
1Password
Access
Password Management
Mycroft reads 1Password vault and group membership to show who can reach each shared credential.
Shared credentials such as service accounts and vendor logins cannot be tied to one person, so frameworks require the list to be controlled and reviewed. Mycroft pulls vault permissions and two-factor status into the same access review as every other system.
How Mycroft connects to 1Password
- How it connects
- You create a 1Password service account for Mycroft, which authorizes with client credentials.
- What Mycroft can access
- Read-only. Mycroft reads the account member list behind access reviews.
Which controls 1Password evidence maps to
Each row is a control an auditor tests and the specific artifact Mycroft collects from 1Password to satisfy it. Collection runs on a schedule and every result is timestamped.
| Framework | Control | What it requires | Evidence collected from 1Password |
|---|---|---|---|
| SOC 2 | CC6.1 | Logical access controls restrict access to information assets. | Vault inventory with group and individual permissions, showing exactly who can reach each shared or privileged credential. |
| SOC 2 | CC6.2 | Credentials are issued only to authorized users and reviewed. | Account roster with status and provisioning date, reconciled against the workforce roster from your HRIS or identity provider. |
| SOC 2 | CC6.3 | Access is removed when no longer needed. | Account suspension and removal events, with vault membership changes recorded when someone leaves. |
| SOC 2 | CC6.6 | Authentication measures protect against unauthorized access. | Two-factor authentication enforcement policy and per-user enrollment, plus account recovery and unlock policy settings. |
| ISO 27001 | A.5.17 | Authentication information is allocated and managed securely. | Proof that shared and privileged credentials are held in a managed vault with controlled membership rather than circulated informally. |
| ISO 27001 | A.8.2 | Privileged access rights are restricted and controlled. | Membership of vaults containing administrative and break-glass credentials, reviewed periodically with decisions recorded. |
| ISO 27001 | A.5.18 | Access rights are provisioned, reviewed and revoked. | Vault and group membership included in the periodic access review alongside every other connected system. |
| HIPAA | §164.308(a)(5)(ii)(D) | Procedures for creating, changing and safeguarding passwords. | Password and authentication policy configuration for the account, with two-factor enrollment state per member. |
What Mycroft collects automatically
Gathered from 1Password on a schedule, dated and stored against the controls above.
- Vault inventory with group and individual permission assignments
- Account roster with status, provisioning date and last activity
- Two-factor authentication enforcement policy and per-user enrollment
- Group membership, showing which teams reach which vaults
- Account recovery and unlock policy configuration
- Guest and external account inventory
Manual work this removes
The tasks that disappear from someone's quarter once 1Password is connected.
- Compiling who can reach the vaults holding privileged credentials
- Confirming a leaver's vault access was removed
- Checking two-factor enrolment member by member
- Producing an inventory of shared credentials for the auditor
1Password and Mycroft: frequently asked questions
Can Mycroft see the passwords stored in 1Password?
What does 1Password prove to an auditor?
How does this fit into a user access review?
We turn the compliance nightmare into a dream
Talk to us


