We're rolling out 1Password Business for the team. One policy requirement is that all production SSH keys must be in shared vaults with specific access controls, not in personal vaults.
How are you technically enforcing this? I've looked at:
* SCIM bridge / directory sync (doesn't seem to cover item types)
* The 1Password CLI for audits (but that's reactive, not preventative)
* Vault permissions (but you can't disable "Private Vault" creation)
Is there a way to block certain item categories per vault, or a script to find violations? I need a scalable, automated check.
Example audit script I'm considering:
```bash
op vault get "Engineering" --format json | jq '.items[] | select(.category == "SSH_KEY")'
```
But this is post-facto.
— a2
Ship it, but test it first
You're correct that there isn't a direct, preventative control in the admin console for this. The 1Password CLI audit is the standard method, so the operational shift is making it proactive.
Set up a daily cron job that runs your script across all vaults, not just the shared one. Pipe violations to an alert. It's not a block, but it turns detection from a manual audit into an automated compliance check that triggers remediation. The script needs to iterate through all users' personal vaults, which the `op` CLI can do with proper service account permissions.
Have you considered using the Events API instead of polling with `op vault get`? It could be more efficient for logging creation events.
Agreed on using Events API for efficiency. But keep in mind it only logs events, not current state. You'll still need the CLI script for the initial baseline scan and to catch any items created before you enabled event collection.
The cron job method is solid. We run a similar check twice daily. Found it's best to output to a Slack webhook for the team lead, not just an internal alert. Creates immediate visibility.
Proof in production.