document with you
  • Session chat and a voice huddle beside the file, for when typing is too slow
covault · notices
The CoVault notice board, with a pinned notice at the head of the wall
covault · document session
A document open in the online editor, with a rail showing who else is in the session

Administration that can answer questions afterwards

Users, invitations, groups, capability templates, per-person overrides, sign-in domains, retention and upload limits. Underneath all of it, a log of every action taken against every item, filterable by who, what and when.

  • Invitations admit one named address, including one outside the organization’s domains
  • Deleted items sit in a recycle bin showing the countdown to permanent purge
  • Folder templates rebuild a standard folder tree, with its group access already attached
  • Reading the audit log is itself a capability: granted, not assumed
covault · audit log
The CoVault audit log, filterable by user, action and date range
Live collaboration

The document, the conversation and the voice, on one screen

A vault the organization runs itself is usually where collaboration stops: you keep control, and everyone goes back to email to talk about the file. CoVault keeps the conversation attached to the document. Several people edit it at once, chat sits beside it, and when typing is too slow a voice huddle connects them directly.

covault · quarterly narrative 2026 Q2.docx · session
Quarterly narrative 2026 Q2.docx Editing in the browser · every version kept by the vault
AM KO SA 3 people in this document
Session chat
Kwesi O.
The district table is still on the June extract, not July.
You
Replacing it now. Same columns, or add the outreach figure?
👍 1
Kwesi O. · voice note
0:14
Serwaa is typing
Live voice
AM KO SA
Your microphone Mute Peer to peer · 3 in the huddle

Presence, chat and the huddle are all scoped to the item you are in, so what you can see of a session is exactly what your access to the file already allowed.

Presence, everywhere One live connection carries who is in the vault, who is in this folder, and who is in this document beside you. The same channel moves project boards and whiteboards as they change, so nobody is looking at a stale screen. SignalR
Editing together Word, Excel and PowerPoint open in the browser for several people at once, with named cursors and a rail showing who else is in the session. The document goes back to the vault with the version history intact. Document server
Text, voice notes and a huddle Chat sits beside the file, with emoji, reactions and recorded voice notes that play back with their waveform. The huddle is a live audio call between browsers, with a meter showing your own microphone so you can see that you are being heard. WebRTC, peer to peer
Permissions

Everything is denied until something grants it

CoVault starts from no. Every capability (uploading, deleting, sharing, approving a document, reading the audit log) is denied to everyone until something grants it. There is no implicit permission anywhere in the system, and no role that quietly means everything.

Grants arrive by three routes. A role carries a default set: a Member works with their own content, a Manager also approves documents and browses the whole folder tree, an Admin also runs users, groups and settings. A template is a reusable bundle applied to many people at once. An override adjusts one person, in either direction, on top of whatever their role gave them.

What people actually meet is quieter than that. CoVault hides what you cannot use rather than showing you a control that will refuse you. A Member never sees an Administration menu that would only turn them away. The exception is deliberate: when a Manager reaches a folder they cannot open, it is marked locked rather than hidden, and the page offers to ask the owner. That request is approved or declined on a screen of its own, and both outcomes are notified.

Upload filesRole
Create foldersRole
Share with peopleRole
Edit onlineRole
Approve documentsTemplate
Browse all foldersTemplate
Manage folder templatesTemplate
Read the audit logOverride
Manage usersNone
Change settingsNone
Manage groupsNone
Purge permanentlyNone
Granted, and visible to this person Still denied, and hidden from them entirely
Accountability

What “audit-grade” actually means

Audit-grade is a specific claim, not a mood. It means every action against every item is recorded with who did it, what they did, when, and to which file, and that the record is produced by the system rather than by the person being recorded.

It has consequences you can see. A document sent for review carries its decision against the exact version that was approved, so “we signed this off” names a file rather than a filename. Deleted items go to a recycle bin that shows the countdown to permanent purge, so deletion stays reversible until it is deliberately not. Retention rules clean up on a stated schedule rather than an assumed one. Shared links list themselves: every link anyone has issued, what it permits, and how often it has been used.

And the log is not a privileged back door. Reading it is a capability like any other: granted to named people, and recorded when they do.

Audit log · live
Two things people do not expect

It reads inside the documents, and it runs the work

A self-hosted vault is usually a compromise: you keep control and give up the conveniences. These are the two that most often decide it.

Text is extracted and indexed on upload, and scanned pages go through optical character recognition, so a PDF nobody could search before becomes findable by what it says.

To do
Draft the quarterly narrativeHigh
In progress
Done
Sign off the data requestApproved
Reconcile district returnsMoving

Boards, a filterable list with saved views, a timeline that understands dependencies, a calendar and a whiteboard, all against the same permissions, and linked to the same files.

How it works

From signing in to being accountable for it

1

Sign in

Passwordless by default, restricted to approved organization domains.

2

Work

Upload, organize, edit online, and run the projects the documents belong to.

3

Share

Grant access to named people, groups or a restricted link, and see it listed.

4

Approve

Send for review; the decision binds to the exact version that was approved.

5

Account

Every action is in the log, filterable by who, what and when.

Built on

Ordinary, durable parts

Nothing exotic, and nothing that cannot be run by the organization that owns it.

ASP.NET CoreServer-rendered Razor with progressive enhancement
Relational databaseMetadata, permissions, projects and audit
Owned file storageThe store: bytes only, no authority
SignalRLive presence, board updates, chat and whiteboards
WebRTCPeer-to-peer voice between people in a session
ONLYOFFICEIn-browser co-editing of Word, Excel and PowerPoint
Full-text & OCRContent search, including scanned documents
ExcalidrawThe project whiteboard, versioned by CoVault
Roles

Four defaults, and none of them are final

These are starting points. Any capability can be granted or removed per role, per template or per person, so a given deployment may look nothing like this table.

Member

Upload, download, edit online, rename, move and delete their own content; create folders; share with people and links. The role every new account is created with.

Manager

Everything a Member has, plus approving documents, browsing the whole folder tree, and managing folder templates. Sees locked folders, and can ask for access from there.

Admin

Everything a Manager has, plus users, invitations, groups, permissions, the audit log and settings. Cannot create other administrators.

SuperUser

Everything, always. The system account that ships with the deployment. It is the only one that can create administrators, and it is not listed on the permissions screens.

Built for one organization. Not limited to one.

AYA built CoVault because the alternatives asked us to keep our records somewhere we did not control, under terms we did not set. If that is your problem as well, we are glad to talk about how it was done, and what it would take for you.