Triage 1Password sign-in failures without alerting on typos
Watches every failed 1Password sign-in, works out which ones actually look like an attack, and alerts your security channel only for those.
Watch my 1Password account for sign-in attempts and triage the failures. Use a poll trigger on 1Password so this fires on each new sign-in attempt, successful or failed. I do not want an alert for every failure. I want the ones that actually look like someone trying to get in.
For each attempt, read the record with the 1Password List Sign-in Attempts operation and pull out who the attempt was against, the timestamp, the IP address and the location it resolves to, the client or device used, and, when it failed, the cause: a wrong password, a failed multi-factor challenge, an unrecognized device, or rate limiting.
Judge each failure against history, not on its own. Pull the recent sign-in attempts for that same account so you can see how many times it has failed in the last hour, which countries and IP ranges that person normally signs in from, and whether this attempt sits inside a run. Successful sign-ins matter as context even though they never trigger an alert on their own.
Escalate only when the pattern is genuinely risky. Any of these clears the bar: the same account collects repeated failures inside a short window, say three or more within fifteen minutes; a failure arrives from a country or an IP range that account has never signed in from before; or a multi-factor challenge fails immediately after the correct password was accepted, which means somebody already holds working credentials and is one step away. Rate limiting that follows a run of failures is a strong signal too, so treat it as escalation worthy rather than as the system already handling it.
Stay silent on everything else. A single failure from a device and network that person uses every day is a typo. Count it toward that account's running total so it can feed a later pattern, then move on without posting anything. Group related failures into one incident as well: if six attempts belong to the same burst, that is one alert and one ticket, never six.
When something clears the bar, post an alert to my security channel with the Slack Bot Send a Message operation. Include the person whose account was targeted, the failure cause, the IP address and the location it resolves to, and the attempt count with the window those attempts landed in. Add one sentence explaining why this cleared the bar when earlier failures did not. Lead with the account name and the cause so the message is readable from a notification preview.
Then open a tracked ticket with the Jira Create Issue operation in my security project. Put the account and the failure cause in the summary, and give the description the full timeline: every attempt in the incident with its timestamp, IP address, location and cause. Set the priority from the strength of the signal, with a correct password followed by a failed second factor as the highest, an unfamiliar country next, and a burst of wrong passwords after that. Include a link back to the Slack alert so whoever picks the ticket up has the conversation.
Before filing, check with the Jira Search Issues (JQL) operation whether an open ticket already covers this account and this burst. If one exists, use the Jira Add Comment operation to append the new attempts to it instead of opening a duplicate.
Additional information
What does this prompt do?
- Checks every sign-in failure on your 1Password account as it happens and records what went wrong: a wrong password, a failed two-factor prompt, an unrecognized device, or too many tries.
- Compares each failure against that person's recent history instead of judging it alone, so one mistyped password stays quiet.
- Raises an alert only when the pattern looks genuinely risky: several failures against one account in minutes, a sign-in from a country or network that person has never used, or a two-factor prompt failing right after the correct password.
- Posts the alert to your security channel in Slack with the person, the cause, the location and the attempt count, then opens a matching ticket in Jira so nothing gets lost in the scroll.
What do I need to use this?
- A 1Password Business, Teams or Enterprise account, set up by an owner or administrator so the workflow can read sign-in activity.
- A Slack workspace and a channel where security alerts should land.
- A Jira project for security work, and permission to create issues in it.
How can I customize it?
- Move the escalation bar: change how many failures inside how long counts as a burst, or require a stronger signal before anyone gets pulled in.
- Change where alerts land, whether that is a private security channel, a direct message to whoever is on call, or both.
- Adjust how tickets are filed: which Jira project, what priority each kind of failure gets, and who they land on.
FAQs
Will this alert me every time someone mistypes their password?
Do I need a paid 1Password plan?
How quickly do alerts arrive?
Can it lock the account or force a password reset?
What if we already send this data to a security tool?
Related templates
Every weekday, find every unpaid JobNimbus invoice, email each customer one reminder that gets firmer as it ages, and post a receivables summary to Slack.
Every weekday at 7am, your active courses are checked for missing work, silent logins, and slipping grades, with a ranked list sent to your advising channel.
Every hour, find the tickets closest to breaching, leave a nudge on each one, and post a ranked at-risk list to your support channel.
Every new customer request gets a priority, triage labels, a friendly reply with the right help article, and a Slack ping only when it is truly urgent.
Every weekday afternoon, each student who is behind gets a warm, personal message in their Canvas inbox listing exactly what they owe.
Every Monday at 8am, see exactly which assignments have work waiting, sorted worst first, posted to Slack and logged to a spreadsheet.
Stop drowning your security channel in failed logins.
Let this workflow watch every 1Password sign-in failure and speak up only when the pattern actually looks like an attack.