To audit shared password vaults for inactive or departing employees, the most reliable approach is to use a business password manager with a dedicated admin console — specifically 1Password Business — which lets you instantly see every shared vault a user can access, revoke their permissions vault-by-vault or in bulk, and generate a full audit log of their credential activity before deprovisioning the account. The entire process, done correctly, takes under 30 minutes per employee.
Prerequisites / What You'll Need
Before starting, confirm you have:
- Admin or Owner role in your password manager's business account (not just a standard user)
- 1Password Business account (or equivalent — see Recommended Tools below); minimum 1 team seat on a Business plan
- HR or IT offboarding ticket with the departing employee's exact username/email address and last working date
- List of shared vaults your organization uses (pull this from the admin console before the employee's last day)
- Access to downstream systems (e.g., AWS IAM, GitHub, Slack) for credentials that may need rotation at the source
- MFA method for your own admin account (TOTP app, hardware key, or WebAuthn) — you'll be making irreversible permission changes
- A text editor or spreadsheet to log your findings — no special software required
Step 1: Pull the Departing Employee's Activity Report
In 1Password Business, log into your admin console at 1password.com/signin, then navigate to Reports → Activity Log. Filter by User and enter the departing employee's email address. Set the date range to the last 90 days (or full tenure if available — logs are retained for 365 days on Business plans, unlimited on Enterprise).
Expected output: A timestamped list of every vault item viewed, copied, edited, or deleted by that user, including the vault name and item type (login, secure note, API key, etc.).
Export this log immediately using the "Export CSV" button. Once the user account is deprovisioned, their activity history is no longer filterable by user in some views.
Common gotcha: If the employee used the 1Password desktop app in offline mode, some actions may not appear in the Activity Log until the client synced. Check "Last sync" timestamp on the Users page — if it's more than 48 hours old, flag this for manual credential rotation regardless of what the log shows.
Step 2: Map Every Shared Vault the Employee Could Access
In the admin console, go to People → [Employee Name] → Vaults. This page lists every vault — both shared team vaults and any vaults they were explicitly granted access to — along with their permission level: View, Edit, or Manage.
Write down every vault where their permission is Edit or Manage. These are your highest-priority rotation targets because the employee could have modified or exfiltrated credentials without leaving an obvious trail.
For vaults where they had View only, you still need to rotate credentials that are high-sensitivity (admin passwords, API keys, payment credentials, customer PII access).
Expected output: A named list of vaults with permission levels, e.g.:
DevOps-AWS— EditSocial-Marketing— ViewFinance-Stripe— ManageShared-WiFi— View
Common gotcha: 1Password Collections can bundle multiple vaults under one access grant. Check the Collections tab on the user profile — a single Collection assignment can expose 10+ vaults that won't all show individually until you expand it.
Step 3: Rotate Credentials in Every High-Access Vault
For each vault where the employee had Edit or Manage access, rotate the underlying credentials — not just the password manager entry. Log into the actual service (AWS Console, GitHub, Stripe dashboard, etc.) and generate new credentials there. Then update the vault entry with the new credentials.
Do not simply change the password inside the vault without changing it at the source. The departing employee may have noted or cached the old credential outside the vault.
Rotation priority order:
- Infrastructure credentials (cloud provider keys, server passwords, VPN keys)
- Financial/payment system credentials
- Third-party SaaS with admin-level access
- Shared social media and marketing accounts
- View-only low-sensitivity items (rotate opportunistically, not urgently)
Expected output: Each rotated item in the vault shows a "Modified by [your name]" entry with today's timestamp in the Activity Log.
Common gotcha: Some services (older SMTP relays, legacy FTP accounts) don't invalidate sessions when a password changes. Audit active sessions on those services separately.
Step 4: Revoke the Employee's Vault Access and Suspend Their Account
Before fully deleting the account, suspend it first — this revokes all active sessions and prevents login, but preserves the Activity Log and vault access history for your audit trail.
In 1Password Business: People → [Employee Name] → Suspend User. Confirm in the dialog. The user is immediately signed out of all devices and loses vault access.
Do not click Delete User until you have confirmed:
- The exported Activity Log CSV is saved
- All high-priority credentials have been rotated
- Any vaults they owned (not just accessed) have been transferred to another admin
To transfer vault ownership: People → [Employee Name] → Transfer Vaults, then select the receiving admin account.
