The Vault Platform counts people in two layers. A user has one license type, which is the first level of access control that Vault applies, and a security profile with one or more permission sets, which is the second. Both must grant access before the user can use a feature.[1] In Vaults that hold several applications, the user also carries one application license value per application, which lets Veeva track licenses at the application level. This article describes those constructs, the counting exclusions, and the sandbox and size rules that surround them. Veeva states that product terms are governed by the written customer agreements, so the help pages explain mechanics but do not set entitlements.[6]
Editions
License types
Vault includes six license types.[1]
| License type | What Vault Help says | Restrictions |
|---|---|---|
| Full User | The most common type; does not block access to any functionality; may be a regular user or administrator | None by license type |
| Read-only User | Extremely limited access | No reports or dashboards, no editing documents, binders or records, no workflow initiation; may sign Read & Understood tasks |
| External User | Users outside the company, slightly limited access | No reports or dashboards, bulk document action or CrossLink creation; email domain must differ from the Vault domain |
| Portal User | eTMF only | Cannot access Admin, reports and dashboards or custom tabs |
| Site User | Clinical Operations only | Not available in new implementations |
| Learner | Veeva Training only | Can view documents and complete training assignments |
Catalog rows: Vault license types; Vault Full User license; Vault Read-only User license; Vault External User license; Vault Portal, Site and Learner licenses. Further rows: Full User is the only license type with Admin access; External Users must use a different email domain; Site User license not available in new implementations; Learner license is Veeva Training only.
The Full User license is the only type that gives access to Admin functionality, and it also grants access to Vault file staging, as does the External User license.[1] Veeva’s Site Connect product is described as providing similar functionality to the Site User license, which is not available in new implementations, enabling sponsors and CROs on Clinical Operations Vaults to exchange documents and data with sites on SiteVault Vaults.[1]
Security profiles and permission sets
Security profiles apply permission sets to users. Vault includes standard profiles that correspond to the user types of earlier releases: Document User, Read-Only User, External User, Business Administrator, System Administrator and Vault Owner, with Legal User, Portal Experience User, External IIS User and Configuration Only for specific uses.[1] The Glossary notes that “user type” no longer exists as a user attribute as of V10, and that the standard profiles are named for the former user types.[3] An asset manager reading a user export should therefore treat the license type, not the profile name, as the licence-relevant field. To change a user’s license type or security profile, an administrator needs a permission set that grants Admin: Users: Edit.[1] Catalog rows: License type is the first access control level; License type and permission set must both grant access; License changes need an admin permission.
Metrics
Application licensing
Application licensing applies to Vaults that use several applications, for example a RIM Vault with Submissions and Registrations. Users have a license value for each application they can access. This lets the system track available licenses per application, although in most Vaults it does not control access.[1] A single user assigned to three applications uses three application licenses.[1] The Glossary defines a license as typically granting one user access to one application, and notes that some Vaults may share the total number of licenses through “pooling”.[3]
Application licensing applies only to product families that use a user-based licensing model: Quality, QualityOne, RIM, RegulatoryOne, Safety, Medical, Commercial, Vault CRM and Veeva Claims.[1] The valid license values depend on the application.
| Suite | Examples of valid values (from Vault Help) |
|---|---|
| Medical | MedComms, Publications and Multichannel: Full, External, Read Only. MedInquiry: Full, Read Only |
| PromoMats | PromoMats and Multichannel: Full, External, Read Only |
| Quality | QualityDocs: Full, External, Read Only. Veeva Training and Study Training: Full, External, Learner. QMS, Product Surveillance and Validation Management: Full, External. Station Manager, Batch Release and HACCP: Full |
| QualityOne | Document Control: Full, External, Read-only. QMS: Full, Lite, External. HACCP and HSE: Full, Lite. Training: Full, External, Learner |
| RIM | Registrations, Submissions Archive and Submissions Publishing: Full. Submissions: Full, Read Only |
| Safety | Safety Management, Signal and Workbench: Full. SafetyDocs: Full, External, Read Only |
| RegulatoryOne and Claims | Compliance and Registration & Dossier Management: Full, Lite. Regulatory Documents and Claims: Full, External, Read-only |
Catalog rows: Vault application license; One license per user per application; Application licensing product families; A license grants one user access to one application.
