Automated 1Password Access Review
Once a month, WebRun opens your 1Password admin console, lists every member with their status, the groups they belong to and the vaults each group can reach, writes the whole picture into a dated Google Sheets tab, flags departed staff who still hold access, invitations never accepted and vaults shared more widely than your policy allows, then posts a short summary to Telegram.
How do I run a monthly review of who has access to which vault?
Once a month WebRun opens your 1Password admin console, lists every member, the groups they belong to and the vaults each group can reach, and exports it to Google Sheets. It flags people who left, pending invitations and vaults shared too widely, then posts the summary to Telegram.
- Departed staff holding access are found within a month, not a year
- Auditors get a dated access map instead of a screenshot
- Vaults that quietly grew their membership are questioned
Built for IT administrators · security teams · compliance managers · operations leads
What does WebRun do on every run?
The exact actions WebRun takes, in order - in plain language, so you can adjust anything.
-
WebRun signs in and gets to work
Opens
my.1password.comin a real browser with your saved login - no setup, no API keys. -
1
1Password - read members, groups and vaults
WebRun opens 1Password to read members, groups and vaults. - Sign into the 1Password admin console for your account
- List every member with their status: active, suspended, invited or recovery pending
- For each group, capture its members and the vaults it has access to
- Note members who have not signed in for longer than your policy window
- Read membership and permission metadata only. Never open, copy, export or read the contents of any item, password or secret
Done when Every member, group and vault permission is captured with no item contents touched.
-
2
Google Sheets - export the access map
WebRun opens Google Sheets to export the access map. - Open your Access review sheet and create a dated tab for this month
- Write one row per member with status, groups, last sign-in and the vaults they can reach
- Add a second table listing each vault and everyone who has access to it
- Highlight rows for departed staff, invitations never accepted and members inactive beyond your window
- Keep previous months in place so an auditor can see the history
Done when This month's tab holds the full access map with exceptions highlighted.
-
3
Telegram - post the review summary
WebRun opens Telegram to post the review summary. - Post a summary to your internal security group: member count, changes since last month, exceptions found
- List by name anyone flagged as departed but still holding access, since that is the one to fix today
- Call out any vault whose membership grew unexpectedly
- Link the sheet, and never include an item name, secret or credential in the message
Done when The security group has this month's access review summary.
How is each run configured?
Secure by default
Connect once, stays signed in
WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.
Every action is checked against this policy before it runs.
Questions, answered
Does it read my passwords or secrets?
No. WebRun reads membership and permission metadata only: who is a member, which groups they are in and which vaults those groups reach. It never opens an item, copies a credential or exports vault contents.
Will it remove someone's access?
No. Suspending a member, changing a group or revoking a vault permission is never done by WebRun. It reports the exception and an administrator makes the change.
Why keep every month instead of overwriting?
Because an access review is only useful with history. Each month gets its own dated tab, so you can show an auditor when a permission was granted and when it was removed.
Put this on autopilot.
Turn it on in minutes - or have our team set it up for you.