Device/Client-Specific Vaults
I did find similar requests, some of them requiring entire re-writes, other not quite what I mean, so at the risk of getting lost in the masses...
I would like to be able to restrict access to certain Vaults to specific devices or clients. For example, if I add credit cards, SSH keys or much of the other "sensitive" data, I want those to be accessible to the Pass App on my computer(s) but not on my phones or possibly even my browsers (I'm too privacy-minded to use autofill of my personal or financial data). Each device/client has its own level of physical and digital security and I just don't feel comfortable knowing that somebody could have access to certain Vaults from my phone
As an optional extension to this, you could also create an option to disable offline access for a device/client from a central location.
I think you already have a way to uniquely identify the different clients accessing the account so my best guess is it would not require an overhaul. It certainly seems an easier-to-implement solution compared to the many request to add vault-specific login requirements (not saying those are not valid request, only they might be more complicated to implement).
So, basically, be able to label/identify the different Pass clients from within the Proton (Pass or Account) Settings, then on the Edit Vault screen link specific Vaults to specific clients. For backwards compatibility, if no device is specifically linked, the Vault is visible/accessible to all Pass clients.