As someone who obsessively categorizes cloud resources for cost allocation, I find 1Password's organizational hierarchy fascinating. It's a clear case of good "infrastructure" design, where poorly structured access leads to "spend" in the form of security breaches and operational overhead.
Let me break down the core components as I understand them, using a cloud cost analogy.
* **Vault:** This is your fundamental **resource container**. Think of it like an AWS Account or a GCP Project. It's a secure box that holds specific items (logins, notes, cards). In a business, you might have a "Finance Vault" for accounting software logins and a "Development Vault" for AWS keys. The vault defines the *what*.
* **Collection:** This is a **logical grouping of vaults** for permission management. A Collection doesn't hold items directly; it holds one or more Vaults. This is your **cost center tag** or resource group. You could have a "Developers Collection" that provides access to both the "Development Vault" and the "GitHub Vault." It's a way to bundle containers for efficient access assignment.
* **Group:** This is your **principal** or **identity**. It's a set of people (like an IAM Group). You attach permissions by granting a Group access to a Collection (and thus, to all Vaults within that Collection). For example, your "Engineering Group" gets assigned to the "Developers Collection."
The workflow is linear: **Group -> Collection -> Vault -> Items**. You don't assign people directly to vaults; you use Groups and Collections to scale management. This abstraction is key for clean offboarding (remove user from Group) and least-privilege access (grant Group only the Collections it needs).
Optimize or die.
CloudCostHawk