1Password Businessintermediate

How to Generate Security Reports in 1Password Business

Master 1Password Business security reporting with Watchtower, Insights dashboard, and admin reports. Monitor password health, breaches, and team usage.

10 min readUpdated January 2025

Want us to handle this for you?

Get expert help →

Security reporting in 1Password Business provides visibility into your organization's password health, data breach exposure, and overall security posture. This guide covers Watchtower, Insights dashboard, and administrative reports to help you monitor and improve your team's credential security.

Prerequisites

Before you begin, ensure you have:

  • 1Password Business subscription (some features not available on Teams)
  • Owner access or membership in the Security group
  • Team members actively using 1Password
  • Understanding of password security best practices

Understanding 1Password Security Reporting

1Password offers several reporting tools:

ToolPurposeAccess Level
Watchtower (Personal)Individual password healthAll users, own vaults
Business WatchtowerOrganization-wide password healthOwners, Security group
Insights DashboardConsolidated security overviewOwners, Security group
Team ReportUser activity and statisticsOwners, Administrators
Domain Breach ReportEmail domain exposureOwners, Security group
Activity LogAudit trail of actionsOwners, Administrators

Step 1: Access the Watchtower Dashboard

Watchtower is your primary tool for identifying credential security issues.

View Personal Watchtower

For individual users:

  1. Open 1Password (app or browser extension)
  2. Click Watchtower in the sidebar
  3. View your personal security score and issues

View Business Watchtower Report

For organization-wide visibility:

  1. Sign in to 1Password.com as an owner or Security group member
  2. Navigate to Reports in the sidebar
  3. Select Watchtower
  4. View the Business Watchtower dashboard

Step 2: Understand Watchtower Categories

Watchtower checks for multiple security issues:

Compromised Passwords

What it checks: Passwords that have appeared in known data breaches.

How it works:

  • Uses Have I Been Pwned database
  • Checks via k-anonymity (privacy-preserving)
  • Only partial password hash is transmitted

Action required: Immediately change any compromised passwords.

Weak Passwords

What it checks: Passwords that don't meet strength requirements.

Criteria includes:

  • Short length
  • Common patterns
  • Dictionary words
  • Insufficient complexity

Action required: Replace with strong, randomly generated passwords.

Reused Passwords

What it checks: Same password used across multiple accounts.

Risk: One breach exposes multiple accounts.

Action required: Generate unique passwords for each login.

Unsecured Websites

What it checks: Logins for sites using HTTP instead of HTTPS.

Risk: Credentials transmitted in plain text.

Action required: Check if site now supports HTTPS, or consider discontinuing use.

Two-Factor Authentication

What it checks: Accounts that support 2FA but don't have it enabled.

Risk: Account vulnerable to credential theft.

Action required: Enable 2FA where available.

Expiring Items

What it checks: Items with expiration dates approaching.

Examples: Credit cards, passwords with rotation policies, certificates.

Action required: Renew or update before expiration.

Passkeys Available

What it checks: Sites supporting passkeys where you're still using passwords.

Benefit: Passkeys provide phishing-resistant authentication.

Action required: Consider upgrading to passkeys where supported.

Step 3: Use the Insights Dashboard

Insights provides a consolidated view of organizational security.

Access Insights

  1. Sign in to 1Password.com as an owner or Security group member
  2. Navigate to Reports in the sidebar
  3. Select Insights

Insights Dashboard Sections

Breach Checks

Monitor data breaches affecting your team:

  • Affected domains: Your email domains found in breaches
  • Affected team members: Users whose credentials may be exposed
  • Breach details: When and where breaches occurred

Password Health

Organization-wide password statistics:

MetricDescription
CompromisedPasswords found in breach databases
WeakPasswords below strength threshold
ReusedPasswords used multiple times
Missing 2FAAccounts without two-factor auth

Team Usage

Understand how your team uses 1Password:

  • Active users: Members who signed in recently
  • Items created: New credentials being saved
  • Vaults in use: Collaboration patterns
  • App usage: Desktop, mobile, browser extension

Filter and Drill Down

  1. Click on any metric to see details
  2. Filter by:
    • Time period
    • User groups
    • Vault types
  3. Export data for further analysis

Step 4: Generate Team Reports

Team reports provide administrative insights into usage and security.

Access Team Reports

  1. Navigate to Reports > Team Report
  2. Select the reporting period
  3. View or export the report

Team Report Contents

SectionInformation
OverviewTotal users, active users, items
MembershipNew members, removed members, pending
VaultsShared vaults, vault usage
SecurityWatchtower summary, compliance status
ActivitySign-ins, item changes, sharing

Export Team Reports

  1. Generate the desired report
  2. Click Export
  3. Choose format:
    • CSV for spreadsheet analysis
    • PDF for documentation
  4. Save and distribute as needed

Step 5: Review the Domain Breach Report

Monitor if your organization's email domains appear in data breaches.

