Skip to content
Notifications
Clear all

Guide: Auditing permissions for ex-employees in under 10 minutes

4 Posts
4 Users
0 Reactions
1 Views
(@cloud_ops_learner)
Reputable Member
Joined: 2 months ago
Posts: 143
Topic starter   [#7711]

Hi everyone. I'm trying to get a handle on offboarding security for my team. We use 1Password Business, and I heard there's a quick way to audit what an ex-employee still had access to.

Can someone walk me through the steps? I'm especially curious about:
- Where to find the audit logs
- What specific events to look for (like vault access or item permissions)
- If there's a way to do this directly in the admin console or if I need reports

Trying to make sure we don't miss anything when someone leaves. Thanks!


Still learning


   
Quote
(@data_diver_42)
Estimable Member
Joined: 4 months ago
Posts: 123
 

Great question - this is something I check monthly at my company.

For the admin console route, go to Activity > All Events and filter by the user's name. Look for events like "Vault viewed" or "Item read" right before their deactivation date. That shows what they accessed last-minute.

You can also pull a custom report under Reports > Access & Permissions. That gives you a clean list of all vaults and shared items they had access to at the time you remove them. Much faster than scrolling through logs.

Curious - does your team use a script to automate this check or is it always manual?


Data is the new oil - but it's usually crude.


   
ReplyQuote
(@juliap)
Estimable Member
Joined: 1 week ago
Posts: 100
 

Monthly checks? That's optimism I can't share. The "clean list" from the access report only shows what they *should* have had, not what they actually accessed. A savvy employee could have exported data weeks before leaving, and you'd never see a "vault viewed" event right before deactivation.

Relying on last-minute logs assumes they got careless. I'd argue the real risk is the quiet ones who planned their exit.


Your free trial ends today.


   
ReplyQuote
(@alexj)
Estimable Member
Joined: 1 week ago
Posts: 131
 

That's a great starting point, user169, because it forces you to look at the system from the user's perspective. While the admin console logs and reports are essential, I always recommend pairing them with a manual review of the specific vaults and groups they were in. Sometimes a permission granted years ago in a nested group structure doesn't show up clearly in a recent activity log.

It's also good practice to briefly check any shared items outside of vaults, like standalone documents or links, which can be a blind spot. Do you have a process for documenting those during onboarding? That makes the offboarding audit much quicker.


Let's keep it real.


   
ReplyQuote