Expected output: The user's status badge changes to "Suspended." Their name still appears in the People list with a gray indicator. Vault access columns on their profile now show "None."
Common gotcha: If the employee was a vault Manager, other team members may have been able to share that vault externally (via Guest links in 1Password). Check Sharing → Guest Access and revoke any guest invitations tied to vaults they managed.
Step 5: Verify Removal Across All Shared Vaults
Do not rely solely on the user profile page. Cross-check by going to Vaults → [Each High-Priority Vault] → People and confirming the suspended/deleted user no longer appears in the member list.
For each vault you rotated credentials in, open the vault item and confirm the "Last modified" timestamp matches your rotation date and your admin username.
Run one final Activity Log query filtered to the suspended user — if any new entries appear after the suspension timestamp, investigate immediately (this could indicate a still-active API token or integration key tied to their identity).
You should see: Zero vault memberships, zero active sessions, and no post-suspension Activity Log entries for that user.
Recommended Tools
1Password Business
1Password is the strongest fit for this workflow because the Activity Log, Collections management, and vault-level permission controls are all available in a single admin console — not spread across separate apps.
Pricing: $2.99/user/month for Teams (billed annually, 1-seat minimum); $7.99/user/month for Business (billed annually, 1-seat minimum); Enterprise pricing starts at negotiated rates above the Business tier.
Encryption: AES-256-GCM with PBKDF2-SHA256 key derivation. Vault keys are encrypted with the user's account key locally before sync.
MFA: TOTP, WebAuthn/FIDO2, hardware security keys (YubiKey, etc.), Duo push.
Audit trail: SOC 2 Type II audited; third-party security assessments published on their security page.
Jurisdiction: Headquartered in Toronto, Canada; data stored on AWS infrastructure; subject to Canadian privacy law (PIPEDA) and GDPR for EU users.
Platforms: macOS, Windows, iOS, Android, Linux, Chrome, Firefox, Safari, Edge, Brave.
Honest limitation: 1Password's Activity Log does not capture clipboard events — if an employee copied a password, that action is logged, but what they did with it is not. This is a fundamental limitation of client-side logging, not unique to 1Password.
Try 1Password Business — the Activity Log and vault-level permission controls make offboarding audits systematic rather than manual.
For teams that also want automated inactive-user detection, Keeper Security is worth evaluating alongside 1Password. Keeper at $4.00/user/month (Business tier, billed annually, 5-seat minimum) includes an Admin Console with a dedicated "Inactive Users" report that flags accounts with no login activity in a configurable window (7, 30, or 90 days). Keeper uses AES-256 encryption with PBKDF2-SHA512 key derivation, supports TOTP, WebAuthn, hardware keys, and SSO via SAML 2.0, and is SOC 2 Type II audited. Headquartered in Chicago, IL, USA; subject to US law with optional EU data residency. Platforms: Windows, macOS, iOS, Android, Linux, Chrome, Firefox, Edge, Safari.
Try Keeper Security — the Inactive Users report is genuinely useful for catching stale accounts before they become an offboarding emergency.
For broader context on enterprise password manager selection, see our Best Enterprise Password Manager Review (2026) and our guide to Best Password Manager for Teams & Remote Work in 2026.
Troubleshooting
Issue 1: "User not found" when searching Activity Log
The employee may have had multiple accounts (personal and business email). Search by partial email or check People → All Users including the "Guests" tab. Guest accounts have separate Activity Logs under Sharing → Guest Access.
Issue 2: Vault transfer fails with "No eligible vaults to transfer"
This appears when the departing user owned no vaults directly — all their access was via group membership. No transfer is needed. Verify by checking Groups on their profile and confirming the group still has the correct members post-suspension.
Issue 3: Suspended user still appears as a vault member
This is a display refresh bug seen occasionally in the 1Password web console. Hard-refresh the page (Ctrl+Shift+R / Cmd+Shift+R). If the user still appears, navigate away and back. If the issue persists after 10 minutes, use the 1Password CLI (op user get ) to confirm actual suspension status at the API level.
