With app discovery, 1Password can identify work-related applications across vaults in a business account and includes them in reports available through 1Password SaaS Manager. This gives administrators better visibility into the work apps team members are using.
App discovery is designed to provide you with useful insights while upholding 1Password’s commitment to user privacy and data security.
To turn on app discovery:
- Sign in to your account on 1Password.com.
- Select Policies in the sidebar, then select Sharing and permissions.
- Turn on Let SaaS Manager discover work apps in the “Identifying work items” section.
- Select Save.
Technical design

When you turn on “Discover work apps”, 1Password generates a keyset that contains a public and private key, specific to app discovery.
If you’re signed in to 1Password and app discovery is turned on, the 1Password clients will automatically generate encrypted snapshots that contain limited information about vault items. The public key is used by 1Password clients to encrypt snapshots of vault items before they’re sent to the 1Password server.
The confidential computing service within 1Password’s infrastructure uses the private key to decrypt snapshots, filter snapshot information, and send work-related application results to SaaS Manager.
What gets discovered
Whether an item is discovered depends on the type of vault it’s stored in:
- Shared vaults: Any work-related items in the SaaS Manager app catalog can be discovered.
- Employee vaults: Only work-related items with a username field containing an email address in your approved email domains are discovered.
Because the Employee vault filter only recognizes email-based usernames, an item can still be discovered even if it isn’t work-related. For example, a personal banking login saved with an account number as the username isn’t filtered out, since it doesn’t look like an email address.
To reduce the chance of personal items being discovered, ask your team members to store personal logins in their free 1Password family account instead of their Employee vault.
Security model
To maintain the privacy and security of vault items, snapshots never contain password credentials. Encrypted snapshot information includes item titles, usernames, websites, Watchtower alerts, and vault names. Usernames aren’t filtered, so if a team member uses sensitive personal information like an account or ID number as a username, that information can be included.
Snapshot information is encrypted with the ChaCha20-Poly1305 key, then encrypted with HPKE using the x25519 public key.
With confidential computing, your data and private key are secured inside a special, isolated environment called an “enclave.” Confidential computing creates this tightly controlled enclave for your data, ensuring that it remains private and secure when processed. Learn more about the security of 1Password confidential computing.
Risk considerations
Snapshots only include information collected from 1Password vaults within a business account. If a team member is signed in to an individual or family account, their personal account vault information will never be collected with app discovery.
1Password helps minimize the risk of team members storing personal information in their Employee vaults with in-app communication and by limiting the information presented in vault reports. You can take steps to communicate that your team’s 1Password account should not be used to store personal information.
Turn off app discovery
When you turn off Let SaaS Manager discover work apps, 1Password stops generating new snapshots, but it doesn’t delete apps that SaaS Manager has already discovered.
To remove an already-discovered item, delete it directly in SaaS Manager. Keep in mind that:
- Items discovered from an Employee vault stay deleted.
- Items discovered from a shared vault can reappear later if a team member or group is added back to the shared vault. This happens because SaaS Manager can associate the item with the newly added user or group.
Bulk deletion of previously discovered items is currently not supported. If you need to remove a large number of items, contact 1Password support.
Was this article helpful?
Glad to hear it! If you have anything you'd like to add, feel free to contact us.
Sorry to hear that. Please contact us if you'd like to provide more details.