How to Comment on a Resource
Comments are short notes attached to a resource, visible to everyone who has access to it. They are the place for the context a password field cannot hold: which server this account belongs to, why it was rotated, who to ask before changing it.
Unlike the secret, a comment is stored as plain text on the server. It is readable by anyone who has access to the resource, it appears in the database and in SQL backups, and it can be included in email notifications if your administrator enables that option.
Never put a password, a key, a token or any other secret in a comment.
Read the comments of a resource
- In the passwords workspace, select the resource. Its details appear in the sidebar on the right.
- Click Comments to unfold the section, which starts collapsed.
The list shows one entry per comment, each with the avatar and the name of its author, or "You" for your own, and a relative date. An author who has since been suspended is shown with the mention "(suspended)".

Add a comment
- Unfold the Comments section, then click Add comment.
- Type your text in the field, which prompts you with "Add a comment".
- Click Save, or Cancel to drop it.
A comment holds up to 255 characters. Nothing stops you from typing more, and nothing counts down as you type: the length is checked when you save, and too long a comment is refused with an error under the field. Keep it to one or two sentences and you will never meet the limit.
The interface offers no way to correct a comment once it is saved. Delete it and write a new one instead.
Delete a comment
Use the delete button of the comment, then confirm.
You can only delete your own comments. Nobody else can remove them for you, and this includes your administrator, who has no way to delete another person's comment from passbolt. A comment posted by mistake in a resource you no longer own is therefore not something support can tidy up for you, which is one more reason to keep secrets out of comments.
Who sees your comment
Everyone who has access to the resource. Reading the comments requires nothing more than access to the resource, and so does writing one: read-only access is enough to comment, you do not need to be able to update the resource.
Adding a comment also sends an email notification. The recipients and the content of that email are described in the email notification settings: the notification lists the resource, and includes the text of your comment only when your administrator has turned that option on, which is not the default.
Your administrator can remove the right to see comments from a role. The whole section then disappears from the sidebar, which also means the users of that role can no longer comment.
What comments are not
The list is flat and chronological. The interface offers no reply to a specific comment, no threads, no mentions and no notifications addressed to one person in particular.
For the record of who did what to a resource, comments are the wrong tool: use the activity of the resource, which is filled in by passbolt itself and cannot be edited.