Hey everyone! I'm looking into setting up emergency access for our team's 1Password Business vaults. We're a small startup and I'm the one handling most of the cloud infra. If something happens to me, nobody else can get into our AWS or Terraform secrets right now, which is scary.
I want to avoid creating a shared account or writing a master password down somewhere. Can someone walk me through the best way to set this up in 1Password Business? I'm especially worried about accidentally making a security hole while trying to solve this problem. What are the step-by-step settings I should use? 😅
Great question - this is super important for small teams. 1Password Business has a dedicated "Emergency Kit" feature for exactly this scenario.
You can assign specific people (like a co-founder or ops lead) as emergency requesters. They won't see the passwords until they formally request access, and you get a notification to approve or deny. If you don't respond after a set waiting period you choose (like 24 or 72 hours), access is automatically granted to them. That delay is your safety net.
Just make sure those emergency contacts have strong, unique master passwords and 2FA on their own accounts. The real trick is testing the process once with a dummy vault - that way everyone knows how it works before you need it for real 😅
Keep it simple.
That exact scenario kept me up at night before we set ours up! You're smart to focus on the "without making a security hole" part.
The Emergency Kit feature user1376 mentioned is definitely the way to go. My big addition is to pick emergency requesters who are *outside* the engineering/infra function if you can. Like a co-founder in finance or ops. They're less likely to be a daily target for phishing, and they have a different risk profile. Giving emergency access to another engineer who already has high-level system access can sometimes create a single point of failure in a different way.
Also, be super deliberate about the waiting period. We started with 24 hours but realized that wasn't enough time to account for me being on a long flight or camping trip without service. We moved it to 48. It feels like a long time in a panic, but the delay is the whole point. You have to balance "real emergency" with "I'm just temporarily offline." Definitely do the practice run!
Pipeline is king.
Thanks for explaining the Emergency Kit, that makes sense. Testing with a dummy vault is a great callout. I'm curious about the actual mechanics though: when someone requests access and the waiting period starts, what's the exact chain of notifications? Does it just rely on your email, or does 1Password also send a push alert to your phone or something? I'd hate for the safety net to fail because an email got buried or went to spam.
Good question, it's exactly what we checked when we set ours up. It does send both an email *and* a push notification to the 1Password app on your phone, provided you have notifications enabled. So there's a dual channel.
But you've hit on the real weak spot - if you're the only one who gets that notification and you're the one incapacitated, the system still relies on someone else knowing to *start* the emergency request. That's why our team rule is: if I'm unreachable for X hours on a critical issue, the trigger to *use* the emergency process is discussed in our runbooks. The tech works, but the human process around it is just as important.
K8s enthusiast