Skip to main content

Customer Trust Accounts

✅ Feature availability: Customer Trust Accounts are available on to customers with Customer Trust enabled on their plan. Advanced features, including tagging, CRM-based access approval, Salesforce account linking, and CRM or NDA integrations, may require an add-on to your plan. Refer to Vanta Plans and Pricing for details.

Customer Trust Accounts are the central company-level profile in Vanta's Customer Trust module. Each account represents a prospect or existing customer, and lets you group all of your Trust Center and Customer Commitments activity in one place. This makes it easy to understand your relationship with each account, control how they access your content, and track the commitments you've made to them.

⚙️ User permissions: Admins, Editors, and Trust Admins can manage Customer Trust Accounts. Learn more: User Permissions by Product Area


Viewing account activity

From Customer Trust > Accounts, you can see engagement across all accounts at a glance, then drill into a specific account to see details.

Account overview

The Accounts page displays a spreadsheet-style view of all accounts. This view makes it easy to scan activity across your customer trust program, including:

  • Account name and domain

  • NDA and auto-approval status (depending on your account-level settings)

  • Active Trust Center viewers

  • Number of questionnaires associated with the account

  • Number of contracts associated with the account

  • Last active date a linked viewer interacted with your Trust Center

Individual accounts

Clicking an account from the Accounts page opens a detailed view with multiple tabs so you can understand all interactions tied to that account. This view gives you a full picture of how an account is engaging with your Trust Center content and security questionnaires, including:

Tab

Description

Overview

Account name and domain, tags, and account-level settings

Viewers

All Trust Center viewers associated with the account and viewing activity

Subscribers

All Trust Center subscribers tied to the account and subscriber activity

Questionnaires

All questionnaires linked to the account and questionnaire status

Contracts

All contracts associated with the account

Commitments

All commitments associated with the account


Adding accounts

Accounts can be created in a few ways:

To add an account manually:

  1. Go to Customer Trust > Accounts using the navigation menu in your account.

  2. Click the Add account button.

  3. Enter the account name and domain.

  4. Click Save to create the account.


Managing accounts

Each customer account can be associated with the following:

  • Trust Center viewers: People who have requested or been granted access to your Trust Center.

  • Subscribers: People who subscribe to Trust Center updates.

  • Questionnaires: Security questionnaires associated with the account.

  • Contracts and commitments: Contracts associated with the account and the commitments extracted from them.

Adding viewers and subscribers

To add Trust Center viewers or subscribers to an account, go to Customer Trust > Trust Center and click through each tab:

Tab

Description

Viewers granted access

  • Click the ••• menu to move an existing viewer to an account.

Access requests

  • Click the checkmark to review viewer access requests and select an account.

Subscribers

  • Click the ••• menu to move an existing subscriber to an account.

  • Click the Add subscriber button to add a new subscriber and select an account.

Adding questionnaires

To add questionnaires to an account, go to Customer Trust > Questionnaires:

  • Click the ••• menu to move an existing questionnaire to an account.

  • Click the Add questionnaire button to add a new questionnaire and select an account.

  • When you select an account, any tags associated with that account are automatically applied to the questionnaire, as long as those tags are enabled for question answering.

Adding contracts and commitments

If you use Customer Commitments, you can link related contracts and commitments to accounts.


Account-level settings

Account-level settings let you set NDA requirements and auto-approval behavior for each account, giving you finer control over how customers and prospects access your Trust Center.

Account domain

How domains work

Each account has a domain that Vanta uses to match viewers to that account.

  • Vanta checks a viewer's email domain against your configured account domains when they submit an access request, or when you grant them access manually without selecting an account for them.

  • If you manually grant access and select an account yourself, Vanta uses that account directly and skips domain matching.

  • If you've connected a CRM, Vanta also checks for a matching CRM-linked account. CRM-based matching takes precedence over domain matching—if a viewer's email domain matches one account but also matches a CRM contact linked to a different account, the CRM-linked account is used.