When users are created or edited in Vaults that use application licensing, the License Type field is not shown on the record details page; Vault sets the License Type from the most permissive application license value. If the most permissive value a user has is Read-Only, Vault sets the License Type to Read-Only and applies its limits.[1] A user in a multi-application Vault must be given a license value for at least one application.[2] Catalog row: License type follows the most permissive application license.
Lite User
A Lite User appears in the QualityOne and RegulatoryOne tables as an asterisked value. It cannot be selected as a license value: it is the Full User license value configured with security profiles to limit access, and customers are told to contact their Veeva representative for details.[1] Whether a Lite User is priced differently from a Full User is not stated publicly. Catalog rows: Lite User configuration; Lite User is a configured Full User.
Counting and floors
System accounts
The User object holds system-owned records that appear in every Vault, such as System and Application Owner, to capture actions Vault performs itself. These records are not included in license counts.[2] System Managed User accounts, which are Vault Owners, include System, Application Owner, Java SDK Service Account, MyVeeva Integration User, Clinical Survey Respondent, Clinical Transfer, Falcon Integration Users and Agent Users, and none counts toward the license limit.[2] The License Types page adds that system-owned users operate with Full User licenses but are not included in license counts.[1] Catalog rows: System managed and system-owned users; System-owned users are not counted; System managed users are not counted.
The exclusions are stated for system-owned and system-managed accounts. Vault Help does not list integration accounts that a customer creates itself, so their treatment should be confirmed in the customer’s agreement.
Vault size and data usage
Separately from users, Vault assigns a size class to each Vault from its total data usage. Small is below 100,000 object records and 10,000 document versions, Medium below 1,000,000 and 100,000, Large below 10,000,000 and 1,000,000, Very Large below 100,000,000 and 10,000,000, and Extra Large above those figures. The class is the greater of the object-record and document-version classifications, and system-managed data is excluded.[5] Admins can see the figures under Admin > About > Vault Information > Data Usage Information, and can download the table as a CSV file.[5] The pages do not state whether size class affects fees, but sandbox sizes use the same limits. Catalog rows: Vault size classification; Vault size follows data usage.
Virtualization and partitioning
Sandbox Vaults
Sandboxes are licensed as an entitlement of the production Vault. Customers may have four Small, two Medium and one Full configuration sandbox Vaults for every production Vault, and prerelease Vaults do not count against this. More sandboxes require an add-on order with Veeva’s finance team.[4] Each size has object-record and document-version limits, ranging from 100,000 records and 10,000 document versions for Small to no limit for Full, and sandboxes that exceed their limits are blocked from creating new records or documents until data is removed.[4] Small sandboxes automatically expire after 30 days of inactivity, and Vault warns Vault Owners twice before deleting one.[4]
Sandbox users are not discussed as a separate licence class in the pages cited. The sandbox License Information view, available under Admin > Settings, shows usage values that start at zero and can be recalculated up to 100 times in 24 hours, but these are data limits, not user counts.[4] Catalog rows: Sandbox Vault entitlement; Sandbox Vault entitlement program; Sandbox entitlement per production Vault; Additional sandboxes are an add-on order; Small sandboxes expire after 30 days of inactivity; Sandboxes over their limits are blocked.
Domains
Vault user names include the domain that the company uses for its Vaults. Veeva provides one sandbox domain and one production domain, and can provide an additional domain for testing domain-level settings.[2][4] External Users must use an email domain different from the Vault domain, which is how Vault distinguishes company staff from outside parties.[1]
Cloud and BYOL
Vault is cloud software; no bring-your-own-licence programme appears in the documentation. Veeva describes Vault Platform as supporting 50+ applications.[7] Because each application is licensed per user and per application, customers that add an application to an existing Vault increase the number of user-application pairs, not only the number of people.
Programs
The public Vault Help pages describe no discount or bundling programme for user licenses. The sandbox entitlement is the main included allowance documented, and the counting exclusion for system accounts is the main carve-out from license counts.
Out of scope
This article does not cover Vault CRM license tiers, Veeva AI, or the data products, which are in separate articles. It does not state prices, minimum quantities or contract terms, because Veeva does not publish them in the sources used. It also does not describe permission set design, which is configuration rather than licensing.