For advisors: the Pro console
AmberKey Pro is a status dashboard for estate planners, family offices, and fiduciaries whose clients keep a plan in AmberKey. It answers one question, for every client who has consented: is this plan current, and how covered is it?
It is deliberately narrow. The console is read-only. It shows metadata about a plan, never the plan itself. You cannot see an account, a password, a key, a letter, or the names of the people in a client’s recovery circle, because the server that feeds the dashboard cannot see them either. Those live encrypted, and the keys live with your client and the people they chose.
The console lives at its own address, separate from the client app, and it contains no cryptographic code at all. That is enforced by a check that fails the build if anyone ever tries to add some. It is a claim you can verify rather than a promise you have to accept.
Getting set up
AmberKey provisions firms directly. There is no self-serve signup on the console, and no way to create a firm from the sign-in page. We arrange billing with you, then create your firm and its first seat.
You will receive an email with an activation link. Opening it asks for your name and a passkey. That passkey becomes your sign-in. The link works once and expires after 21 days. If it goes missing or bounces, ask us to resend it: a new link supersedes the old one, which stops working the moment the new one is issued.
Additional seats for colleagues are created the same way. Ask us and each person gets their own activation link and their own passkey.
Seats and roles
Every seat at your firm sees the same thing: all of the firm’s consented clients, the same audit log, and the same tools. Seats are recorded as either admin or member, but that distinction does not currently restrict anything in the console. It exists so that firm-managed seats can arrive later without migrating your data.
If someone leaves, ask us to revoke their seat. Revocation ends their live sessions immediately, not at the next expiry.
Working with more than one firm
Advisors often practise across more than one firm, so a single email address can hold a seat at several of them. Each seat is independent: its own passkey, its own client roster, its own audit trail. Nothing is shared between them, and one firm cannot see another’s clients.
When you sign in, AmberKey offers the passkeys for every live seat registered to your address. The passkey you choose determines which firm you are signing into. Pick your Acme passkey and you are in Acme’s console, seeing Acme’s clients.
To switch firms, sign out and sign in again with the other passkey. There is no in-console firm switcher yet, because each session belongs to exactly one seat.
If you name your passkeys when you create them, your browser or password manager will show those names at sign-in, which makes choosing obvious.
What the dashboard shows
For each consented client:
- Liveness. Whether the client is checking in on schedule, or has begun escalating toward a release.
- Last check-in. The date only.
- Coverage. The share of a client’s accounts that have a recovery path which has been confirmed within the last year. Accounts that rely on a legal process or on a secret held in the encrypted vault do not count toward it, so a low number is not automatically a neglected plan. Read it as “how much of this is self-service for the family” rather than as a grade.
- Shares confirmed and pending. Counts only, of how many of the printed recovery cards have been attested recently. Never who holds them.
- Backup age. When the client last exported or synced their family backup. Stale backups are the most common real problem you will spot here.
- Packet. Whether the executor packet is complete.
- Ceremony status. Whether a release is in progress, and at what stage.
- Client label. Whatever name the client chose to show you, if any.
That list is the whole of it. It is written down as a fixed allowlist in the threat model, and anything not on it is denied by default.
Why some clients show as a code instead of a name
The server does not know who your clients are. It never receives their names.
So identity has to come from the client, not from us. When someone connects to your firm, they are asked to choose the name you will see, prefilled from their own profile name. If they leave it blank, the roster shows a short code instead. They can set or change that label at any time, and it is per firm: a client can appear to you one way and to another firm differently.
If a roster row is a code and you would like a name, ask the client to add one in their AmberKey settings. We cannot add it for them.
Consent, and what it does not let you do
Every client relationship rests on consent that the client grants and the client can withdraw. Withdrawal takes effect immediately: the next read fails, and the client vanishes from your roster. You cannot object to it, delay it, or be notified in a way that lets you act first.
Most importantly, an advisor is never a release gate. Nothing you do or fail to do can trigger a release of a client’s plan, block one that their circle has properly initiated, or speed one up. If your firm disappears tomorrow, every client’s plan still works exactly as before. That is a deliberate design constraint, and it is the reason a compromised advisor account cannot become a compromise of a client’s estate.
The audit log
Every read of a client’s status is recorded, from the first request, along with consent grants, withdrawals, and invitations. The Audit tab shows your firm’s own trail: when, what happened, which seat did it, and which client it concerned.
It is scoped to your firm and it is read-only. Neither you nor we can edit or remove entries. If a compliance officer asks who at your firm looked at a client’s status and when, that tab is the answer.
Inviting a client
The Invite client tab sends an email invitation. The client follows the link into their own AmberKey app, signs in or creates an account, and the connection plus consent are recorded there. Invitations work once.
Clients can also connect to you without an invitation by entering your firm code, which is shown at the top of your console. Either way, the client is the one who grants consent.