1Password logo

1Password

Access
Password Management

Mycroft reads 1Password vault and group membership to show who can reach each shared credential.

Shared credentials such as service accounts and vendor logins cannot be tied to one person, so frameworks require the list to be controlled and reviewed. Mycroft pulls vault permissions and two-factor status into the same access review as every other system.

How Mycroft connects to 1Password

How it connects
You create a 1Password service account for Mycroft, which authorizes with client credentials.
What Mycroft can access
Read-only. Mycroft reads the account member list behind access reviews.

Which controls 1Password evidence maps to

Each row is a control an auditor tests and the specific artifact Mycroft collects from 1Password to satisfy it. Collection runs on a schedule and every result is timestamped.

1Password compliance control mappings and the evidence Mycroft collects for each
FrameworkControlWhat it requiresEvidence collected from 1Password
SOC 2CC6.1Logical access controls restrict access to information assets.Vault inventory with group and individual permissions, showing exactly who can reach each shared or privileged credential.
SOC 2CC6.2Credentials are issued only to authorized users and reviewed.Account roster with status and provisioning date, reconciled against the workforce roster from your HRIS or identity provider.
SOC 2CC6.3Access is removed when no longer needed.Account suspension and removal events, with vault membership changes recorded when someone leaves.
SOC 2CC6.6Authentication measures protect against unauthorized access.Two-factor authentication enforcement policy and per-user enrollment, plus account recovery and unlock policy settings.
ISO 27001A.5.17Authentication information is allocated and managed securely.Proof that shared and privileged credentials are held in a managed vault with controlled membership rather than circulated informally.
ISO 27001A.8.2Privileged access rights are restricted and controlled.Membership of vaults containing administrative and break-glass credentials, reviewed periodically with decisions recorded.
ISO 27001A.5.18Access rights are provisioned, reviewed and revoked.Vault and group membership included in the periodic access review alongside every other connected system.
HIPAA§164.308(a)(5)(ii)(D)Procedures for creating, changing and safeguarding passwords.Password and authentication policy configuration for the account, with two-factor enrollment state per member.

What Mycroft collects automatically

Gathered from 1Password on a schedule, dated and stored against the controls above.

  • Vault inventory with group and individual permission assignments
  • Account roster with status, provisioning date and last activity
  • Two-factor authentication enforcement policy and per-user enrollment
  • Group membership, showing which teams reach which vaults
  • Account recovery and unlock policy configuration
  • Guest and external account inventory

Manual work this removes

The tasks that disappear from someone's quarter once 1Password is connected.

  • Compiling who can reach the vaults holding privileged credentials
  • Confirming a leaver's vault access was removed
  • Checking two-factor enrolment member by member
  • Producing an inventory of shared credentials for the auditor

1Password and Mycroft: frequently asked questions

No. The connection is a 1Password service account authorized with client credentials, and Mycroft reads the account member list behind access reviews. Item contents are not retrieved.
That credentials which cannot be tied to a single identity (service accounts, shared vendor logins, break-glass access) are held in a managed vault whose membership is controlled and reviewed. That is the substance of ISO 27001 A.5.17 and a meaningful part of SOC 2 CC6.1, and it is otherwise very hard to evidence.
Vault and group membership is reconciled against the workforce roster alongside every other connected system, so reviewers see 1Password access in the same review as AWS and GitHub. Access to a privileged vault held by someone who changed roles is exactly what a review exists to catch.

We turn the compliance nightmare into a dream

Talk to us