Weekly 1Password vault audit with Slack digest and Jira tickets

By General Input

Every Monday morning, spot stale passwords, missing two-factor, and duplicate logins across your vaults, then assign the risky ones for rotation.

Integrations

  • 1Password
  • Slack Bot
  • Jira

Type

Agentic Task

Categories

  • Operations
  • Engineering

Every Monday at 7am, run a credential hygiene review across our 1Password vaults and give me a prioritized picture of what needs attention. Use the 1Password Connect server credential for this, not the Events API one. The two tokens are not interchangeable, so check the base URL before choosing an operation.

Start with List Vaults to enumerate every vault the Connect token can reach. For each vault, call List Items to get its contents. List Items deliberately omits sections and field values, so for any item you intend to evaluate you must call Get Item Details on it individually to read its fields and timestamps. Vault and item collections come back unpaginated as a complete set, so there is no cursor to follow, though you can narrow a collection with a SCIM-style filter if useful (vaults filter on name only, items on title or tag only).

Surface four categories of risk. First, items that have not been updated in over a year, judged by the item's last-updated timestamp. Second, login items with no MFA, one-time password, or recovery detail recorded anywhere in their fields. Third, entries that look duplicated or reused, meaning the same credential appears to be saved across several services or vaults, matched on title, username, and website. Fourth, vaults that have quietly grown far beyond what their name implies, for example a narrowly named vault that now holds hundreds of unrelated items.

Post the digest with Slack Bot Send a Message to our security channel. Rank the riskiest findings first rather than grouping them by vault, and for each finding give the item title, the vault name, the last-updated date, and one short line on why it was flagged. Put a count per risk category at the top so the trend stays readable week to week.

For every item in the top tier, open a Jira Create Issue ticket so rotation actually gets assigned to someone. Title it with the item and vault, describe why it was flagged and what needs to happen, and reference the digest. One ticket per top-tier item, not one ticket for the whole batch. If an item was already ticketed in an earlier run and nothing about it has changed, mention it in the digest but do not open a duplicate ticket.

This part is critical. Get Item Details returns real secret values, and none of them may leave 1Password. Never put a password, key, token, one-time password seed, or any other secret value into the Slack message or the Jira ticket. Only item titles, vault names, dates, and your own reasoning belong in the output. If you are unsure whether a piece of data is sensitive, leave it out.

Related prompts

Explore more prompts
A brand asset library your marketing team actually searchesTurn Mailjet email clicks into ranked HubSpot follow-upsClean out the Looker dashboards and Looks nobody opensLiveKit live operations console for room moderationWake up dormant Keap leads with a researched reasonLiveChat coverage board for planning next week's shiftsPhone routing control panel for LiveKit voice agentsLinkedIn Ads budget pacing dashboard for every client accountGive your team Looker numbers without buying more seatsPause marketing emails to escalated customers, then restore them