Access Domain Breach Report

  1. Navigate to Reports > Domain Breach Report
  2. View breaches affecting your domains
  3. See which team members may be affected

Understanding Breach Data

ColumnDescription
Breach NameThe compromised service/database
DateWhen the breach occurred
Exposed DataWhat information was leaked
Affected UsersTeam members potentially impacted

Respond to Breaches

  1. Notify affected users immediately
  2. Reset passwords for breached services
  3. Enable 2FA if not already active
  4. Monitor for unauthorized access
  5. Document for compliance

Step 6: Review Activity Logs

Activity logs provide an audit trail of all actions in your 1Password account.

Access Activity Logs

  1. Navigate to Reports > Activity Log
  2. View recent activity across your organization

Filter Activity

Filter by:

  • User: Specific team member
  • Action type: Sign-ins, item changes, sharing
  • Date range: Custom time periods
  • Vault: Specific vaults

Activity Types Tracked

CategoryEvents
AuthenticationSign-ins, sign-outs, failed attempts
ItemsCreated, edited, deleted, shared
VaultsCreated, deleted, access changes
TeamMembers added, removed, recovered
SettingsPolicy changes, integrations

Export for Compliance

  1. Set your desired filters
  2. Click Export
  3. Choose format and date range
  4. Use for audit documentation

Step 7: Create Custom Reports

For specific compliance or analysis needs:

Using the API

1Password provides APIs for custom reporting:

# Example: List all users
op user list --format=json

# Example: Get vault details
op vault list --format=json

Integrate with SIEM

For enterprise security monitoring:

  1. Enable event streaming (if available)
  2. Configure integration with your SIEM
  3. Create custom dashboards
  4. Set up alerts for security events

Step 8: Establish Reporting Cadence

ReportFrequencyReviewer
WatchtowerWeeklySecurity team
Breach ReportWeeklySecurity team
Team ReportMonthlyIT management
Activity LogWeekly (or on-demand)Security team
InsightsMonthlyIT management

Create Report Distribution

  1. Generate reports on schedule
  2. Export in appropriate format
  3. Distribute to stakeholders:
    • Executive summary for leadership
    • Detailed data for security team
    • Compliance reports for auditors

Step 9: Act on Security Findings

Prioritize Issues

PriorityIssue TypeAction Timeline
CriticalCompromised passwordsImmediate
HighWeak passwordsWithin 24 hours
MediumReused passwordsWithin 1 week
LowMissing 2FAWithin 1 month

Communicate with Team Members

  1. Notify affected users of security issues
  2. Provide guidance on remediation
  3. Track completion of password changes
  4. Follow up on outstanding issues

Sample Notification

Subject: Action Required: 1Password Security Alert

Dear [Name],

Our security review identified the following issues
with your 1Password account:

- [X] compromised passwords
- [X] weak passwords
- [X] reused passwords

Please address these issues by [date] by:
1. Opening 1Password and clicking Watchtower
2. Reviewing flagged items
3. Updating passwords as recommended

Contact [IT support] if you need assistance.

Troubleshooting Common Issues

Watchtower Not Showing Data

Solutions:

  1. Ensure internet connectivity
  2. Wait for initial sync to complete
  3. Manually refresh Watchtower
  4. Check if vaults are properly synced

Can't Access Security Reports

Solutions:

  1. Verify you're an owner or Security group member
  2. Check your account permissions
  3. Contact your 1Password administrator

Export Fails or Times Out

Solutions:

  1. Reduce the date range
  2. Filter to specific users or vaults
  3. Try a different export format
  4. Contact 1Password support for large accounts

Best Practices for Security Reporting

Establish Baselines

  1. Document current Watchtower scores
  2. Set improvement targets
  3. Track progress over time
  4. Celebrate security wins

Automate Where Possible

  1. Schedule regular report generation
  2. Set up alerts for critical issues
  3. Integrate with ticketing systems
  4. Use APIs for custom dashboards

Document for Compliance

Maintain records of:

  • Regular security reviews
  • Remediation actions taken
  • Policy acknowledgments
  • Training completion

Next Steps

After implementing security reporting:

  1. Set improvement goals: Target Watchtower score improvements
  2. Create policies: Establish password requirements
  3. Train team members: Educate on security best practices
  4. Automate monitoring: Set up regular report distribution
  5. Plan remediation: Create process for addressing issues

Additional Resources


Need help with your security reporting program? Inventive HQ provides comprehensive security assessment and monitoring services, including 1Password security optimization, compliance reporting, and ongoing security management. Contact us for a free consultation.

Frequently Asked Questions

Find answers to common questions

Owners and members of the Security group can access Insights, the domain breach report, and Business Watchtower reports. Regular team members can only see Watchtower data for their own vaults.

Need Professional IT & Security Help?

Our team of experts is ready to help protect and optimize your technology infrastructure.