# Blog on 1Password Blog

Recent content in Blog on 1Password Blog

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Introducing universal sign-in: a seamless solution for every way you login

DevFeed: [Introducing universal sign-in: a seamless solution for every way you login](<https://devfeed.tech/articles/introducing-universal-sign-in-a-seamless-solution-for-every-way-you-login-1935.md>)

Original publisher: [Read original article](<https://1password.com/blog/introducing-universal-sign-in>)

Author: info@1password.com (Travis Hogan and Brandon Lucier)

Published: 2026-09-03T00:00:00Z

Content type: release

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [passwords](<https://devfeed.tech/topics/passwords.md>), [MFA](<https://devfeed.tech/topics/mfa.md>)

Tags: [1password-in-the-browser](<https://devfeed.tech/tags/1password-in-the-browser.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [browser](<https://devfeed.tech/tags/browser.md>), [extension](<https://devfeed.tech/tags/extension.md>), [launch](<https://devfeed.tech/tags/launch.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

1Password releases universal sign-in in its browser extension, presenting passwords, passkeys, one-time codes, social logins, and managed-app methods in one prompt.

### Source excerpt

Today we're releasing universal sign-in, a new experience from 1Password that provides a seamless and secure way to sign into any site with your preferred method. It's currently available to all customers in the latest version of the 1Password browser extension. A single prompt for every sign-in Signing in doesn't happen one way anymore. A single site might support passwords, passkeys, or third-party providers like Google. Over the last several years, 1Password has evolved to support all major authentication methods used today (passwords, passkeys, 2FA, social logins, OIDC and SAML). But the authentication experience varied because of differences with the underlying technologies. Not having a consistent way to use every authentication type 1Password offered meant needing to remember which third-party provider account you used, manually submitting pages, or needing to find and click sign-in fields. No password manager on the market had a single, consistent way to let you sign in, until now. Universal sign-in means that when you land on a login page, 1Password displays a single prompt to sign in using the authentication method you've chosen for that website. No need to remember how you've logged into the website in the past; passwords, passkeys, one-time codes, social logins, and company-managed apps will all appear in the same, intuitive prompt. Simply pick which account you'd like to sign in with, and 1Password handles the rest. How it works Visit a login page, or launch a saved login in 1Password with an available sign-in URL. The universal sign-in prompt appears at the top of the login page using our new advanced field analysis. It'll appear when you need it, and disappear when you don't. Every account and available authentication method is listed and selectable within the universal sign-in prompt. Choose the login you'd like to use. Over time, 1Password also learns which accounts and methods you prefer using for that site. 1Password then automatically fills your

## 5 ways to optimize AI costs and reduce wasted AI spend

DevFeed: [5 ways to optimize AI costs and reduce wasted AI spend](<https://devfeed.tech/articles/5-ways-to-optimize-ai-costs-and-reduce-wasted-ai-spend-1889.md>)

Original publisher: [Read original article](<https://1password.com/blog/5-ways-to-optimize-ai-costs>)

Author: info@1password.com (Rachel Sudbeck)

Published: 2026-09-03T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [cursor](<https://devfeed.tech/topics/cursor.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [ai-models](<https://devfeed.tech/tags/ai-models.md>), [cost](<https://devfeed.tech/tags/cost.md>), [cursor](<https://devfeed.tech/tags/cursor.md>), [saas-management](<https://devfeed.tech/tags/saas-management.md>), [shadow-ai](<https://devfeed.tech/tags/shadow-ai.md>), [unified-access](<https://devfeed.tech/tags/unified-access.md>)

### AI overview

The article outlines ways businesses can reduce AI spending, including choosing less expensive models, overseeing AI agents, and identifying shadow AI.

### Source excerpt

The tokenmaxxing era has left companies grappling with an uncomfortable reality. Now that AI vendors have switched to usage-based billing models, businesses are facing sky-high bills, and IT and finance teams are under pressure to rein in spending without slowing down innovation. The logical first step is to locate areas where that spend is going to waste, but even getting visibility into usage can be overwhelming when it's spread across departments, users, models, vendors, and agents. If you're trying to track down wasted AI spend and find opportunities to optimize your tokens, it helps to start with some of the primary reasons why AI bills may balloon past your company's budget. Top ways to optimize your company's AI costs So IT and Finance teams can know where to focus their efforts, here are five of the most common sources of unexpected AI spend. 1. Stop defaulting to the most expensive model For businesses to optimize spend, they need a way of overseeing and enforcing which models are being used for what tasks. Different AI models can vary wildly both in their abilities and their cost, and many users default to flagship AI models without realizing that there are more affordable options that can accomplish their goals at a fraction of the cost. For instance, in a recent experiment run by Cursor, building a web browser from scratch cost $10,565 when using a top-tier flagship model, and $1,339 when using a mix of models, even though the end results were comparable in terms of quality. 2. Stop letting agents run without oversight As the Stanford Digital Economy Lab reported, AI agents are "uniquely expensive, consuming 1000x more tokens than code reasoning and code chat." Meanwhile, data from OpenRouter shows that the majority of tokens spent overall are being used by agents. Here's a scenario that's becoming familiar to many AI developers and builders: An agent is instructed to perform a certain task, but it fails. So it tries again, and fails. With each loop, it

## 1Password signs OpenAI open letter calling for collective action on cyber defense

DevFeed: [1Password signs OpenAI open letter calling for collective action on cyber defense](<https://devfeed.tech/articles/1password-signs-openai-open-letter-calling-for-collective-action-on-cyber-defense-1944.md>)

Original publisher: [Read original article](<https://1password.com/blog/openai-open-letter-cyber-defense>)

Author: info@1password.com (1Password)

Published: 2026-08-28T00:00:00Z

Content type: opinion

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [AI Bots](<https://devfeed.tech/topics/ai-bots.md>), [AI, ML & Data Engineering](<https://devfeed.tech/topics/ai-ml-data-engineering.md>), [cursor](<https://devfeed.tech/topics/cursor.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [agentic](<https://devfeed.tech/tags/agentic.md>), [ai](<https://devfeed.tech/tags/ai.md>), [audit-trail](<https://devfeed.tech/tags/audit-trail.md>), [aws](<https://devfeed.tech/tags/aws.md>), [cloud-infrastructure](<https://devfeed.tech/tags/cloud-infrastructure.md>), [codex](<https://devfeed.tech/tags/codex.md>), [collective](<https://devfeed.tech/tags/collective.md>), [cursor](<https://devfeed.tech/tags/cursor.md>), [identity](<https://devfeed.tech/tags/identity.md>), [openai](<https://devfeed.tech/tags/openai.md>), [security](<https://devfeed.tech/tags/security.md>), [unified-access](<https://devfeed.tech/tags/unified-access.md>)

### AI overview

1Password supports OpenAI's call for collective cyber defense, arguing that AI agents need least-privilege access, traceable identities, clear boundaries, and audit trails.

