Build a credential rotation checklist when someone leaves

By General Input

When someone leaves, we check which shared passwords they used in their final months and post a ranked rotation list to your security channel.

Integrations

  • 1Password
  • Rippling
  • Slack Bot
  • Jira

Type

Agentic Task

Categories

  • Operations
  • Engineering

Every weekday at 7am, check Rippling for anyone who has just left the company. Use List Workers with a filter on employment status to find workers who are terminated, and keep only the people whose termination took effect in the last day so each departure is reported exactly once. Expand the worker records so I have the person's name, work email, department, manager, and last day, which I need to identify them in 1Password. If nobody left, stop quietly without posting anything.

For each departure, pull their credential history from 1Password with List Item Usages, covering the 90 days up to and including their last day. Narrow the usage feed to the departing person by matching on their work email or 1Password account, and page through with the cursor until there are no more results so nothing is missed. Record, for every item they touched, when they last opened it and how many times they opened it, splitting the count into their final two weeks versus the earlier baseline.

Enrich the results so the report names real credentials instead of raw identifiers. Use Get Item Details for each item they touched to read its title, category, and tags, and Get Vault Details for each vault to read the vault name, description, and owner. Cache every lookup so a credential accessed fifty times is only fetched once.

Also run List Audit Events for that person over the same window, paying close attention to their final week. I want to catch anything they changed on the way out: new or updated item sharing links, vault permission and membership changes, items moved or exported, and any access they granted to themselves or to others. Report these separately from ordinary day to day access, because a sharing link created the day before someone leaves is the highest risk signal in the whole review.

Work out which credentials genuinely need rotating rather than listing everything the person ever opened. Weight upward: items in shared or production vaults, admin and infrastructure credentials such as root cloud accounts, package publishing tokens, CI and deploy keys, database access, and VPN or network gear, and anything accessed unusually often in their final two weeks compared with their earlier baseline. Weight downward or exclude entirely: items in their own private vault, personal items, credentials already deprovisioned or deleted, and single sign-on logins that are already revoked by disabling their identity. Give each credential that survives an urgency of critical, high, or medium, along with a one line reason a security lead can act on.

Post one message per departing person to my security channel using Send a Message in Slack, ordered most urgent first. Lead with the person's name, department, last day, and how many credentials need rotating, then give the ranked checklist with the credential title, the vault name, the urgency, when they last opened it, how often they used it in their final two weeks, and why it made the list. Finish with a short section for the last minute sharing and permission changes from the audit events, and a line noting what was deliberately skipped, such as private vault items and already revoked logins. If several people left the same day, post a separate message for each, most urgent person first.

Then open one Jira issue per credential that needs rotating using Create Issue. Title each issue with the credential and vault name, for example "Rotate: AWS Root Account (Production Infrastructure vault)". In the description include who left, their last day, when they last accessed the credential, how often they used it, the urgency and the reasoning behind it. Assign the issue to the vault owner where the vault metadata identifies one, and fall back to the security channel owner when it does not. Map the urgency onto the Jira priority field, and do not create an issue if one already exists for the same credential and the same departure.

One important detail about 1Password: it exposes two separate APIs with separate tokens and separate base URLs. The Events API covers item usage and audit events, while the Connect server covers item and vault details, and a token issued for one does not authenticate against the other. This workflow may therefore need two distinct 1Password connections. If only an Events connection is available, still produce the full report and the rotation ranking, but refer to credentials and vaults by their identifiers and note in the Slack message that titles could not be resolved. Never fail the run just because the enrichment lookups are unavailable.

Related prompts

Explore more prompts
A brand asset library your marketing team actually searchesTurn Mailjet email clicks into ranked HubSpot follow-upsClean out the Looker dashboards and Looks nobody opensLiveKit live operations console for room moderationWake up dormant Keap leads with a researched reasonLiveChat coverage board for planning next week's shiftsPhone routing control panel for LiveKit voice agentsLinkedIn Ads budget pacing dashboard for every client accountGive your team Looker numbers without buying more seatsPause marketing emails to escalated customers, then restore them