  • This matching only determines which account a viewer belongs to. It doesn't affect whether they can view public Trust Center content, since that doesn't require an account match.

Supported domain formats

Each account supports one domain. Editing or removing an account's domain doesn't affect viewers already associated with the account. They keep their current access, tags, and NDA status. The change only applies to future access requests and manual grants.

You can enter a domain in two ways:

  • An exact domain: Like acme.com, to match only that domain. Must be a valid, all-lowercase, standard domain (letters/numbers/hyphens, proper TLD). No protocol, no path, no trailing slash.

  • A wildcard domain: Like *.acme.com, to match acme.com and all its subdomains. The * must be the first character in the pattern, in addition to the above requirements.

ℹ️ Note: Vanta doesn’t automatically create accounts for viewers using free or personal email domains, such as gmail.com. These viewers may still match an existing account through CRM or domain matching, or be assigned manually.

Wildcard domain matching

Wildcard domains are useful for grouping viewers who share a domain pattern but not an exact domain.

  • If a viewer isn't already linked to an account, Vanta checks for a match in this order: a CRM-linked account (if you've connected a CRM), then an exact domain match, then the most specific wildcard domain match. Once a viewer is linked to an account, that link is used going forward, regardless of later CRM or domain changes.

  • If a viewer's email matches more than one account's domain, Vanta uses the most specific match. An exact domain match beats a wildcard, and a longer wildcard suffix beats a shorter one.

    • For example, if one account has *.gov and another has abc.hhs.gov, a viewer at abc.hhs.gov is matched to the abc.hhs.gov account.

    • If one account has *.gov and another has *.hhs.gov, a viewer at agency.hhs.gov is matched to the *.hhs.gov account, since it's the more specific match.

  • A wildcard also matches the domain immediately following the *., not just its subdomains.

    • For example, *.hhs.gov matches viewers at hhs.gov itself, in addition to subdomains like agency.hhs.gov.

  • Setting a domain only determines which account a viewer is matched to. It doesn't grant them access on its own. To automatically approve access requests from viewers matched to an account, turn on auto-approval for that account.

Non-disclosure agreements (NDAs)

You can manage whether an account must sign an NDA to access your Trust Center, or whether a single NDA signature applies to the entire account.

NDA requirements can be configured globally from your settings and then adjusted per account. In your account header, click the Settings icon > scroll to the Features section > select Customer Trust > go to the Trust Center tab.

Outcome

How to achieve outcome

I want all viewers in an account to sign an NDA

  • Go to Settings > Customer Trust and turn off “Allow accounts to satisfy the NDA requirement on behalf of viewers.”

  • This setting is global—turning it off applies to all accounts and removes the ability to disable NDA requirements at the account level.

I want one viewer to sign an NDA that applies to the whole account

  • Go to Settings > Customer Trust and turn on “Allow accounts to satisfy the NDA requirement on behalf of viewers.”

  • In the account, choose Enable NDA requirement.

I don’t want to require an NDA for this account

  • Go to Settings > Customer Trust and turn on “Allow accounts to satisfy the NDA requirement on behalf of viewers.”

  • In the account, choose Disable NDA requirement.

I want to change the NDA setting within an account, but there's already a signed NDA

  • You cannot change the NDA requirement while an NDA is signed for the account.

  • In the account, choose Mark NDA as invalid to reset the NDA status. After resetting, you can enable or disable the NDA requirement again.

💡 Tip: From Settings > Customer Trust, you can also configure email-based and domain-based rules to allow viewers to bypass NDAs.

Tags

Adding tags to an account determines which resources and controls account viewers can access within your Trust Center.

  • Applying a tag to an account grants access to any shareable resource or control with the same tags applied.

  • Before you can add tags to an account, enable the tag categories for resources and controls in Settings > Customer trust > Tags.

  • If you tag a new resource or control later, any account with a matching tag gains access to it right away.