Issue 4: "Insufficient permissions to view Activity Log"
Only Owners can view full Activity Logs in 1Password Business. Administrators see a scoped view. If you're an Admin and need full logs for a compliance audit, request an Owner to export the CSV on your behalf, or ask your Owner to temporarily elevate your role.
Issue 5: Employee had access via SCIM provisioning (Okta, Azure AD)
If your organization uses SCIM, deprovisioning in the IdP (Okta, Azure AD) should automatically suspend the 1Password account. Verify this happened by checking the user's status in the 1Password admin console within 15 minutes of IdP deprovisioning. If the account is still active, the SCIM sync may be broken — check Integrations → Directory Sync → Sync Status for error messages.
FAQ
How often should I audit shared password vaults, not just during offboarding?
Quarterly audits are the minimum recommended cadence for most teams. During each audit, pull an access report for every shared vault, identify any users whose job roles have changed since the last audit (promotions, department transfers, extended leave), and revoke or downgrade permissions that no longer match current roles. For regulated industries — healthcare under HIPAA, legal under state bar requirements — monthly audits are more appropriate. Our Best Password Manager for Healthcare & HIPAA Compliance in 2026 covers the specific audit documentation HIPAA requires.
What's the difference between suspending and deleting a user in a business password manager?
Suspending a user immediately revokes all active sessions and vault access but preserves their account data, Activity Log history, and vault ownership records in the admin console. Deleting a user permanently removes their account and — depending on the platform — may purge associated logs. For offboarding audits, always suspend first, complete your credential rotation and log export, then delete after a retention window (30–90 days is common). In 1Password Business at $7.99/user/month, suspended accounts do not count toward your billed seat count after the current billing cycle.
Do I need to rotate passwords the departing employee could only view, not edit?
Yes, for any credential that grants privileged access to systems containing sensitive data. A user with View access still saw the plaintext password — the vault's encryption protects credentials from external attackers, not from authorized users who read them. The practical threshold most security teams use: rotate all admin, root, API key, and financial credentials regardless of permission level; rotate standard SaaS credentials if the employee had any potential motive or if the account accesses customer data.
Can a shared vault audit be automated instead of done manually each time?
Partially. Tools like 1Password and Keeper support SCIM provisioning, which automates account suspension when an employee is removed from your IdP (Okta, Azure AD, Google Workspace). However, credential rotation cannot be fully automated — the underlying services require human authentication to generate new secrets. You can automate the detection and alerting steps (inactive user flags, access anomaly reports) but the rotation and verification steps require a human decision and action. Workflow automation tools like Okta Workflows or Tines can script parts of the process, but are not a substitute for the manual rotation checklist.
What should I document for a compliance audit after offboarding an employee?
Your compliance documentation should include: (1) the exported Activity Log CSV covering the employee's full tenure or last 90 days minimum, (2) a timestamped list of every vault they had access to with permission levels, (3) a rotation log showing which credentials were rotated, by whom, and on what date, (4) the suspension and deletion timestamps from the admin console, and (5) any vault ownership transfers. Store these records for the duration required by your applicable regulation — 6 years under HIPAA, 7 years under SOX, and typically 3 years under GDPR Article 5 accountability requirements. A PDF export of the admin console's user profile page at time of suspension is a useful single-page summary.
Wrapping Up
A shared vault audit during employee offboarding is not a one-click process, but it is a repeatable one. The steps above — activity log export, vault mapping, credential rotation, account suspension, and cross-verification — take under 30 minutes when your team has the right tooling in place before an employee's last day, not after.
1Password Business at $7.99/user/month remains the tool I'd recommend for most teams running this workflow. The Activity Log depth, vault-level permission granularity, and Collections management give you everything you need to conduct a defensible audit. The main gap — clipboard event logging — is a limitation to understand and compensate for with a rotation-first policy on all sensitive credentials, regardless of what the logs show.
If automated inactive-user detection is a priority, pair 1Password with an IdP that supports SCIM, or evaluate Keeper Security at $4.00/user/month as an alternative with built-in inactive user reporting.
For teams in regulated industries, our Best Enterprise Password Manager Review (2026) covers compliance-specific features in more depth, including FedRAMP-authorized options and detailed SOC 2 audit comparisons.
**[