Skip to Main Content
Back to blog

Your business runs on credentials IT did not provision

by Jairo Camacho

July 28, 2026 - 3 min

An illustration in blues and whites, showing a computer window surrounded by abstract shapes and graphics representing users, security, and other computer settings.

Related Categories

Right now, in one of your employee's personal vaults, there's a login for a vendor portal your team has been using for three years. Whoever set it up no longer works at the company. The password has never been rotated. And until today, you didn't know it existed.

That credential was created outside your systems, became essential to a business workflow, and went invisible. Every organization has hundreds like it: break-glass accounts copied into multiple vaults as a precaution, contractor logins that outlasted the contract, apps that don't support SAML so someone signed up and shared the password in Slack. Nobody in IT provisioned any of them, and all of them grant access to real systems.

These are your highest-risk credentials: unrotated, unaccountable, and largely invisible. Attackers go after exactly these accounts: the ones with no rotation schedule, no owner, and no audit history. And credentials are the way in: 88% of attacks against web applications involve stolen credentials, according to Verizon's Data Breach Investigations Report (2025). Every unmanaged credential expands your organization's attack surface.

These credentials persist because the alternatives are hard. The SSO tax makes federation too costly for some apps. Others simply don't support SAML or OIDC. So the credentials keep accumulating, untracked and unrotated, while auditors ask for evidence you can't produce. 

Credential Governance gives admins a repeatable way to find those accounts, take ownership of them, and govern access over time, all inside 1Password Enterprise Password Manager.

How Credential Governance works 

Credential Governance gives IT and security admins a repeatable workflow to discover unmanaged credentials, reclaim them as company-managed credentials, and govern access over time.

  • Discover: Build a complete inventory of unmanaged credentials. 1Password finds Login items across all employee and shared vaults and filters by domain to surface company-owned accounts. With every company-owned account in one place, your team can pinpoint the highest-risk credentials and prioritize which to remediate first.

  • Reclaim: Convert an existing credential into a company-managed item. When a credential is reclaimed, 1Password creates a company-managed version, eliminates duplicate copies, and reassigns access to only the users and teams who need it. The credential becomes a company asset instead of belonging to the person who created it.

  • Govern: Manage the credential as a company asset. Admins control who can view, use, and modify a credential. They can rotate it, revoke access instantly, and prevent non-admins from editing company-managed credentials. Every access change is recorded, giving you a complete audit trail of who can access a credential today and who could access it in the past.

Manageable, measurable, and auditor-ready

Every unmanaged credential is a question you can't answer under audit: who has access to this, when did they last use it, and can you prove they should still have it? For most organizations, the honest answer to all three is no.

Credential Governance closes that gap. When an admin reclaims a credential, access gets scoped to least privilege, duplicates get removed, and every subsequent change gets recorded. The audit trail is continuous, so when an auditor asks, you already have the answer. Standing access gets revoked, and former contractor access stops lingering.

It runs on the same security model as the rest of 1Password: end-to-end encrypted, never readable by 1Password's servers, and decrypted only on the devices that need it.

Interested in learning how 1Password can help you manage credentials and secure access? Reach out to our team today.