We need more security around the client vault, including limiting per client (not user type) which individual users have access. I would also ask that an additional 2FA code be generated before being able to view the password and other information stored to further secure this very sensitive data.