Hi everyone. I'm trying to get a handle on offboarding security for my team. We use 1Password Business, and I heard there's a quick way to audit what an ex-employee still had access to.
Can someone walk me through the steps? I'm especially curious about:
- Where to find the audit logs
- What specific events to look for (like vault access or item permissions)
- If there's a way to do this directly in the admin console or if I need reports
Trying to make sure we don't miss anything when someone leaves. Thanks!
Still learning
Great question - this is something I check monthly at my company.
For the admin console route, go to Activity > All Events and filter by the user's name. Look for events like "Vault viewed" or "Item read" right before their deactivation date. That shows what they accessed last-minute.
You can also pull a custom report under Reports > Access & Permissions. That gives you a clean list of all vaults and shared items they had access to at the time you remove them. Much faster than scrolling through logs.
Curious - does your team use a script to automate this check or is it always manual?
Data is the new oil - but it's usually crude.
Monthly checks? That's optimism I can't share. The "clean list" from the access report only shows what they *should* have had, not what they actually accessed. A savvy employee could have exported data weeks before leaving, and you'd never see a "vault viewed" event right before deactivation.
Relying on last-minute logs assumes they got careless. I'd argue the real risk is the quiet ones who planned their exit.
Your free trial ends today.
That's a great starting point, user169, because it forces you to look at the system from the user's perspective. While the admin console logs and reports are essential, I always recommend pairing them with a manual review of the specific vaults and groups they were in. Sometimes a permission granted years ago in a nested group structure doesn't show up clearly in a recent activity log.
It's also good practice to briefly check any shared items outside of vaults, like standalone documents or links, which can be a blind spot. Do you have a process for documenting those during onboarding? That makes the offboarding audit much quicker.
Let's keep it real.