Lesson 12 / 24

Offboarding and Revocation

Remove access when someone leaves and rotate the secrets they could read.

Removing access is not enough

Removing a person from a vault stops future reads, but they may have seen or copied the values while they had access. For anyone with access to production secrets, rotate those secrets as part of offboarding.

An offboarding checklist

Run through it the day the person leaves. Order matters: revoke first, then rotate.

1. Suspend the user in the identity provider and in 1Password
2. Remove them from groups and shared vaults
3. Rotate production keys they could read
4. Revoke their personal access tokens and SSH keys
5. Record the date and what was rotated

Quick check: A developer with production vault access has left. What else should you do besides removing access?

  • Nothing more
  • Rotate the production secrets they could read
  • Rename the vault
  • Delete the audit log
Answer

Rotate the production secrets they could read — They may have copied values, so rotation closes that gap.