To audit shared password manager vaults for a departing employee, export a full audit log of that user's vault access, revoke their permissions before their last day, rotate every shared credential they touched, and document the changes in writing. The fastest way to do this reliably is with 1Password Business, which gives admins a filterable activity log, per-user vault access reports, and a one-click offboarding workflow under People → [User] → Suspend Account.
Prerequisites / What You'll Need
- Admin or Owner role in your password manager's business or team account
- 1Password Business (v8.10 or later on macOS, Windows, Linux, iOS, Android) — or Keeper Business / Dashlane Business as alternatives
- HR confirmation of the employee's exact last day and last active hour
- A secure destination for the exported audit log (encrypted folder or your SIEM platform)
- List of shared vaults the departing user was a member of — pull this before revoking access
- MFA reset authority if the user was the only admin holding backup codes for shared accounts
- Replacement credentials list — a spreadsheet or Secure Note where you'll log every rotated password
Step 1: Pull a Complete List of Shared Vaults the User Belongs To
Log in to your admin console before touching any permissions. If you revoke access first, some platforms stop showing you which vaults that user could see.
1Password Business: Go to Manage → People → [Employee Name] → Vaults. You'll see a table of every vault with their permission level (View, Edit, Manage). Export this page or screenshot it — 1Password doesn't offer a one-click CSV export of per-user vault membership at the team tier, so a manual record is necessary. The audit log at Reports → Activity Log lets you filter by user and date range and does export to CSV.
Keeper Business: Navigate to Admin Console → Users → [Employee] → Shared Folders. Keeper shows shared folder membership and role-based permissions (Can Edit, Can Share). Export via Reports → User Activity Report, which outputs a CSV with timestamp, item UID, action type, and IP address.
Common gotcha: If the employee is a vault admin on any shared vault, they can currently invite other users or change permissions. Downgrade that role to Member before you start the audit, so nothing changes under you while you work.
Step 2: Export the User's Activity Log
Activity logs tell you exactly which credentials the employee viewed, copied, or edited. This is your forensic record.
1Password Business: Reports → Activity Log → Filter by Actor → [Employee Name]. Set the date range to their entire tenure, not just the past 30 days. Export to CSV. The log records: timestamp (UTC), action (item\_viewed, item\_edited, item\_created, item\_deleted), item UUID, vault name, and IP address. Retention is 365 days on the Business plan.
Keeper Security: Admin Console → Reports → Activity Report. Filter by user, set date range. Keeper's log includes the record title, folder, action, device type, and geolocation. Keeper retains logs for 2 years on Business+ ($6.00/user/month, billed annually) and Advanced Reporting & Alerts Module (ARAM) is available as an add-on for $2.00/user/month.
Dashlane Business: Admin Console → Activity Logs. Dashlane logs credential views, shares, and revocations with timestamps. Export is CSV. Log retention on the Business plan ($8.00/user/month, billed annually, minimum 1 seat) is 90 days — notably shorter than 1Password or Keeper, which matters if an employee's notice period is long or if you're doing a retrospective audit.
Expected output: A CSV with hundreds or thousands of rows. Your goal is to isolate every row where action = item_viewed or item_edited and cross-reference it against your shared credentials list.
Common gotcha: "Item viewed" in most platforms fires when a user opens a record, not necessarily when they copy the password. Treat every viewed item as a credential that may be compromised.
Step 3: Identify Which Credentials Were Accessed
Open the exported CSV in Excel or Google Sheets. Filter the action column for item_viewed, item_edited, item_created. The result is your rotation list — every credential the employee could have seen in plaintext.
Add a second column: Rotation Priority. Mark anything labeled with payment, infrastructure, admin, API key, or production as Priority 1. Customer-facing service accounts are Priority 2. Internal tools are Priority 3.
If the employee had access to a vault containing MFA backup codes or hardware key seeds, flag those separately — rotating the password alone won't help if they still hold a TOTP secret.
Step 4: Revoke Access and Suspend the Account
Only after you have your complete vault list and activity log should you pull the trigger on revocation.
1Password Business: People → [Employee] → Suspend Account. This immediately invalidates their session tokens and prevents new logins. It does not delete their private vault, which is important if you need to recover any business credentials they stored privately. A suspended account in 1Password still counts against your seat license until you delete it.
