All templates

Automated 1Password Access Review

Once a month, WebRun opens your 1Password admin console, lists every member with their status, the groups they belong to and the vaults each group can reach, writes the whole picture into a dated Google Sheets tab, flags departed staff who still hold access, invitations never accepted and vaults shared more widely than your policy allows, then posts a short summary to Telegram.

Runs on WebRun · Strict Lockdown policy
First Monday of each month at 9:00 AM WebRunorchestrates each step
1 1Password read members, groups and vaults
2 Google Sheets export the access map
3 Telegram post the review summary
In short

How do I run a monthly review of who has access to which vault?

Once a month WebRun opens your 1Password admin console, lists every member, the groups they belong to and the vaults each group can reach, and exports it to Google Sheets. It flags people who left, pending invitations and vaults shared too widely, then posts the summary to Telegram.

  • Departed staff holding access are found within a month, not a year
  • Auditors get a dated access map instead of a screenshot
  • Vaults that quietly grew their membership are questioned

Built for IT administrators · security teams · compliance managers · operations leads

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens my.1password.com in a real browser with your saved login - no setup, no API keys.

  2. 1
    1Password - read members, groups and vaults
    1password.com
    WebRun in 1Password: read members, groups and vaults
    WebRun opens 1Password to read members, groups and vaults.
    • Sign into the 1Password admin console for your account
    • List every member with their status: active, suspended, invited or recovery pending
    • For each group, capture its members and the vaults it has access to
    • Note members who have not signed in for longer than your policy window
    • Read membership and permission metadata only. Never open, copy, export or read the contents of any item, password or secret

    Done when Every member, group and vault permission is captured with no item contents touched.

  3. 2
    Google Sheets - export the access map
    google.com
    WebRun in Google Sheets: export the access map
    WebRun opens Google Sheets to export the access map.
    • Open your Access review sheet and create a dated tab for this month
    • Write one row per member with status, groups, last sign-in and the vaults they can reach
    • Add a second table listing each vault and everyone who has access to it
    • Highlight rows for departed staff, invitations never accepted and members inactive beyond your window
    • Keep previous months in place so an auditor can see the history

    Done when This month's tab holds the full access map with exceptions highlighted.

  4. 3
    Telegram - post the review summary
    telegram.org
    WebRun in Telegram: post the review summary
    WebRun opens Telegram to post the review summary.
    • Post a summary to your internal security group: member count, changes since last month, exceptions found
    • List by name anyone flagged as departed but still holding access, since that is the one to fix today
    • Call out any vault whose membership grew unexpectedly
    • Link the sheet, and never include an item name, secret or credential in the message

    Done when The security group has this month's access review summary.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
my.1password.com
ScheduleRuns automatically on this cadence
First Monday of each month at 9:00 AM
DeliveryHow each run's result reaches you
Access review · Telegram
OutputWhat each run produces - A dated Google Sheets access map of members, groups and vault permissions with exceptions highlighted, plus a Telegram summary of what changed.
Spreadsheet
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Does it read my passwords or secrets?

No. WebRun reads membership and permission metadata only: who is a member, which groups they are in and which vaults those groups reach. It never opens an item, copies a credential or exports vault contents.

Will it remove someone's access?

No. Suspending a member, changing a group or revoking a vault permission is never done by WebRun. It reports the exception and an administrator makes the change.

Why keep every month instead of overwriting?

Because an access review is only useful with history. Each month gets its own dated tab, so you can show an auditor when a permission was granted and when it was removed.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.