Skip to Main Content
Customer story

DigitalOcean governs access across devices, applications, and emerging AI workflows

About the company

DigitalOcean is an American multinational technology company and comprehensive agentic cloud, empowering developers at AI-native businesses and digital native enterprises to build full-stack AI applications with straightforward tools. 

Unlike larger cloud providers that can feel complex and overwhelming, DigitalOcean’s mission is to simplify cloud computing and AI to allow builders to spend more time creating software that changes the world. 

www.digitalocean.com

Industry

  • Cloud infrastructure

  • Platform as a Service (PaaS)

  • Technology

Use cases

  • Helping secure device access in a fully remote business environment

  • Enabling secure password, secret, and credential sharing at scale

  • Automating employee onboarding and offboarding

Secured device access to 100% of high-risk apps

Up to 10 minutes saved per employee by automating onboarding and offboarding

Achieved 100% 1Password adoption over 3 years


Outcomes

  • Strengthened overall security posture by ensuring only managed, trusted devices can access critical systems

  • Reduced organizational concerns regarding compromised sessions, phishing, and leaked credentials

  • Established a foundation for governing access across applications, devices, and emerging AI workflows

  • Improved productivity with security hardened storage and sharing between teams

  • Reduced operational IT burden by automating provisioning and deprovisioning

We needed to further strengthen our security posture, particularly in our hybrid work environment. 1Password Enterprise Password Manager and Device Trust helped us accomplish this.

Heather Cannon
Director, Security at DigitalOcean

Challenges

DigitalOcean is the AI-Native Cloud,  a fully integrated platform from silicon to agents built for AI-native and digital-native enterprises scaling production workloads. The company’s mission is to simplify cloud and AI so builders can spend more time creating software that changes the world. Founded originally as a virtual private server (VPS) provider, DigitalOcean has since built out a full stack for production AI, from GPU infrastructure to inference to managed agents.

As DigitalOcean expanded its AI-native cloud platform and global workforce, the company needed unified visibility and control across applications, AI tools, devices, credentials, and machine identities. Its existing password management solution could no longer provide the level of governance DigitalOcean desired for its’ modern, distributed environment. Heather Cannon, Director, Security, researched product features and fit for DigitalOcean, and chose 1Password to address these key challenges:

  • Limited endpoint visibility. Operating as a hybrid, globally distributed workforce meant the team had limited visibility into employee devices, increasing the company’s concern regarding unmanaged devices accessing critical infrastructure.

  • Rising risk of phishing. A significant concern to the company was phishing attacks, which could result in stolen credentials and unauthorized account access.

  • Credential sprawl and limited admin controls. The company’s previous password management tool lacked multi-factor authentication (MFA) for shared resources and couldn’t provide the desired administrative oversight, preventing granular control over user access to specific vaults and passwords.

  • Need for granular control. DigitalOcean wanted granular, customizable device health checks to secure access to highly sensitive SaaS apps.

  • Emerging AI governance requirements. As employees increasingly adopted AI-powered tools and automation workflows, DigitalOcean wanted better visibility into how AI applications were being used and a path toward governing access for both human users and software-driven workflows.

Implementing security hardened access to devices, apps, and data

The Security and IT teams implemented 1Password Enterprise Password Manager and 1Password Device Trust to put identity-based controls at the core of their cybersecurity architecture. They were confident 1Password could provide the foundation the company desired for governing access across people, devices, applications, and emerging AI-powered workflows. With centralized visibility into accounts beyond SSO and the ability to apply policies consistently across teams, DigitalOcean saw 1Password as a way to shift to more proactive identity governance.

Other key decision-makers at DigitalOcean had prior experience with and trusted 1Password, so switching from another vendor was an easy decision. The team initially migrated 1,000 users to 1Password and expanded adoption to 100% over three years, reaching 1,600 seats.

DigitalOcean’s high-risk applications are now protected by 1Password Device Checks.

Heather Cannon
Director, Security at DigitalOcean

Enforcing enterprise-grade security with programmatic control 

1Password Enterprise Password Manager gave DigitalOcean centralized control over credential sharing across teams. Sensitive access was moved into shared vaults with clear ownership, enforced permissions, and complete visibility for IT and Security. As a result, credential sprawl decreased, and strong authentication, including passkeys and two-factor protection, became the default across the organization.