Keeper Business: Admin Console → Users → [Employee] → Lock Account. Keeper distinguishes between Lock (immediate session termination) and Delete (permanent, cannot be undone). Lock first; delete after the retention window closes.
Dashlane Business: Admin Console → Members → Revoke Access. Dashlane immediately removes the user's decryption key from shared spaces. Their personal vault data is gone from your admin view the moment you revoke.
Common gotcha: Suspending the account does not rotate passwords automatically in any of these platforms. That step is manual — and it's Step 5.
Step 5: Rotate Every Accessed Credential
Work through your Priority 1, 2, 3 list. For each credential:
- Log in to the service directly using the current password.
- Change the password to a new randomly generated string (minimum 20 characters, mixed character set).
- If the service supports it, revoke all active sessions for the old account.
- Update the entry in the shared vault with the new credential.
- Check whether the service has its own audit log showing the ex-employee's last login — screenshot it.
- If the account uses TOTP or hardware MFA, verify the seed is stored in the vault and not only on the ex-employee's personal authenticator app. If the latter, rotate the MFA method entirely.
Log each completed rotation in your tracking spreadsheet: credential name, service URL, date rotated, rotated by (your name), new vault location.
Step 6: Archive the Audit Log and Document the Process
Save the exported activity log CSV to an encrypted location — your SIEM, an encrypted S3 bucket, or a locked folder in your document management system. Include: the employee's name and last day, the date you performed the audit, a list of vaults audited, and a list of credentials rotated.
For regulated industries, this documentation may be required. If you're in healthcare, review our best password manager for healthcare workers & HIPAA compliance guide for retention requirements specific to PHI access. Law firms should check our best password manager for law firms in 2026 article for bar-compliance considerations.
Verification — What "Done" Looks Like
You should confirm each of the following before closing the ticket:
- Account suspended: Attempt to log in with the ex-employee's credentials — you should receive an "Account locked" or "Invalid credentials" error.
- Vault membership cleared: The user should no longer appear under any shared vault's member list.
- Activity log exported and saved: Confirm the CSV file exists, opens correctly, and covers the full tenure date range.
- Rotation log complete: Every Priority 1 and Priority 2 credential has a rotation date in your spreadsheet with no blanks.
- MFA reviewed: Every shared account that uses TOTP has a seed stored in the vault, not solely on a personal device.
Recommended Tools for This Process
1Password Business — Best Overall for Offboarding Audits
1Password Business ($7.99/user/month, billed annually, no seat minimum on the Business plan) gives admins the most complete offboarding workflow of any consumer-adjacent tool I've tested. The activity log exports cleanly to CSV, retains 365 days of history, and the Suspend Account action is immediate and reversible.
Encryption: AES-256-GCM with PBKDF2-SHA256 key derivation. 1Password adds a Secret Key to the standard master password, meaning a compromised master password alone cannot decrypt vault data. MFA support includes TOTP, WebAuthn/FIDO2, Duo, and hardware keys (YubiKey). Headquartered in Toronto, Canada; subject to Canadian privacy law (PIPEDA). Platforms: macOS, Windows, Linux, iOS, Android, Chrome, Firefox, Safari, Edge, Brave. SOC 2 Type II audited (third-party audited annually).
The one honest limitation: 1Password has no automated offboarding workflow that triggers vault access removal when an HR system marks someone as terminated. You still have to do Step 4 manually, or connect via their 1Password Business SCIM Bridge to an identity provider like Okta or Azure AD.
Try 1Password Business — the most complete audit log and suspension workflow for departing employee offboarding.
Keeper Security Business — Best for Regulated Industries and Deep Reporting
Keeper Security Business costs $4.99/user/month billed annually with no seat minimum. Keeper Business+ runs $6.00/user/month and adds dark web monitoring and advanced reporting. The ARAM (Advanced Reporting & Alerts Module) add-on is $2.00/user/month and enables real-time alerts — useful if you want to be notified the moment a user views a high-value credential.
