1Password

1Password

Connect 1Password Events Reporting to Corma to spot dormant members, suspend leavers on day one and know which shared credentials to rotate afterwards.

The Corma integration for 1Password brings Events Reporting data (sign-in attempts, item usage and audit events) into your access governance, so offboarding a team member covers the passwords they used and not only their seat. It complements the 1Password Business access integration, which creates and removes accounts.

Key takeaways

  • The 1Password Events API reports sign-in attempts, audit events and item usage in shared vaults, including who viewed, copied or edited an item and from which device.
  • 1Password's own offboarding guide asks admins to change the shared passwords a departing member could access, not just to remove the account.
  • 1Password Business does not bill suspended or deleted members, but deleting a member permanently erases the items in their Employee vault.

What does the 1Password Events API show?

Events Reporting is a 1Password Business integration. An owner or administrator creates it from the Integrations page, and 1Password issues a bearer token that can be limited to sign-in attempts, item usage or audit events. The item usage feed records the user, the vault, the item and the action taken (such as fill, reveal, copy, export or share), with the app, IP address and location.

Three limits matter. Item usage only covers shared vaults, events arrive when the app syncs so they can lag, and the token never expires unless you choose 30, 90 or 180 days when you create it.

Why is removing the seat not enough when someone leaves?

A suspended member can no longer open any vault, but they may remember or have copied what they saw. That is why 1Password recommends resetting shared passwords and tokens after a departure, and assuming that an owner or administrator accessed every item in the vaults they managed. Without usage data, IT either rotates everything or guesses.

Order matters as well. Suspension is reversible and free, while deletion wipes the Employee vault. Suspend on the last day, then delete once the handover has been checked.

What Corma adds to 1Password

  • Day-one suspension: the HR departure date triggers suspension in 1Password, inside the same deprovisioning run as every other app.
  • Targeted rotation: item usage shows which shared credentials the leaver actually used, so each vault owner receives a short rotation task instead of a blanket reset.
  • Dormant members: sign-in and usage activity flag members who have not used 1Password for 30, 60 or 90 days before your renewal.
  • Token hygiene: the Events Reporting token is a non-human identity, so it gets an owner, an expiry date and a place in your reviews.
  • Audit evidence: sign-ins and access changes land in one audit trail next to your other apps, ready for ISO 27001 or SOC 2.

1Password Events integration FAQ

Which 1Password plan includes the Events API?

Events Reporting is part of 1Password Business, the plan that also includes automated provisioning, Unlock with SSO and usage reports in the admin console.

Is this the same as SCIM provisioning for 1Password?

No. Provisioning creates, updates and suspends accounts from your identity provider: Entra ID, Okta, JumpCloud and OneLogin through 1Password's hosted provisioning, Google Workspace and Rippling through the SCIM Bridge. Events Reporting reads activity. Corma uses both, within its identity governance platform.

Can Corma see what is stored in our vaults?

No. The Events API describes who used an item, never the secret itself. Corma stores that activity on AWS inside the European Union, encrypted, under its ISO/IEC 27001:2022 certification.

Want to see a 1Password offboarding with its rotation tasks attached? Book a Corma demo.

Related Integrations

Check out other integrations that could help you on managing your software licences and accesses!