### Source excerpt

As AI moves from answering questions to taking actions, the ecosystem around it will determine whether organizations can use it safely and with confidence. OpenAI's open letter on collective cyber defense warns that defenders have a limited window to strengthen security. It urges organizations to fix their highest-risk weaknesses, build least privilege and strong access controls, verify fixes, and make agentic identities traceable and accountable. The real work is building the ecosystem that lets them act safely and earn trust in production. That is why we continue working with OpenAI on trusted access for people and their agents. 1Password integrations with OpenAI, Codex, Anthropic Claude Code, Cursor, Kiro, Perplexity, and AWS Secrets Manager extend trusted access across development and cloud workflows. People should give agents access to key systems without exposing underlying credentials to the AI model. Cyber defense is a leadership responsibility. AI changes who and what can act inside the most sensitive systems, so identity security can no longer stop at human login. OpenAI is right to call for urgency, coordination, and fixes that organizations can verify without disrupting essential services. The standard is simple: every agent needs an identity, a boundary, and an audit trail." -Nancy Wang, Chief Technology Officer, 1Password Status quo security won't be enough Every security organization balances known weaknesses, technical debt, and limited time. The challenge for CISOs is deciding where to focus first and finding controls that reduce risk across the environment where AI is changing who and what can act inside an organization. Agents that work across browsers, repositories, terminals, cloud infrastructure, and production systems create a security challenge that begins before they take action. Standing access gives an agent more authority than a specific task requires and keeps it available after the task ends. If the agent is compromised or follows untru

## How to start the AI-accelerated defense

DevFeed: [How to start the AI-accelerated defense](<https://devfeed.tech/articles/how-to-start-the-ai-accelerated-defense-1898.md>)

Original publisher: [Read original article](<https://1password.com/blog/ai-assisted-detection-engineering>)

Author: info@1password.com (Wade Wells)

Published: 2026-08-27T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Detection engineering](<https://devfeed.tech/topics/detection-engineering.md>), [Prompt Engineering](<https://devfeed.tech/topics/prompt-engineering.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [log management](<https://devfeed.tech/topics/log-management.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-adoption](<https://devfeed.tech/tags/ai-adoption.md>), [documentation](<https://devfeed.tech/tags/documentation.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [llm](<https://devfeed.tech/tags/llm.md>), [logging](<https://devfeed.tech/tags/logging.md>), [onboarding](<https://devfeed.tech/tags/onboarding.md>), [security](<https://devfeed.tech/tags/security.md>), [validation](<https://devfeed.tech/tags/validation.md>), [workflow](<https://devfeed.tech/tags/workflow.md>)

### AI overview

This article explains how a security team began adopting AI for detection engineering by supplying the documentation and workflow context that AI systems lack. It covers an AI Detection Engineering stack involving logging pipelines, log onboarding, detection validation, threat modeling, and detection logic, and shows why better context produces more reliable results than relying on prompts or increasingly powerful models.

### Source excerpt

Early on in the AI adoption boom, I gained a reputation for just throwing everything at it to see what would stick. That wasn't the most effective strategy, and my token usage was crazy high. There are a ton of talks and posts on all the cool ways you can use AI for detection engineering, but I didn't see any that showed you where to begin. So, this isn't another blog about why you need to use AI in your defensive workflows. It seems most people understand why we need that. My focus is to show how our team got started and realized that providing AI with the necessary context is key to detection engineering successfully adopting AI. This is not just about building detection logic, but that is one of the goals. This foundation helps create the AI Detection Engineering stack: logging pipelines, log onboarding, detection validation, threat modeling, and more. An LLM does not know your stack, so out of the box it has limited value in a security review. In our experience, reliable results depend less on the fanciest model and more on the documentation and context around the workflow. If a human reads your log inventory and still has to ask three people what the ingestion method is, your agent does too. Why cold prompting fails When we first started using AI tooling, we realized prompts alone could get stuff done, but the output was inconsistent. Fields were missed, assumptions were made, and some detection logic was wrong. We saw it write queries that would not work in our SIEM. Usually these were around wildcards. The playbooks it wrote were generic, the tuning was poor, and some detections were just bad. With enough re-prompting, the output would improve, but it always required some massaging. The effort invested in the agent inputs had a noticeable impact on the quality of the outputs. TL;DR: garbage in, garbage out. Where our context came from At the start, this was just internal documentation we built to make our own lives easier. It started with new-hire materials a

## 1Password product enhancements: Smarter autofill, phishing prevention, and more

DevFeed: [1Password product enhancements: Smarter autofill, phishing prevention, and more](<https://devfeed.tech/articles/1password-product-enhancements-smarter-autofill-phishing-prevention-and-more-1884.md>)

Original publisher: [Read original article](<https://1password.com/blog/1password-product-enhancements-smarter-autofill-phishing-prevention>)

Author: info@1password.com (Elaine Atwell)

Published: 2026-08-27T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [1Password in the browser](<https://devfeed.tech/topics/1password-in-the-browser.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Passkeys](<https://devfeed.tech/topics/passkeys.md>), [macOS](<https://devfeed.tech/topics/macos.md>), [iOS](<https://devfeed.tech/topics/ios.md>), [iphone](<https://devfeed.tech/topics/iphone.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [migration](<https://devfeed.tech/topics/migration.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [ios](<https://devfeed.tech/tags/ios.md>), [iphone](<https://devfeed.tech/tags/iphone.md>), [macos](<https://devfeed.tech/tags/macos.md>), [migration](<https://devfeed.tech/tags/migration.md>), [news](<https://devfeed.tech/tags/news.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [product](<https://devfeed.tech/tags/product.md>), [saas](<https://devfeed.tech/tags/saas.md>), [update](<https://devfeed.tech/tags/update.md>)

### AI overview

This English developer article presents recent 1Password product enhancements focused on smoother credential management and sign-in. It covers universal sign-in for personal and business accounts, macOS autofill, native password generation and saving in iOS 26.2, an iOS autofill health check, and improvements related to data ownership and migration.

### Source excerpt

At 1Password, we're constantly working to make life simpler and more secure for our users, from the biggest businesses to each individual who signs up for our password manager. Over the past few months, we've been rolling out a slew of updates designed to make a difference for customers, whether you're using us at home, at work, or (ideally) both. Here are some of the latest developments for you to explore. Upgrades to autofill and autosave One of the most immediate benefits of using 1Password in your daily life is a smooth experience of creating, saving, and inputting your credentials and logins. These updates help you get the most out of that experience, with fewer clicks, on the devices you already use. Universal sign-in for personal and business accounts Signing in just got simpler with a smarter, modern experience using a one-click prompt. Now in beta, 1Password seamlessly logs you into any site or service at the right moment using your desired authentication method (passwords, passkeys, social sign in, OIDC, SAML*). We remove all the extra steps so you sign in quickly and smoothly, while staying secure. *SAML is only available for business accounts that also have 1Password SaaS Manager. macOS autofill 1Password now works as a native Credential Provider on macOS, so your logins and passkeys easily fill right inside Safari and other desktop apps. Save and generate passwords in iOS 26.2 The password creation experience on iPhone and iPad should happen at the exact moment you need it, especially when you're signing up for a new account. With this update, 1Password shows up natively in Safari and other iOS-native apps so you can generate and save a strong password right in the account creation flow, without leaving what you're doing. This makes it easier to capture credentials when they're created and keeps account setup uninterrupted. Autofill health check for iOS The reliability of iOS autofill depends on a tangle of systems, and when there's a problem with one,

## When AI adoption outpaces IT visibility

DevFeed: [When AI adoption outpaces IT visibility](<https://devfeed.tech/articles/when-ai-adoption-outpaces-it-visibility-1973.md>)

Original publisher: [Read original article](<https://1password.com/blog/when-ai-adoption-outpaces-it-visibility>)

Author: info@1password.com (Stephanie Torto)

Published: 2026-08-27T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [Responsibility & Safety](<https://devfeed.tech/topics/responsibility-safety.md>), [dashboards](<https://devfeed.tech/topics/dashboards.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-adoption](<https://devfeed.tech/tags/ai-adoption.md>), [ai-governance](<https://devfeed.tech/tags/ai-governance.md>), [cost](<https://devfeed.tech/tags/cost.md>), [dashboards](<https://devfeed.tech/tags/dashboards.md>), [models](<https://devfeed.tech/tags/models.md>), [saas](<https://devfeed.tech/tags/saas.md>), [saas-management](<https://devfeed.tech/tags/saas-management.md>), [unified-access](<https://devfeed.tech/tags/unified-access.md>)

### AI overview

1Password describes how fragmented vendor dashboards and consumption-based AI pricing made it difficult for IT to understand AI spending. It argues that IT should provide visibility and context for business and engineering leaders making budget and model decisions.

