Lesson 12 / 24
Offboarding and Revocation
Remove access when someone leaves and rotate the secrets they could read.
Removing access is not enough
Removing a person from a vault stops future reads, but they may have seen or copied the values while they had access. For anyone with access to production secrets, rotate those secrets as part of offboarding.
An offboarding checklist
Run through it the day the person leaves. Order matters: revoke first, then rotate.
1. Suspend the user in the identity provider and in 1Password
2. Remove them from groups and shared vaults
3. Rotate production keys they could read
4. Revoke their personal access tokens and SSH keys
5. Record the date and what was rotatedQuick check: A developer with production vault access has left. What else should you do besides removing access?
- Nothing more
- Rotate the production secrets they could read
- Rename the vault
- Delete the audit log
Answer
Rotate the production secrets they could read — They may have copied values, so rotation closes that gap.