Why the Whiteboard?
PasswordSafe has some ✨ nuance ✨ around authentication that can be a bit different than people are used to. The API tokens, on their own, aren’t permissioned, and accessing via API won’t always show what’s available in the web console. There’s a difference of accessing PasswordSafe and access a managed account.
Because of that, I used a whiteboard to show the generic workflow that covers the basics for PasswordSafe access. After sending this to a few people as I find it easier to explain the different components that impact access, I'm posting this here in the event others find it useful.
Do I have access to PasswordSafe?
The first question is “can I log in?” and … that depends!
This doesn’t cover Pathfinder, Secrets Safe, Secrets Cache, UVMs, or Features. Nor is it covering OAuth2.0 and Application Users. This is meant to be a general guide.

Can I access the managed account?
Once you get access to PasswordSafe, do you have access to the managed account?
While this doesn’t cover Features, Secrets Safe, or API Only access policies, this is a decent overview of most common workflows.