### Source excerpt

At 1Password, we started expanding our use of AI with a familiar IT playbook. We identified the problems we wanted to solve and the tools that could help us achieve those goals. The plan was straightforward: enable teams, move quickly, learn what worked, and build the visibility needed to manage the cost. Then the operating model changed. AI vendors introduced consumption-based pricing faster than our processes could keep up, leaving us with a distributed system of vendor-specific dashboards to track and manage our AI use. For IT, that created a new kind of chaos when it came to understanding how much we were spending on AI and where that budget was being used throughout the company. We had data spread across systems, but we didn't yet have a clear, shared answer. How IT teams can govern AI use IT teams are close to the tools and access patterns that shape AI usage. That gives IT an important role in AI spend decisions, and is no small part of why AI governance can become framed as an IT mandate. Budget and model decisions belong with the leaders who set business and engineering priorities, while IT's role is to provide the context those leaders need. In the face of the changing nature of AI governance, IT teams should focus on finding ways to make AI spend explainable, to give the company a more useful basis for making decisions. Visibility changes the conversation Previously, 1Password's IT team could see activity in individual vendor consoles, but each view covered only part of the picture. We spent too much time moving between systems and interpreting different definitions. By the time we exported data from one tool and combined it with another, the result was already out of date. When we started using AI Spend and Consumption Management in 1Password SaaS Manager, it felt like a breath of fresh air. We now had a shared view of AI usage and spend across vendors and teams, with detailed insights on users and models, meaning that we could better understand our budg

## Fewer lockouts, less manual work: What's new for 1Password EPM admins

DevFeed: [Fewer lockouts, less manual work: What's new for 1Password EPM admins](<https://devfeed.tech/articles/fewer-lockouts-less-manual-work-what-s-new-for-1password-epm-admins-1972.md>)

Original publisher: [Read original article](<https://1password.com/blog/whats-new-for-1password-epm-admins>)

Author: info@1password.com (Jairo Camacho)

Published: 2026-08-26T00:00:00Z

Content type: release

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [Provisioning](<https://devfeed.tech/topics/provisioning.md>), [Multi-tenancy](<https://devfeed.tech/topics/multi-tenancy.md>), [Entra ID](<https://devfeed.tech/topics/entra-id.md>), [releases](<https://devfeed.tech/topics/releases.md>), [Single sign-on (SSO)](<https://devfeed.tech/topics/sso.md>)

Tags: [documentation](<https://devfeed.tech/tags/documentation.md>), [entra-id](<https://devfeed.tech/tags/entra-id.md>), [identity](<https://devfeed.tech/tags/identity.md>), [integration](<https://devfeed.tech/tags/integration.md>), [multi-tenancy](<https://devfeed.tech/tags/multi-tenancy.md>), [news](<https://devfeed.tech/tags/news.md>), [outage](<https://devfeed.tech/tags/outage.md>), [releases](<https://devfeed.tech/tags/releases.md>), [scale](<https://devfeed.tech/tags/scale.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

1Password announces releases for EPM admins focused on reducing lockouts and automating provisioning at scale. The updates include Entra ID secret-expiration tracking with reminders and guided rotation, integration between Multi-Tenancy and Automated Provisioning, and Vault Migrations for populating shared vaults in linked accounts.

### Source excerpt

As a company grows, more employees join, but the size of the IT team overseeing critical systems often doesn't grow at the same pace. Admins have to be intentional about prioritizing their efforts to meet the needs of a growing organization. That's why we're excited to announce several releases aimed at helping admins optimize their organization's use of 1Password in two important areas: reducing lockouts and automating provisioning at scale. Preventing avoidable lockouts Entra ID Secret Expiration Most 1Password Business accounts sign in via SSO through an identity provider like Microsoft Entra ID. Admins rely on a secret provisioned by Entra to establish connectivity with 1Password. However, it comes with an expiration date. Once it expires, the connection breaks, preventing anyone from signing in. This was one of the most common and disruptive patterns we'd observe with customers. Entra ID Secret Expiration now tracks it for you. Simply record the expiration date, and 1Password will send escalating reminders across in-app banners, emails, and login prompts at a fixed cadence (e.g., 90/60/30 days). Once it's time to rotate the secret, follow the guided flow in the Admin Console, confirm it's working as intended, and the countdown resets automatically. A predictable secret expiration date should never become an outage, and now it doesn't have to. Standing up new parts of the business quickly Multi-Tenancy and Automated Provisioning integration Earlier this year we released Multi-Tenancy and Automated Provisioning, hosted by 1Password, two critical features for admins to manage provisioning, deprovisioning, and parent/child accounts at scale. Now admins can use these features in tandem, so enterprises with multi-tenant setups can take advantage of Automated Provisioning. To get started, check out our detailed documentation for setting up the Multi-Tenancy and Automated Provisioning integration To get started, check out our detailed documentation for setting up the M

## What makes a good AI coworker? With OpenAI's Codex product lead

DevFeed: [What makes a good AI coworker? With OpenAI's Codex product lead](<https://devfeed.tech/articles/what-makes-a-good-ai-coworker-with-openai-s-codex-product-lead-1897.md>)

Original publisher: [Read original article](<https://1password.com/blog/ai-agents-as-coworkers>)

Author: info@1password.com (Chris Fowler)

Published: 2026-08-25T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [codex](<https://devfeed.tech/topics/codex.md>), [OpenAI](<https://devfeed.tech/topics/openai.md>), [long-context](<https://devfeed.tech/topics/long-context.md>), [Filesystems](<https://devfeed.tech/topics/filesystems.md>), [coding](<https://devfeed.tech/topics/coding.md>), [cursor](<https://devfeed.tech/topics/cursor.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [agentic](<https://devfeed.tech/tags/agentic.md>), [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-coding](<https://devfeed.tech/tags/ai-coding.md>), [autonomous](<https://devfeed.tech/tags/autonomous.md>), [codex](<https://devfeed.tech/tags/codex.md>), [context-window](<https://devfeed.tech/tags/context-window.md>), [cursor](<https://devfeed.tech/tags/cursor.md>), [dev](<https://devfeed.tech/tags/dev.md>), [developers](<https://devfeed.tech/tags/developers.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [filesystems](<https://devfeed.tech/tags/filesystems.md>), [memory](<https://devfeed.tech/tags/memory.md>), [openai](<https://devfeed.tech/tags/openai.md>), [podcast](<https://devfeed.tech/tags/podcast.md>), [podcasts](<https://devfeed.tech/tags/podcasts.md>)

### AI overview

An episode featuring OpenAI Codex product lead Rohan Varma explores what makes AI agents effective coworkers. It focuses on shared context, durable memory and state outside the context window, filesystem-based task continuity, and steerability so people can understand and guide agent output.