Keeper encrypts with AES-256 and uses PBKDF2-SHA256 for key derivation. MFA: TOTP, WebAuthn/FIDO2, hardware keys (YubiKey, Google Titan), Duo, RSA SecurID, SMS (not recommended but available). Headquartered in Chicago, Illinois; subject to US law, FedRAMP Authorized (Agency ATO). Platforms: macOS, Windows, Linux, iOS, Android, Chrome, Firefox, Safari, Edge. SOC 2 Type II audited (third-party audited).
Keeper's audit reports are notably more granular than 1Password's — they include device type, geolocation of each login, and which specific fields within a record were viewed. For compliance-heavy environments (HIPAA, SOC 2, FedRAMP), that granularity matters. See our best enterprise password manager review for 2026 for a full Keeper vs. 1Password breakdown.
Try Keeper Security — granular per-field access logs make it the stronger choice for compliance and audit trails.
Troubleshooting
Problem: "You don't have permission to view this user's activity" when generating the report
Fix: Your admin role may be scoped to a subset of vaults. In 1Password, only Owners and full Administrators can view account-wide activity logs. Ask your Owner-level admin to export the log, or elevate your role temporarily under Manage → Administrators.
Problem: The activity log only shows 90 days of history, but the employee has been with the company for 3 years
Fix: Dashlane Business has a 90-day log retention window. If you need longer history, Dashlane does not offer a way to recover older logs retroactively. Going forward, export logs monthly and archive them to your SIEM or encrypted cloud storage. For longer retention natively, switch to 1Password Business (365 days) or Keeper Business+ with ARAM (2 years).
Problem: Shared vault still shows the ex-employee as a member after suspension
Fix: In 1Password, account suspension prevents login but does not automatically remove vault membership. Go to each shared vault → Manage Access → remove the suspended user manually. In Keeper, locking an account does remove the user from shared folders immediately — confirm by refreshing the Admin Console.
Problem: A shared credential uses the ex-employee's personal email as the recovery address
Fix: This is a vault hygiene issue, but it's common. Before rotating the password, log in to the service and change the recovery email to a company-controlled address (e.g., [email protected]). Then rotate the password. If you can't log in because 2FA codes go to the ex-employee's phone, contact the service's enterprise support — most providers have an account recovery process for business accounts.
Problem: The ex-employee was the only admin on a shared vault and you've already deleted their account
Fix: In 1Password, the account Owner can always access and manage any vault regardless of membership. Log in as the Owner and re-assign admin rights to another user. In Keeper, contact Keeper enterprise support with your admin credentials — they can assist with orphaned shared folder recovery. This is why deleting (vs. suspending) accounts should wait at least 30 days post-departure.
FAQ
How long does a vault audit for a departing employee typically take?
A thorough audit for one employee takes 2–4 hours if your password manager's activity logs are organized and your credential inventory is current. The time-consuming part is rotating credentials — plan 5–10 minutes per service for login, password change, session revocation, and vault update. An employee with access to 50 shared credentials could mean 8+ hours of rotation work. Using a tool like 1Password Business or Keeper Security, which both export machine-readable CSV logs, cuts the inventory phase to under 30 minutes.
Should I revoke access before or after exporting the audit log?
Export the audit log first, then revoke access. If you revoke access before pulling the log, some platforms restrict or anonymize historical records for removed users, which can create gaps in your forensic trail. The sequence is: (1) pull vault membership list, (2) export full activity log, (3) suspend the account, (4) rotate credentials, (5) archive documentation. The window between log export and suspension should be minutes, not hours — ideally done in a single admin session on the employee's last day.
What happens to passwords the employee stored in their private vault?
In most zero-knowledge business password managers — including 1Password, Keeper, and Dashlane — the admin cannot read the contents of a user's private vault. The encryption key is derived from the user's master password, which the platform never sees. When you delete the account, that private vault data becomes inaccessible. If a departing employee stored company credentials in their private vault (instead of a shared vault), those credentials are effectively lost — which is exactly why a shared vault policy for all business credentials must be enforced before an employee's departure, not after.
Do I need to audit the vault if the employee was terminated for cause versus resigning?
Yes, in both cases — but the urgency differs significantly. For terminations for cause (misconduct, policy violation, or security incident), suspend the account immediately, even mid-day, and treat every credential the employee accessed in the past 90 days as potentially compromised. For standard