Give every shared 1Password login an owner and a rotation date

By General Input

An inventory of every shared login in 1Password, with a named owner, a rotation schedule, and a private nudge for anyone who is overdue.

Integrations

  • 1Password
  • Slack Bot
  • Jira

Type

App

Categories

  • Operations
  • Engineering

I want an app that gives every shared login in our 1Password account a named owner and a rotation schedule. Right now nobody owns these credentials, so nobody ever rotates them. The app is where I fix that, and the ownership record has to live on the 1Password item itself rather than in a separate database that quietly drifts out of date.

The main view is an inventory table covering every shared vault. Build it with 1Password List Vaults to find the vaults, List Items for each vault, and then Get Item Details for each item, because List Items deliberately omits sections and field values and the ownership metadata lives in those fields. Each row shows the credential title, its vault, its tags, the assigned owner, the rotation cadence, the number of days since it was last rotated, and the date it was last actually used. Pull the last used date from List Item Usages. Give the table quick filters for overdue, unowned, and never used, plus a text search over title and vault.

Clicking a row opens a detail panel for that credential where I can assign an owner, choose a rotation cadence of 30, 60, 90, or 180 days, and mark the credential as rotated today. Write all three back onto the 1Password item with Patch Item Attributes, which takes a JSON Patch document. Store the owner and the last rotated date as custom fields on the item, and reflect the cadence as both a field and a tag so it is visible from inside 1Password. Never display or edit the secret value of a credential in this app, even though the item details response contains it.

Colour the days since last rotation column red once the credential is past its cadence, and amber when it is within seven days of being due. Treat a credential with no owner recorded as unmanaged, make that obvious in the table, and include it in the unowned filter. A credential with an owner but no cadence set should still count as overdue once it is a year old.

Add a Nudge owners button above the table. It groups every overdue credential by its assigned owner and sends each owner a private Slack message listing only their own overdue logins, with the vault name and how many days past due each one is. Resolve each owner to a Slack account with Slack Bot Look Up User by Email, then send the direct message with Slack Bot Send a Message. Owners with nothing overdue get no message. When the run finishes, report inside the app how many messages went out and which owners could not be matched to a Slack account.

In the row detail panel, add an Open rotation ticket button that files a single Jira issue for that one credential using Jira Create Issue. Prefill the summary with the credential title, and the description with the vault, the assigned owner, the cadence, the last rotated date, and how many days overdue it is. Let me choose the Jira project and issue type in app settings. Write the resulting issue key back onto the 1Password item as a field and show it on the row, so nobody files a duplicate ticket for the same credential.

Give deletion candidates their own tab. A deletion candidate is any credential with zero recorded usage in the last 180 days. Show the same columns there, sorted by longest unused first, and allow the same owner assignment and ticket filing from that tab, so I can either claim a credential or raise the work to remove it.

The item reads and writes need a 1Password Connect server credential, while the last used column and the deletion candidates tab need a separate 1Password Events API token. Make the app degrade gracefully. If only the Connect credential is connected, still render the full inventory and every ownership feature, show the last used column as unavailable rather than empty, and explain in the never used filter and the deletion candidates tab that they need the events reporting credential. Connect vault and item identifiers are 26 character lowercase alphanumeric strings.

Because the inventory needs one detail fetch per item, load vaults and items first, render the table quickly from what that returns, and fill in the field level metadata progressively behind a visible progress indicator instead of blocking on the whole account. Keep the assembled inventory for the session with a manual refresh button, and refresh a single row in place after I assign an owner, change a cadence, or mark a rotation.

Related prompts

Explore more prompts
A brand asset library your marketing team actually searchesTurn Mailjet email clicks into ranked HubSpot follow-upsClean out the Looker dashboards and Looks nobody opensLiveKit live operations console for room moderationWake up dormant Keap leads with a researched reasonLiveChat coverage board for planning next week's shiftsPhone routing control panel for LiveKit voice agentsLinkedIn Ads budget pacing dashboard for every client accountGive your team Looker numbers without buying more seatsPause marketing emails to escalated customers, then restore them

Stop letting shared logins go unowned.

Put a name and a rotation date on every shared credential, then let the app chase the overdue ones for you.

Use prompt

Create a free account to use this prompt. No credit card required.