TL;DR:
Please allow **“Send Copy” for password/credential entries to be sent to arbitrary external email addresses, even when the recipient does not have a Devolutions account.
This would be especially useful for MSPs when securely sharing credentials with customers or external service providers. Existing security features such as expiration, revocation, permissions and audit logging should remain available.
Description
We would like to request an enhancement to the “Send Copy” functionality for password/credential entries in Devolutions Hub.
Currently, when using “Send Copy” on a password entry, it appears that the recipient must have an existing Devolutions account / be an internal user. Sending a copy directly to an arbitrary external email address is not possible.
For MSPs and IT service providers, there are many legitimate use cases where credentials need to be securely shared with external parties who do not have a Devolutions account.
Example use case
An IT service provider stores a customer's credentials in Devolutions Hub.
The customer asks for a specific password or credential, or an external service provider needs temporary access information.
The desired workflow would be:
Password Entry → Send Copy → External Email Address → Send
For example:
admin@customer.com
The recipient should be able to receive and access the shared credential without having to create a Devolutions account.
Suggested functionality
Allow users with the appropriate permissions to enter any valid email address in the “Send Copy” recipient field, including addresses that are not associated with a Devolutions account.
Ideally, the existing security mechanisms should remain in place, for example:
Secure sharing of the credential rather than sending the password as plain text
Optional expiration of the shared copy
Ability to revoke access where applicable
Audit logging of who shared which credential and with whom
Respecting the existing permissions of the user sending the credential
Optional additional authentication / verification for external recipients
The feature could potentially use the existing Devolutions Send mechanism for external recipients, if technically appropriate.
Why this would be valuable
This would be particularly useful for MSPs, IT service providers and companies working with external contractors, customers and third-party service providers .
Creating a Devolutions account for every external recipient is often impractical, especially when credentials only need to be shared once or very occasionally.
The ability to securely share a specific credential with an external email address would make the existing “Send Copy” functionality considerably more useful while still allowing Devolutions to maintain appropriate security controls and auditability.
Thank you for considering this feature request.
Best regards
Julian