### Source excerpt

Zero-Shot Learning is a podcast about how AI is built, secured, and deployed. Hosted by Nancy Wang, 1Password CTO, and Dev Tagare, Senior Director of Engineering at Google Gemini, it offers a builder's view of the architecture and complex decisions involved in shipping AI. In this episode, Rohan Varma, Product Lead for Codex at OpenAI, described what happens when teams move from using agents for one-off tasks to enabling autonomous coworkers. Having worked on AI coding products at Cursor and OpenAI, Ro understands what people need to work effectively with agents and what agents need to work effectively with people. What makes a good (agentic) coworker? With any coworker, collaboration works best when everyone is working from the same context, toward a shared goal. Human coworkers are accustomed to working toward shared goals. With proper context and resources, they can divide work without losing sight of how their contribution affects the team. The difference between teams of people and agents is that people don't need to be told how to remember things. Everything they do carries historical context. When a team works together, their shared knowledge expands exponentially. Agents work within context windows, a temporary working memory that fills as a task continues. When the window is full, the system has to summarize the work without losing decisions and constraints that could cause the agent to miss crucial directives. State is a fundamental building block for making an agent feel more like a coworker. Without memory, every time you prompt an agent, it's kind of like its first day on planet Earth." -Rohan Varma, Codex Product Lead, OpenAI To be a useful long-term collaborator, an agent's memory has to exist outside its context window. The system has to preserve the work durably to understand which files were changed, which decisions were made, which results were gathered, and which tasks are yet to be completed. That shared state lets one agent resume a task, anoth

## 451 Research report: How agentic AI is redefining identity security

DevFeed: [451 Research report: How agentic AI is redefining identity security](<https://devfeed.tech/articles/451-research-report-how-agentic-ai-is-redefining-identity-security-1927.md>)

Original publisher: [Read original article](<https://1password.com/blog/how-agentic-ai-is-redefining-identity-security>)

Author: info@1password.com (1Password)

Published: 2026-08-20T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Security](<https://devfeed.tech/topics/security.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>)

Tags: [agentic-ai](<https://devfeed.tech/tags/agentic-ai.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [developers](<https://devfeed.tech/tags/developers.md>), [identity](<https://devfeed.tech/tags/identity.md>), [news](<https://devfeed.tech/tags/news.md>), [security](<https://devfeed.tech/tags/security.md>), [unified-access](<https://devfeed.tech/tags/unified-access.md>)

### AI overview

A 1Password article summarizes a 451 Research report on how agentic AI is changing enterprise identity and access security. It highlights the need to discover AI agents and non-human identities, deliver credentials just in time, guide developer remediation, and provide auditable attribution for actions.

### Source excerpt

In the short time that AI agents have been a part of the enterprise, they have upended many of our bedrock assumptions about the nature of identity, access, development, and work itself. At 1Password, we've been in the trenches of the agentic revolution; we've seen its positive impact on productivity, and the serious concerns it raises about security. We've worked to build solutions that both harness AI's potential and rein in its risks, and watched customers and colleagues grapple with the same issues. In order to better understand how the industry at large is facing the agentic moment, 1Password commissioned a Vanguard Report from 451 Research, titled A new access model for the agentic enterprise. The report describes how agentic AI is redefining access and identity, and lays out what C-level leaders can do to ensure a smooth transition to this new paradigm. Its core recommendations include: Start with discovery and visibility of AI agents and poorly governed non-human identities (NHIs). Move to just-in-time credential delivery, rather than static credentials and standing privileges. Implement guided remediation for developers so they can address NHI and agentic risk without interrupting their workflows. Ensure full auditability and clear attribution that ties every action to a specific human or agent identity and authorization context. Read on to explore the report's findings, or download the full report here. An expanding identity perimeter, with agents already inside A new access model for the agentic enterprise begins by establishing that agentic AI is already deeply embedded in the enterprise. 69% of enterprises they surveyed have deployed AI agents, and 90% plan to do so within the next two years (these findings align with 1Password's own research on agentic adoption). But while agents became ubiquitous almost overnight, the tools and strategies to secure them have not kept pace. This on its own isn't unusual; the report reminds readers that this "pattern ha

## Advisory Solutions reaches 1Password Certified Partner status

DevFeed: [Advisory Solutions reaches 1Password Certified Partner status](<https://devfeed.tech/articles/advisory-solutions-reaches-1password-certified-partner-status-1890.md>)

Original publisher: [Read original article](<https://1password.com/blog/advisory-solutions-reaches-certified-partner-status>)

Author: info@1password.com (Rachel Sudbeck)

Published: 2026-08-17T00:00:00Z

Content type: news

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [passwords](<https://devfeed.tech/topics/passwords.md>)

Tags: [business](<https://devfeed.tech/tags/business.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [enablement](<https://devfeed.tech/tags/enablement.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [partners](<https://devfeed.tech/tags/partners.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Advisory Solutions reached Certified Tier status in the 1Password Partner program after scaling its 1Password deployment to more than 1,000 managed users.

### Source excerpt

The launch of 1Password Enterprise Password Manager - MSP Edition marked a critical step in 1Password's mission to support our Managed Service Provider (MSP) partnerships. Now, we are pleased to announce that Advisory Solutions, a New York City-based MSP that works with companies worldwide, has reached the Certified Tier in the 1Password Partner program. 1Password's new Certified tier is a milestone we've implemented to recognize the investment and success of MSP partners who have reached 1,000 or more managed external users. Advisory Solutions was able to become a Certified Partner by rapidly scaling its 1Password deployment to more than 1,000 managed users. This not only represents their dedication as a partner, but demonstrates that the Certified tier is an achievable milestone for MSPs committed to growing their 1Password practice. We're excited to see companies like Advisory Solutions further the momentum behind 1Password's MSP program and embrace the value of participating in it. The journey to Certified Partner for 1Password MSPs What does it take for an MSP to work their way up from Authorized to the Certified Tier? Jay Chaudhrey, Director of Business Development at Advisory Solutions, shares some of the key principles that Advisory Solutions followed to operationalize 1Password and become a Certified Partner so rapidly. Authorized and Certified Partners 1Password's MSP Partner Program now consists of two tiers: Authorized and Certified. Like every MSP in 1Password's program, Advisory Solutions began as an Authorized Partner, establishing the operational foundation that ultimately led to the becoming a Certified Partner. At the Authorized Tier, partners gain immediate benefits, including specialized pricing NFR licenses for internal use, and enablement resources. For Advisory Solutions, "It was really important for us to work with the best companies in their respective fields." That's how they found 1Password. When it comes to finding the "best" tools, Chaud

## Developer secrets management that keeps delivery moving

DevFeed: [Developer secrets management that keeps delivery moving](<https://devfeed.tech/articles/developer-secrets-management-that-keeps-delivery-moving-1915.md>)

Original publisher: [Read original article](<https://1password.com/blog/developer-secrets-management-that-keeps-delivery-moving>)

Author: info@1password.com (Robert Imeson)

Published: 2026-08-17T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [API keys](<https://devfeed.tech/topics/api-keys.md>), [Software Engineering](<https://devfeed.tech/topics/software-engineering.md>), [OpenSSH](<https://devfeed.tech/topics/openssh.md>), [Database](<https://devfeed.tech/topics/database.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [api-keys](<https://devfeed.tech/tags/api-keys.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [code](<https://devfeed.tech/tags/code.md>), [developer](<https://devfeed.tech/tags/developer.md>), [developers](<https://devfeed.tech/tags/developers.md>), [development](<https://devfeed.tech/tags/development.md>), [github](<https://devfeed.tech/tags/github.md>), [incident](<https://devfeed.tech/tags/incident.md>), [logs](<https://devfeed.tech/tags/logs.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [software](<https://devfeed.tech/tags/software.md>), [software-development](<https://devfeed.tech/tags/software-development.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [tokens](<https://devfeed.tech/tags/tokens.md>), [unified-access](<https://devfeed.tech/tags/unified-access.md>)

### AI overview

The article examines how unmanaged developer credentials--such as API keys, cloud credentials, SSH keys, and tokens--can remain outside approved security controls. It argues that secrets management must reduce workflow friction and address credentials at the point where developers create and use them, while enabling rotation, revocation, auditing, and reporting.

### Source excerpt

In March 2025, attackers compromised a GitHub Action used in the development pipelines of more than 23,000 repositories. The malicious code exposed API keys, cloud credentials, SSH keys, and other tokens in workflow logs. Affected teams were advised to review their workflow runs and rotate any credentials the logs exposed. Affected organizations had to determine which credentials had been exposed, what those credentials could reach, and how to replace every one of them without halting development. Many could not confidently answer the first question alone. The incident illustrates the problem those responsible for a team's credentials face today: the credentials that carry the most risk are often the ones nobody is tracking. Security tools cannot govern credentials they never see Unmanaged credentials are simply a byproduct of the modern software development environment, where developers are under pressure to constantly ship code. A developer standing up an application needs a database password or an API key immediately, and the fastest way to supply one is a .env file on the local machine, an SSH key in a home directory, or a token pasted into a pipeline variable. Each choice keeps work moving, and each one creates a working credential that exists outside any approved system, where no one responsible for keeping projects, credentials, and access safe can rotate, revoke, or audit it. Traditional secrets management can leave this gap open because it starts on the wrong side of it. Conventional tools provide a secure destination but depend on developers to bring credentials to it, so governance begins only after migration. When a security process adds friction, teams find workarounds. 1Password's research found that 43% of developers don't use a dedicated secrets manager or vault at all, managing secrets through a mix of secure and unsecure means instead. As a result, credentials remain outside the controls, reporting, and rotation processes intended to protect them.

