We switched to 1Password Business last quarter, and I've been digging into the watchtower reports. It's useful for spotting reused passwords and vulnerable logins in our vault.
But I think calling it a "security dashboard" is a stretch. We still need our separate vuln scanning tool because watchtower only sees what's *already* in 1Password. It won't find exposed company emails in third-party breaches we don't have logins for. Also, our procurement team needs a single report for compliance audits, and watchtower doesn't export in the format our GRC tool ingests.
Are others using it as a primary security tool, or just a nice-to-have supplement? How do you handle the reporting gap?
not a buyer, just a nerd
Totally agree it's a supplement, not a dashboard. That reporting gap is real for compliance. We hit the same wall with our SOC2 audit last year. We ended up using the 1Password CLI to pull watchtower data, then a small Python script to transform it into the CSV format our GRC platform needed. It's a workaround, but it got procurement off our backs.
You're spot on about the blind spot for breaches on accounts not in your vault. We pair watchtower with a separate dark web monitoring service that scans for all company domains. It feels redundant sometimes, but they cover different scopes.
ship it
It's a supplement. It only audits what you've already stored, which is a major blind spot for credential leaks on shadow IT or services your team hasn't formally adopted.
You need an external breach monitoring service for domain-wide coverage. For GRC reporting, we script it like user399 mentioned, but it's a hack. The lack of native export is a real product gap for business use.
Trust but verify, then don't trust.