Investigate 1Password vault changes and sign-ins in one place

Open one console to see every vault permission change, sign-in, and credential access in your 1Password account, with full history for any person.

App
1PasswordSlack BotJiraEngineeringOperationsResearch & Monitoring
PromptCreate

Build me an internal security activity console for 1Password that I open through the week to answer who changed what. The 1Password admin console gives almost no visibility into vault permission changes and sends no alert when someone is added to a vault, so this app is where I go to browse and investigate that history. It is an investigation and browsing surface, not an alerting workflow. Give it three tabs across the top: Permission Changes, Sign-ins, and People.

All data comes from the 1Password Events API, so the connected 1Password credential must use an Events API base URL (events.1password.com, or the events.ent.1password.com, events.1password.ca, and events.1password.eu variants) together with an Events Reporting bearer token. A Connect server token will not authenticate against these operations. All three read operations are POST requests that read data and change no state.

The Permission Changes tab is powered by the 1Password List Audit Events operation. Show every vault grant, vault removal, group membership change, and administrator action as a row carrying the actor, the target person or vault, the action type, and the timestamp. Make it sortable by time and filterable by action type and by actor. This tab is the core value of the app, so give its table the most careful design: someone scanning it should be able to answer "who got access to what, and who gave it to them" in seconds.

The Sign-ins tab is powered by the 1Password List Sign-in Attempts operation. Show each attempt with the person, outcome, country, client or device, and timestamp, with filters for outcome, country, client, and person. Add a cluster view toggle that groups repeated failures by account, so one person fat-fingering a password five times in a row reads as a single cluster rather than five separate alarming rows. Each cluster should show the account, how many attempts it covers, the time span, the countries and clients involved, and whether it ended in a successful sign-in.

The People tab is a per-person drill-down. I pick an individual and get one merged chronological timeline stitched from all three sources: their sign-ins from List Sign-in Attempts, their administrative and vault actions from List Audit Events, and their credential accesses from the 1Password List Item Usages operation. Type each entry visually by source so I can read the story of one person in a single scroll, and let me narrow the timeline to the same date range as the other tabs.

Every row in every tab gets two buttons. Share to Slack posts the record plus surrounding context, meaning the handful of events immediately before and after it, to our security channel using the Slack Bot Send a Message operation. Format it for a human reader rather than dumping raw fields. Investigate opens a Jira ticket through the Jira Create Issue operation, prefilled with the event detail, the person involved, and the timestamp, so the ticket arrives with enough context to act on without anyone going back to look it up.

Bake in the cursor behaviour properly. The Events API is cursor-based and the cursor is a durable checkpoint that stays valid across sessions, so persist it per tab on the server and page forward from it instead of refetching the whole history every time the app opens. On the first load for a tab, send a reset cursor request carrying the selected date range, then replay the stored cursor while the response reports there is more to read. Use a page size of 100 (the valid range is 1 to 1000) and stay well under the ceiling of 600 requests per minute, backing off when a rate limit response comes back.

Default every tab to the last seven days, with a date range picker I can widen when I am investigating something older. Changing the range should start a fresh cursor for that tab rather than reusing the stored checkpoint.

Visually flag any action taken with the owner role. Owners have unrestricted vault access and can silently add themselves to any vault at any time, which is the single thing I most want to catch, so make the flag obvious in the table and filterable on its own.

The Events token is scoped per feature, so an account may be granted audit events but not item usage. Detect that and degrade gracefully: a tab whose data type has not been granted should explain which report to enable in 1Password rather than showing an error or an empty table, and the remaining tabs should keep working normally. Keep the layout comfortable on a 13 inch laptop screen, since the 1Password admin console itself gets cramped on smaller displays and this console should not repeat that.

What does this prompt do?

  • Keeps a running log of vault permission changes: who was added to or removed from which vault, group changes, and administrator actions, each with the person responsible and the exact time
  • Gives you a sign-in view you can filter by outcome, country, device, and person, plus a grouped view that gathers repeated failures by account so one person mistyping a password does not look like an attack
  • Lets you pick any individual and see their sign-ins, administrator actions, and credential accesses stitched into a single timeline
  • Highlights anything done with owner permissions, because owners can add themselves to any vault without anyone being told
  • Puts a Share button on every record to post it with surrounding context to your security channel, and an Investigate button to raise a prefilled ticket

What do I need to use this?

  • A 1Password Business or Enterprise account where you are an owner or administrator
  • Activity reporting switched on for your account, which takes a couple of minutes from the Integrations area in 1Password. Tick sign-in attempts, item usage, and audit events so all three tabs have data
  • A Slack workspace and the channel you want to share records into
  • A Jira project to raise investigation tickets in

How can I customize it?

  • Change the default time window. Every tab opens on the last seven days, and you can set that to whatever matches your review rhythm
  • Point the Share button at a different Slack channel, or send each tab to a different channel
  • Choose which Jira project and issue type the Investigate button uses, and adjust what gets prefilled into the ticket
  • Decide which actions earn the owner highlight, and add your own filters for the vaults you care about most

FAQs

Does this replace a full security monitoring platform?
No, and it is not trying to. Tools like Splunk and Elastic are built for teams with a dedicated security function and are heavy to run for a small IT team. This is a browsing and investigation console for teams who have nowhere else for this data to live, so you can answer questions as they come up during the week.
Does 1Password not already tell us when someone is added to a vault?
No, and that is the gap this fills. The 1Password admin console shows very little about vault permission changes and sends no message when someone is added to or removed from a vault. This app builds that history into something you can read, filter, and search.
Will this work on a personal or family 1Password account?
No. The activity reporting this relies on is a Business and Enterprise feature. You also need to be an owner or administrator to switch it on.
Can anyone see actual passwords through this console?
No. It only ever shows that an item was accessed, by whom, and when. The contents of your vault items are never read or displayed.
What if we only switched on some of the reports?
The console handles that gracefully. Access is granted per report type, so if one tab cannot read its data it explains which report to enable in 1Password instead of showing an error or an empty screen. The other tabs keep working.
Why does it highlight owner actions specifically?
Because owners have unrestricted vault access and can add themselves to any vault at any time with no built-in guardrail or notification. Flagging those actions is the quickest way to spot the thing most likely to matter.

Related templates

Share of voice dashboard for your brand and competitors

See how your brand's news coverage and sentiment stack up against four competitors, then let an assistant write the weekly report for you.

GDELT
Notion
Slack Bot
App
Approval war room for every social post awaiting sign-off

One screen showing every social post waiting on approval, sorted by deadline, so reviewers can approve or reject without leaving the page.

Hootsuite
Slack Bot
App
Turn champion job changes into new pipeline in Attio

Every Monday, find the past champions and closed-won contacts who changed jobs, update Attio, and get the moves worth chasing in Slack.

Boomerang
Attio
Slack Bot
Agentic Task
Collect social post requests and schedule them in Hootsuite

Staff submit what happened, your social manager edits the copy, picks the accounts and puts it on the calendar without a single spreadsheet.

Hootsuite
Slack Bot
General Input Database
App
Voice agent QA review board for your Hume EVI calls

Open one board each morning, see which voice calls went badly, replay the exact moment the caller got frustrated, and file the fix.

Hume
Linear
Slack Bot
App
Clear your Guru verification backlog in one weekly app

A personal queue of every overdue Guru card, sorted by how late it is, with one-click verify, reassign, comment, and an agent that drafts the refresh for you.

Guru
Slack Bot
App

Stop guessing who changed your vault permissions.

Get one console for 1Password vault changes, sign-ins, and credential access, with Slack and Jira a single click away.