## No robots in the gym, with Keith Hoodlet

DevFeed: [No robots in the gym, with Keith Hoodlet](<https://devfeed.tech/articles/no-robots-in-the-gym-with-keith-hoodlet-1943.md>)

Original publisher: [Read original article](<https://1password.com/blog/no-robots-in-the-gym>)

Author: info@1password.com (Dave Lewis)

Published: 2026-08-14T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Computer science](<https://devfeed.tech/topics/computer-science.md>), [Visual Basic](<https://devfeed.tech/topics/visual-basic.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [blog](<https://devfeed.tech/tags/blog.md>), [career](<https://devfeed.tech/tags/career.md>), [github](<https://devfeed.tech/tags/github.md>), [leadership](<https://devfeed.tech/tags/leadership.md>), [podcast](<https://devfeed.tech/tags/podcast.md>), [podcasts](<https://devfeed.tech/tags/podcasts.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>), [spoof](<https://devfeed.tech/tags/spoof.md>)

### AI overview

An article about Keith Hoodlet's nonlinear path into security research, his work at 1Password and Off-by-1 Labs, and lessons from his experience in psychology, computer science, leadership, and AI bias research.

### Source excerpt

Listen to the episode on Apple Podcasts null Listen now Listen to this episode on Spotify null Listen now This week on the Chasing Entropy Podcast, host Dave Lewis sits down with Keith Hoodlet, Director of Security Research at 1Password and leader of the newly formed Off-by-1 Labs. Keith's mission? "To throw stones at glass houses, not to hear the crash necessarily, but to help people build better and more secure houses." A villain-turned-hero origin story As Keith puts it, "I've always been really focused on skill acquisition over formal titling or formalized skillsets in many ways." After all, he got his start as a self-proclaimed "unpaid punk on the internet, messing with video games, mostly." As a teen, Keith would spoof other Diablo players by using a trial key from the back of a CD case, and taught himself Visual Basic so he could spam StarCraft opponents. He realized early on that he was "pretty good at the whole computer thing." That's why he decided to major in psychology - it was something he couldn't do. He wanted to understand people better. Graduating in the midst of the housing market crash had him working odd jobs for several years. He returned to school for computer science, only to drop out when he received a job offer. From there, he built his career gradually through roles at Bugcrowd, Thermo Fisher Scientific, GitHub, Trail of Bits, and now 1Password. It may have been a nonlinear career path, but there have been plenty of highlights throughout that journey, including winning the U.S. Department of Defense's 2024 bias bounty program; it was one of the first times an organization paid external researchers to prove an AI system was biased and unfit for its intended use. Keith continues to make use of the varied skills he built over those years. For instance, his psychology background may not show up in threat models, but it shows up daily in his leadership: "I start from a place of approaching the other party that I'm interacting with as first a hum

## Cognition's Jeff Wang on demoting the IDE, with Richard Liu from Anthropic

DevFeed: [Cognition's Jeff Wang on demoting the IDE, with Richard Liu from Anthropic](<https://devfeed.tech/articles/cognition-s-jeff-wang-on-demoting-the-ide-with-richard-liu-from-anthropic-1913.md>)

Original publisher: [Read original article](<https://1password.com/blog/demoting-the-ide>)

Author: info@1password.com (Chris Fowler)

Published: 2026-08-13T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [AI-assisted coding](<https://devfeed.tech/topics/ai-assisted-coding.md>), [developer tooling](<https://devfeed.tech/topics/developer-tooling.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-coding](<https://devfeed.tech/tags/ai-coding.md>), [developers](<https://devfeed.tech/tags/developers.md>), [ide](<https://devfeed.tech/tags/ide.md>), [podcasts](<https://devfeed.tech/tags/podcasts.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

A podcast episode examines how AI coding agents shift software work from manual coding toward delegating, verifying, and unblocking agent tasks.

### Source excerpt

How AI coding agents are changing software development Zero-Shot Learning is a podcast about how AI gets built, secured, and deployed. Hosted by Nancy Wang, 1Password CTO, and Dev Tagare, Senior Director of Engineering at Google, it's a builder's view of the architecture and the complex decisions it takes to ship with AI. This episode features guest co-host Richard Liu, Head of API Products at Anthropic, who sits in for Dev. The IDE has been the center of software development for decades, but Jeff Wang thinks its time in the spotlight is ending. On Zero-Shot Learning, the President of New Enterprise at Cognition described how his team's workflows are shifting from manually writing every change to delegating work and verifying the results of AI coding agents. After leading Windsurf and now working with Devin at Cognition, Jeff has seen developers across industries explore how to implement AI. From interactively collaborating with coding agents to deploying long-running agents in the cloud, he has seen what agents change inside the editor and what they require outside of it. If the question is what's the most effective way to ship, Jeff isn't betting on the IDE. Offloading undesirable work to AI coding agents For Jeff's team, AI coding agents prove useful for the work no one volunteers for. Agents respond to event-triggered tasks like reproducing bugs, remediating vulnerabilities, and repairing CI failures, where they effectively reduce noise that distracts developers from planned work. "If you go into any engineering organization, you don't want to take away the things they want to do," Jeff says. "You want to take away the things people don't want to do. You ask everybody in the development team, 'Hey, who wants to replicate this bug?' Nobody is going to raise their hand." He says these agents now account for roughly 40% of the workload at Cognition. Cognition also works with enterprise customers using Devin. At some large banks, Jeff says, Devin automatically fixes

## Verified loops: Building AI agent trust and accountability

DevFeed: [Verified loops: Building AI agent trust and accountability](<https://devfeed.tech/articles/verified-loops-building-ai-agent-trust-and-accountability-1968.md>)

Original publisher: [Read original article](<https://1password.com/blog/verified-loops-building-ai-agent-trust>)

Author: info@1password.com (Nancy Wang)

Published: 2026-08-11T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [AI Bots](<https://devfeed.tech/topics/ai-bots.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-agent](<https://devfeed.tech/tags/ai-agent.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [developers](<https://devfeed.tech/tags/developers.md>), [identity](<https://devfeed.tech/tags/identity.md>), [policy](<https://devfeed.tech/tags/policy.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article presents verified loops as a way to give AI agents bounded authority and require system-generated evidence before granting an action capability.