Auto-approval

Account-level auto-approval works alongside your global auto-approval settings and gives you more granular control over how different customers or prospects access your Trust Center content.

You’ll find the Auto-approval setting under Trust Center access within an account. You can control whether access requests from a specific account should be automatically approved:

  • On: Automatically approve all access requests from viewers in this account.

  • Off: Follow your global auto-approval rules as configured in Settings > Customer Trust.​​

ℹ️ Note: If you're using Salesforce or HubSpot to manage auto-approval, CRM-based auto-approval uses CRM account data to approve requests, while account-level auto-approval uses the viewer's email domain, including wildcard domains. These work alongside each other, enabling one does not disable the other.

Resource access

Resource visibility starts with the global rules you set in your Knowledge Base, where you mark individual resources as public or request-only. What an approved viewer actually sees depends on both those global rules and the account-level settings below, which can narrow or extend access beyond the global rules.

Account access level

You'll find the Resource access setting under Trust Center access within an account. Choose how an account's resource access relates to your global rules:

  • Full access: The account follows your global resource visibility rules.

  • Limited access: Overrides the global rules. If you've set up tags for document sharing, the account can only access resources tagged to match the tags configured on the account page. If you haven't set up tags, the account can only access the specific resources you select for it.

📖 Learn more: For help configuring resource tags, see Managing Your Knowledge Base.

Sharing additional resources

You can grant access to specific resources that should be available for the account, regardless of access level or global rules.

  • If auto-approval is on, viewers get these resources right away.

  • If manual approval is required, these selections are pre-filled when you review the access request.

Control access

Control access determines which controls in your Trust Center are visible to viewers associated with an account:

  • All viewers have access to public controls.

  • You can grant an account additional access to a subset of shareable controls with tagging.

To share additional controls with an account:

  1. From Settings > Tags, create the tags categories and tags you want to use.

  2. From Settings > Customer trust > Tags > Trust Center access > Control tag categories, add the tag categories you'd like to use to manage control access.

  3. From Customer trust > Trust Center > Edit > Controls > Edit controls, apply the tags to the controls you want to share.

  4. From Customer trust > Trust Center > Edit > Controls > Configure visibility, change the control category visibility setting to Shareable for each set of controls you want to share.

  5. Within an account, add the same tags. The Control access section updates automatically to show how many additional controls were shared with the account.

📖 Learn more: For help configuring control visibility, see Managing Your Trust Center. For help tagging controls, see Using Tags: Trust Center.


Salesforce CRM integration

When Customer Trust accounts are linked to Salesforce, Vanta can automatically create and connect accounts based on Salesforce data, reducing manual work. You can also configure Vanta to use a Salesforce field to automatically control whether Trust Center access requests are approved for each linked account.

Syncing accounts to Salesforce

When you manually create an account: Vanta automatically finds and links the matching Salesforce account based on the domain you enter. No additional steps are needed.

When Salesforce-based auto-approval is active: Each time a viewer is granted access via Salesforce-based auto-approval:

  • If no matching account exists for the viewer's email domain, one is automatically created and linked to the corresponding Salesforce account.

  • If a matching account already exists but isn't linked, it is automatically linked at that time.

  • When access is granted manually, Vanta looks up the user in Salesforce and automatically creates and links an account if a matching Salesforce account exists.

Trust Center access request auto-approvals

To configure auto-approvals with Salesforce:

  1. Go to Customer Trust, click the Settings button (the gear icon), and then scroll to the Access request automation section.

  2. Set the approval dropdown to Automatically, if request meets condition.

  3. Configure the match condition: select what viewer attribute to match on (for example, Full email address), then select the Salesforce object to match against (for example, Salesforce Contact).

  4. Optional: To apply additional account-level conditions, click Add account condition and select a Salesforce field. The field must be a boolean type (true enables auto-approvals for that account, false disables them).

ℹ️ Note: Auto-approval can still be manually disabled for individual accounts from the account details view, which overrides the Salesforce sync for that account.