1Password CLI also helps security and development teams manage secrets programmatically and migrate large-scale service accounts. At one point, Cannon’s Security team needed to migrate service accounts for their internal MySQL databases in a distributed database setup. They were able to share these accounts with their various engineering teams using the 1Password CLI with minimal manual work. “It was a big win – something we couldn’t do with our previous password management solution,” says Cannon.

1Password Enterprise Password Manager gave us the feature-complete tool we needed to help secure logins, passwords, and sharing, along with a unified console for streamlined identity and access control.

Heather Cannon
Director, Security at DigitalOcean

Extending trusted access across devices, applications, and AI tools 

1Password Device Trust enables organizations to govern access to critical apps and data from any device – including unmanaged devices, contractor, and Linux devices.  Admins can easily implement comprehensive device posture checks and even write custom checks to enforce a wide range of security policies.  This helps ensure that all devices connecting to secured applications are known, trusted, and meet baseline security requirements, such as disk encryption and appropriate OS versions. 

DigitalOcean integrated 1Password Device Trust with Okta using 1Password Hosted SCIM, which acts as a bridge between the two products, and automates the time-consuming administrative tasks associated with employee lifecycle management. 1Password Hosted SCIM doesn't require DigitalOcean to maintain anything in its own infrastructure. They can seamlessly use 1Password Device Trust to ensure that only healthy, managed, and compliant devices are granted access to critical company applications.

Now DigitalOcean’s business-critical applications are protected by 1Password Device Trust Checks. “Through ongoing visibility,  we have significantly reduced  our exposure to many known vulnerabilities,” says Cannon. 

1Password Device Trust enables DigitalOcean to automate the most time-consuming administrative tasks associated with employee lifecycle management, without the need to maintain its own infrastructure. This includes automated account provisioning and deprovisioning, group synchronization to create and manage 1Password groups and vault access, and attribute syncing for user details – such as names and email addresses – in 1Password. 

Cannon also values 1Password Device Trust because it operates quietly in the background without disrupting user workflows. Device Trust works in tandem with DigitalOcean’s MDM solutions, ensuring they’re configured and running correctly to block unauthorized, non-trusted devices from accessing critical systems. When there is an issue, end-users are provided with self-remediation instructions so they can get unblocked without needing to file an IT ticket. 1Password Device Trust can also help close a key security gap for platforms without MDM by enforcing baseline protections, such as encryption, on DigitalOcean’s Linux workstations.

Based on DigitalOcean’s internal estimates, the Security and IT teams save up to 10 minutes per employee by automating onboarding and offboarding with Okta and 1Password Hosted SCIM. Unlike the traditional 1Password SCIM Bridge, Hosted SCIM runs entirely on 1Password’s infrastructure and connects directly to supported identity providers.

Through ongoing visibility, we have significantly reduced our exposure to many known vulnerabilities.

Heather Cannon
Director, Security at DigitalOcean

Future security initiatives

Moving forward, Cannon and her team are currently planning to do more with 1Password to stay ahead of an evolving landscape. As the AI-Native Cloud, DigitalOcean builds the platform companies use to run agents in production. As software-based actors operate alongside human users and governing access for both is a first-order priority.

“AI and automation have completely rewritten the threat landscape. The risk isn't just human error anymore; it's how automated software interacts with  infrastructure and APIs. To manage this confidently, identity governance has to extend past the traditional login page and embed itself directly where credentials are utilized at scale.” 

Heather Cannon Director, Security at DigitalOcean

DigitalOcean was an early participant in the 1Password Unified Access beta and is evaluating how it can better strengthen visibility and governance across AI applications, credentials, devices, and emerging agentic workflows. “Unified Access helps us better understand and govern AI usage, reduce shadow AI risk, and establish the controls needed to enable AI adoption responsibly,” Cannon explains. As DigitalOcean expands its use of AI-assisted development and automation, the company is building an access strategy designed for a world where both humans and AI agents require secure, governed access to critical resources.

Ready to get started?

Request a demo to see how 1Password combines workforce identity, application insights, device trust, and enterprise password management in one place.