### Source excerpt

AI agents have crossed an important line from making suggestions to taking actions. They can read a repository, call internal systems, change code, open a pull request, and keep working while the human moves on. In this world, it is no longer enough to ask whether a model is capable. We have to ask: Who is acting, a person or their agent? What authority did they receive? Which systems could they reach? What evidence did the run produce? What permission should that evidence earn? And who remains accountable for the next consequential action? At 1Password, the pattern we use to answer these questions is the verified loop. In a verified loop, an agent works under a job-specific identity, through tools governed by an access control gateway, and earns a given permission by proving that it satisfies the conditions of a human-defined policy. This is how an organization can begin converting human-owned procedures into production tasks for agents. A verified loop doesn't make the agent infallible, but it clearly defines the agent's task and authority, and makes incomplete or unsupported work harder to pass off as finished. A plausible result is not the same as a verified result Consider an agent asked to draft release notes for a release containing 1,247 commits. The draft is clearly written and looks complete. Every change in the agent's input appears to be accounted for. But the comparison API returned only its first 1,000 commits, and the agent had no way to know that 247 were missing. The problem in this workflow is that there's no process that identifies that this plausible-looking result is, in fact, incomplete. A tool inventory could tell us that the agent used the repository API, and scoped authorization could prove that it could read the repository but not publish. Neither tells us whether it received the full commit range or traced each claim to an approved source. That is what verification adds, by evaluating the run against the job that was actually specified. Au

## 1Password's back-to-school tips for the digital world

DevFeed: [1Password's back-to-school tips for the digital world](<https://devfeed.tech/articles/1password-s-back-to-school-tips-for-the-digital-world-1922.md>)

Original publisher: [Read original article](<https://1password.com/blog/getting-started-students-and-families>)

Author: info@1password.com (1Password)

Published: 2026-08-11T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [passwords](<https://devfeed.tech/topics/passwords.md>), [Security](<https://devfeed.tech/topics/security.md>), [Digital Security](<https://devfeed.tech/topics/digital-security.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Claude](<https://devfeed.tech/topics/claude.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [blog](<https://devfeed.tech/tags/blog.md>), [claude](<https://devfeed.tech/tags/claude.md>), [digital-security](<https://devfeed.tech/tags/digital-security.md>), [guide](<https://devfeed.tech/tags/guide.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [security](<https://devfeed.tech/tags/security.md>), [tips-advice](<https://devfeed.tech/tags/tips-advice.md>)

### AI overview

1Password's back-to-school guide offers parents and students practical advice for staying secure and organized in the digital world. It focuses on evaluating AI tools, protecting personal information and passwords, avoiding phishing and password reuse, and building safer online habits.

### Source excerpt

It happened again. We blinked, and suddenly summer's over and it's time to register for classes. The horror! While the start of a new school year has always been a stressful time for parents and students, the growing number of accounts, apps, and devices students have been responsible for in recent years has made it even more complicated. To help manage the stress, 1Password is sharing our favorite back-to-school security tips for parents and students of all ages, so you can start the 2026 school year secure and organized. School security 101: From AI to user IDs With more AI tools emerging every day, it can be difficult to track which ones are trustworthy. AI tools and agents need access to a lot of data in order to function; AI adopters, and concerned parents, should take care about what data is being shared with the AI. It's worth learning what AI-based tools your kids are using, and educating them about what kinds of information they should never share with a chatbot. That includes sensitive personal information, but it also includes things like passwords, which no AI user should paste directly into a chat window just because a helpful-seeming agent asked for them. Tools like 1Password for Claude offer a safe way for the AI power users in your family to experiment with agents. For any parents, whether your kids are entering elementary school or going off to college for the first time, they can benefit from a talk about AI tools and online safety. You don't have to scare your kids away from technology, nor should you try to control everything they do online. Instead, set them up for success with knowledge and preparation. 💡Heading to college or university? Check out our blog, A college student's guide to better digital security. Make strong passwords a habit now Despite the perception that young people today are tech-savvy, that doesn't mean they're secure. With apps for school, home, and socializing, the average student is creating more accounts than they can po

## Evolving AI maturity for our user experience team

DevFeed: [Evolving AI maturity for our user experience team](<https://devfeed.tech/articles/evolving-ai-maturity-for-our-user-experience-team-1917.md>)

Original publisher: [Read original article](<https://1password.com/blog/evolving-ai-maturity-for-our-user-experience-team>)

Author: info@1password.com (Matt Davey)

Published: 2026-08-07T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [AI Chat](<https://devfeed.tech/topics/ai-chat.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [building-1password](<https://devfeed.tech/tags/building-1password.md>), [community](<https://devfeed.tech/tags/community.md>), [design](<https://devfeed.tech/tags/design.md>), [experimentation](<https://devfeed.tech/tags/experimentation.md>), [prototypes](<https://devfeed.tech/tags/prototypes.md>), [user-experience](<https://devfeed.tech/tags/user-experience.md>), [workflow](<https://devfeed.tech/tags/workflow.md>)

### AI overview

The article presents an AI maturity model for user experience teams, arguing that mature adoption improves decisions, collaboration, and product experiences rather than merely accelerating work.

### Source excerpt

AI is changing how products get made. For user experience teams, that means the very shape of the work is changing. There are two key elements of user experience design. On one side is craft: the interaction, nuance, visual judgement, emotional texture, and other qualities that make a product feel considered. On the other side are systems, strategy and behavioural thinking: journeys, concepts, mental models, product architecture, behavioural patterns, and the shared systems and languages that help teams make better products. AI tooling has created opportunities to deepen both of these skillsets. Designers can now get closer to the front-end experience using real components, real data, and realistic prototypes, instead of hoping that important details survive the process. At the same time, we now have more ability to work upstream, shaping product decisions at the strategy level. Now, rather than strategy and execution conflicting with each other, they can harmonize more closely, held together by a team that can think clearly and ship responsibly. The challenge of AI is that working faster simply produces more work; it doesn't always mean that work is better. For UX and design teams, AI maturity is not simply about whether a team uses AI, but whether it improves the quality of our decisions, our collaboration, and the experiences we ship. An AI maturity model for user experience teams In the early stages of adoption, AI use tends to be experimentation without much structure. A designer might use it to generate a few rough ideas or make an impressive prototype, but it falls apart when the team asks how it would actually work. To avoid the pitfalls of confusing AI enthusiasm with maturity, 1Password has been investing in AI fluency across the company. To make that progress visible and chart a path to impact, we have developed a simple maturity model for design teams, which charts AI use from limited, reactive, developing, embedded, and finally through to leading. Head

## Remove standing access before AI agents exploit it

DevFeed: [Remove standing access before AI agents exploit it](<https://devfeed.tech/articles/remove-standing-access-before-ai-agents-exploit-it-1950.md>)

Original publisher: [Read original article](<https://1password.com/blog/remove-standing-access-before-ai-agents-exploit-it>)

Author: info@1password.com (Sanjay Ramnath)

Published: 2026-08-06T00:00:00Z

Content type: opinion

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [API keys](<https://devfeed.tech/topics/api-keys.md>), [OAuth](<https://devfeed.tech/topics/oauth.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [incident](<https://devfeed.tech/topics/incident.md>), [coding](<https://devfeed.tech/topics/coding.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [api-keys](<https://devfeed.tech/tags/api-keys.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [exploits](<https://devfeed.tech/tags/exploits.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [oauth](<https://devfeed.tech/tags/oauth.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [unified-access](<https://devfeed.tech/tags/unified-access.md>)

### AI overview

The article argues that AI-driven autonomous systems can rapidly discover and exploit standing credentials after gaining access to enterprise environments. It recommends removing unnecessary access, vaulting plaintext secrets, and reducing the blast radius of credential-based attacks.

### Source excerpt

AI has changed the calculus of a credential attack. Before, finding and exploiting credentials in an enterprise environment required time, patience, and human judgment. An attacker had to decide which accounts were worth testing and which systems were worth reaching. Many credentials never made the list. By contrast, an autonomous system that gains a foothold in a victim's systems has no need to be picky. It can sweep an environment in moments, scooping up API keys, service account tokens, OAuth tokens, cloud credentials, and plaintext secrets on developer devices. It authenticates with whatever it finds and moves laterally as far as standing access allows, one credential opening the next, at machine speed. An attacker with AI doesn't need to choose targets. Everything accessible is worth exploiting. Recent high-profile incidents with experimental AI models have shown that pattern in action. Entry points differed: software exploits in two cases, weak passwords in a third. But what followed was the same in each incident: automated systems swept for whatever credentials the environment offered and moved as far as standing access would carry them. In one documented case, that meant more than 17,000 recorded attacker events over a single weekend. These stories are just early indicators of what defenders will soon be facing as these experimental models become commonly available services. As autonomous systems become more capable and more widely deployed, credential sweeps after breaches will become faster, more thorough, and harder to detect. Any enterprise running AI workloads, AI coding tools, or developer workflows on shared infrastructure has accumulated the same kind of exposure that made these headline-grabbing attacks successful: service accounts whose permissions grew beyond their original purpose, API keys that were never rotated, and secrets left in plaintext on developer devices because they were easier to use that way. In the face of what is coming, strengthe

## How to survive the AI spend hangover

DevFeed: [How to survive the AI spend hangover](<https://devfeed.tech/articles/how-to-survive-the-ai-spend-hangover-1930.md>)

Original publisher: [Read original article](<https://1password.com/blog/how-to-survive-the-ai-spend-hangover>)

Author: info@1password.com (Jason Meller)

Published: 2026-08-06T00:00:00Z

Content type: opinion

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [AI, ML & Data Engineering](<https://devfeed.tech/topics/ai-ml-data-engineering.md>), [AI-assisted coding](<https://devfeed.tech/topics/ai-assisted-coding.md>)

Tags: [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [business](<https://devfeed.tech/tags/business.md>), [coding](<https://devfeed.tech/tags/coding.md>), [developers](<https://devfeed.tech/tags/developers.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [llms](<https://devfeed.tech/tags/llms.md>), [saas-management](<https://devfeed.tech/tags/saas-management.md>)

### AI overview

The article argues that organizations need to control and measure AI and LLM spending, connecting token use to projects and return on investment. It also cautions that coding agents still require knowledgeable human direction and expert review.

### Source excerpt

It's 6:30am and you hear the door of the nightclub you've spent the last 8 hours inside shriek as it closes behind you. You watch bleary-eyed as an overly bright sunrise illuminates the business-suited people as they glide effortlessly along the sidewalk, their obnoxiously well-rested faces talking about work on their fully charged phones. You wonder, "Where did all the fun people go? And what happened to my wallet?" This feeling is what many CFOs, CTOs, CEOs, and AI program managers will imminently be experiencing in their board rooms, as they finally wake up to the realities that unrestricted and unmoderated AI use has wrought on their bottom lines and the stability of their core technical assets. You can already feel the party ending and the hangover setting in. The first warning sign came when Uber's engineering org burned through its annual AI budget by April, and then capped its engineers at $1,500 a month per tool. At Meta, an internal leaderboard nicknamed "Claudeonomics" turned token spend into a status game. The company was on pace to spend billions, and the CTO's eventual memo had to spell out that token usage on its own measures nothing. Two of the most sophisticated engineering organizations on the planet have arrived a half step ahead of where we will all be soon: facing down a shocking bill and scrambling to tie it to any real ROI. Worse, many organizations would be hard pressed even to say which teams spent their tokens, on which models, and on what projects. Tokens spent wisely on complex problems, and tokens burned writing personalized fanfic all look the same on an invoice. But untangling them just became an urgent priority for everyone who shares responsibility for their company's AI bill. Like any hangover, this one is going to hurt. But we don't have to wait for the club to close down to start sobering up. There are already lessons to be learned about the differences between the companies using AI responsibly and the ones that have just been pa

## Off-by-1 Labs: Why AI-generated vulnerability patches still require expert human review

DevFeed: [Off-by-1 Labs: Why AI-generated vulnerability patches still require expert human review](<https://devfeed.tech/articles/off-by-1-labs-why-ai-generated-vulnerability-patches-still-require-expert-human-review-1974.md>)

Original publisher: [Read original article](<https://1password.com/blog/why-ai-generated-patches-still-require-human-review>)

Author: info@1password.com (Keith Hoodlet)

Published: 2026-08-06T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [Large Language Model](<https://devfeed.tech/topics/llm.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [LLM evaluation / benchmarking](<https://devfeed.tech/topics/llm-evaluation-benchmarking.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [datasets](<https://devfeed.tech/topics/datasets.md>)

Tags: [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [data](<https://devfeed.tech/tags/data.md>), [developers](<https://devfeed.tech/tags/developers.md>), [large-language-models-llms](<https://devfeed.tech/tags/large-language-models-llms.md>), [openai](<https://devfeed.tech/tags/openai.md>), [research](<https://devfeed.tech/tags/research.md>), [review](<https://devfeed.tech/tags/review.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

A 1Password security research study finds that large language models generated vulnerability patches with embedded defects 53.9% of the time across 6,080 patches for six recently disclosed CVEs. Only 26.0% fully resolved the vulnerability without materially changing application behavior, supporting the need for expert human review.

### Source excerpt

We studied what happens when Large Language Models (LLMs) generate vulnerability patches for recently disclosed, complex vulnerabilities. Our data shows that LLMs produce Fix-Like Artifacts with Embedded Defects (FLAWED) 53.9% of the time when complex patches are required. By sharing the results of our research, our goal is to provide defenders with the tooling and methodology necessary to improve vulnerability remediation outcomes at scale. Along with this blog, we are releasing our tooling, datasets, and an in-depth research paper to share what we've learned. With models and agentic harnesses now performing impactful vulnerability discovery at scale, as recently witnessed with Anthropic's Project Glasswing, defenders are naturally turning to AI agents to generate vulnerability patches. Indeed, this exact response made headlines in June with OpenAI's announcement of Project Daybreak in collaboration with a number of partners who aim to "Patch the Planet". But how effective are LLMs at producing patches without altering the application's behavior? Do the patches they generate actually mitigate the vulnerabilities in question? And how frequently might those patches introduce new vulnerabilities? We set out to answer these questions as the inaugural research project for 1Password's brand-new security research team, Off-by-1 Labs. The paper's title is Frontier Models' Vulnerability Patches are Often F.L.A.W.E.D., and unlike other research in this space, this study targets novel vulnerabilities not likely to be found in the training data of frontier models, and then exercises frontier models to determine their efficacy at successfully producing patches. Across six recently-disclosed CVEs, we produced 6,080 patches using two frontier, cyber-capable reasoning models. The average success rate for generating a patch that fully resolved the vulnerability (without materially changing application behavior) was just 26.0%. Patches that successfully resolved the vulnerability, b

## Productiv shutdown: Switch to 1Password for durable AI and SaaS Management

DevFeed: [Productiv shutdown: Switch to 1Password for durable AI and SaaS Management](<https://devfeed.tech/articles/productiv-shutdown-switch-to-1password-for-durable-ai-and-saas-management-1947.md>)

Original publisher: [Read original article](<https://1password.com/blog/productiv-shutdown-switch-to-1password-for-durable-ai-and-saas-management>)

Author: info@1password.com (Evan Sandhu)

Published: 2026-08-05T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [SaaS Management](<https://devfeed.tech/topics/saas-management.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [shadow AI](<https://devfeed.tech/topics/shadow-ai.md>), [Unified Access](<https://devfeed.tech/topics/unified-access.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Single sign-on (SSO)](<https://devfeed.tech/topics/sso.md>), [Extension](<https://devfeed.tech/topics/extension.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [automation](<https://devfeed.tech/tags/automation.md>), [browser](<https://devfeed.tech/tags/browser.md>), [extensions](<https://devfeed.tech/tags/extensions.md>), [policy](<https://devfeed.tech/tags/policy.md>), [saas](<https://devfeed.tech/tags/saas.md>), [saas-management](<https://devfeed.tech/tags/saas-management.md>), [shadow-ai](<https://devfeed.tech/tags/shadow-ai.md>), [unified-access](<https://devfeed.tech/tags/unified-access.md>)

### AI overview

Productiv is shutting down its SaaS management platform, prompting customers to move app inventory, spend, and usage data. The article presents 1Password SaaS Manager as an alternative with AI spend and consumption tracking, SaaS discovery beyond SSO, access governance, and lifecycle automation.

### Source excerpt

On August 2, 2026, Productiv told customers its SaaS management platform was shutting down on August 6, with account data deleted once access ended. Four days is not much time to pull years of app inventory, spend, and usage data out of a system you've come to depend on, especially with AI tools now adding a fast-moving new layer of spend and access to track on top of everything else. If you're facing that deadline, or just taking stock of what you'd do if your own platform disappeared tomorrow, here's why 1Password SaaS Manager is the strongest place to land. A Leader you can build on 1Password SaaS Manager is a Leader in the 2026 Gartner® Magic Quadrant™ for SaaS Management Platforms, for both Completeness of Vision and Ability to Execute. That recognition reflects work we've been doing deliberately since acquiring Trelica in 2025. We've brought AI and SaaS discovery into our broader Unified Access platform, alongside the credentials, identities, and access controls that secure every application in a portfolio. Built for how AI and SaaS actually get used today We recently launched AI Spend and Consumption Management inside SaaS Manager, giving IT and finance teams a normalized view of AI token usage by vendor, team, and model, with burn-rate alerts before prepaid budgets run out. AI is quickly becoming the least governed, fastest-growing corner of the software portfolio, and we built that governance directly into SaaS Manager rather than bolting it on as a separate tool. It's one of several capabilities that set SaaS Manager apart: Discovery that goes beyond SSO: SaaS Manager continuously discovers apps across identity providers, SSO logs, finance systems, browser extensions, and 1Password Enterprise Password Manager vaults, surfacing the unmanaged SaaS and shadow AI tools that SSO-only discovery misses. Governance you can act on: Discovery is anchored to credentials and sign-ins, so IT can revoke access and enforce strong authentication even for apps outside SSO,

## How CFOs can manage AI costs and prove business value

DevFeed: [How CFOs can manage AI costs and prove business value](<https://devfeed.tech/articles/how-cfos-can-manage-ai-costs-and-prove-business-value-1928.md>)

Original publisher: [Read original article](<https://1password.com/blog/how-cfos-manage-ai-costs>)

Author: info@1password.com (Greg Henry)

Published: 2026-08-04T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [AI Strategy](<https://devfeed.tech/topics/ai-strategy.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [dashboards](<https://devfeed.tech/topics/dashboards.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-adoption](<https://devfeed.tech/tags/ai-adoption.md>), [billing](<https://devfeed.tech/tags/billing.md>), [business](<https://devfeed.tech/tags/business.md>), [business-value](<https://devfeed.tech/tags/business-value.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [dashboards](<https://devfeed.tech/tags/dashboards.md>), [finance](<https://devfeed.tech/tags/finance.md>), [management](<https://devfeed.tech/tags/management.md>), [real-time](<https://devfeed.tech/tags/real-time.md>), [saas-management](<https://devfeed.tech/tags/saas-management.md>)

### AI overview

The article explains how CFOs and Finance teams can manage unpredictable AI spending by gaining earlier visibility into usage, forecasting budget risk, assigning ownership, and connecting AI investments to measurable business outcomes. It highlights consumption-based pricing, changing model costs, and delayed reporting from IT and vendor dashboards as key challenges.

### Source excerpt

Earlier this year, a bill arrived from one of 1Password's AI vendors for 5x the value of the original contract. The initial agreement came in below a certain threshold, so it never reached the right approvers for review. By the time it did, we had a much clearer understanding of how quickly AI costs can add up. This unpleasant surprise revealed a structural gap between IT, Finance, and end users when it came to AI billing and consumption. Although Finance was accountable for the budget, it had no way to see what was being spent on AI until it was already spent. Other CFOs are seeing the same pattern of a bill arriving that no one can explain. Now, as leaders grapple with soaring and unpredictable token costs, what was considered a budget line item just a few months ago has become a board-level topic. Managing AI costs requires Finance and IT to share visibility into consumption before the invoice arrives. Organizations need a way to track usage, forecast budget risk, assign ownership, and connect AI investments to measurable business outcomes. Why AI costs are harder for Finance to forecast Effective Finance and IT are built on predictability: per-seat SaaS contracts, annual budget cycles, and predictable renewal dates. Contracts with AI vendors are fundamentally different. They're based on consumption pricing, which scales with usage, not headcount. As AI usage grows across a team or department, the bill can literally grow overnight. The closest comparison is cloud, which also uses consumption pricing. Cloud sprawl took years to bring under control, but Finance eventually learned to model it. With AI, there is no time for a learning curve. Pricing tiers change constantly, new models ship overnight, and AI adoption continues to accelerate. Why Finance sees AI overspend too late While Finance is responsible for AI spend management, the tools Finance relies on weren't designed to provide real-time visibility. Getting a complete picture requires going through the IT te

## Temporal CTO: A 20-year shortcut to build reliable agents

DevFeed: [Temporal CTO: A 20-year shortcut to build reliable agents](<https://devfeed.tech/articles/temporal-cto-a-20-year-shortcut-to-build-reliable-agents-1907.md>)

Original publisher: [Read original article](<https://1password.com/blog/build-reliable-agents>)

Author: info@1password.com (Chris Fowler)

Published: 2026-08-04T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [distributed-systems](<https://devfeed.tech/topics/distributed-systems.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [Processes](<https://devfeed.tech/topics/processes.md>), [Orchestration](<https://devfeed.tech/topics/orchestration.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [architecture](<https://devfeed.tech/tags/architecture.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [developers](<https://devfeed.tech/tags/developers.md>), [distributed-systems](<https://devfeed.tech/tags/distributed-systems.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [llm](<https://devfeed.tech/tags/llm.md>), [podcasts](<https://devfeed.tech/tags/podcasts.md>)

### AI overview

The article explains why long-running agentic systems encounter familiar distributed-systems failures, especially state loss and retry storms. It presents durable execution, flow control, queues, and rate limiting as mechanisms for making agents recoverable and resilient in production.

### Source excerpt

Zero-Shot Learning is a podcast about how AI gets built, secured, and deployed. Hosted by Nancy Wang, 1Password CTO, and Dev Tagare, Senior Director of Engineering at Google, it's a builder's view of the architecture and the complex decisions it takes to ship with AI. In this episode, 1Password VP, GM of Developer and AI, Jeff Malnick sits in for Dev. When Maxim Fateev, CTO and co-founder of Temporal, joined Zero-Shot Learning, he brought a historical perspective to the challenges developers face when building agentic systems today. From vanishing state to retry storms, Fateev saw that the failures of deploying long-running agents have parallels to the problems he's been working on for decades. Maxim joined Amazon in 2002, where he co-created Simple Workflow Service, the internal orchestration platform that became one of the most widely used services at Amazon. At Uber, he built Cadence, the open-source predecessor to Temporal, the durable execution platform, which he co-founded in 2019. Temporal now runs production workloads for OpenAI, GitLab, Lovable, Docker, and Cloudflare, and has more than 2,500 customers globally. As the industry builds agentic systems, Fateev is watching it rediscover exactly what his infrastructure was built to solve. A brief history of failures Agents become distributed systems the moment they cross a network. Every call to an LLM, every tool invocation, every write to a downstream service crosses a process boundary, and a process boundary is where distributed systems failures begin. Two common ways agents fail in production are state loss and retry storms. While working, an agent builds state, e.g. a record of which tools it called, the results it received, and how far it progressed in a task. When the process crashes, that record is gone. There is no checkpoint to resume from, no record of what was completed, no way to distinguish completed work from incomplete work. The next run starts from scratch, leaving the operator unsure which act

## The 1Password Environments MCP Server is now on Cursor Marketplace

DevFeed: [The 1Password Environments MCP Server is now on Cursor Marketplace](<https://devfeed.tech/articles/the-1password-environments-mcp-server-is-now-on-cursor-marketplace-1963.md>)

Original publisher: [Read original article](<https://1password.com/blog/the-1password-environments-mcp-server-is-now-on-cursor-marketplace>)

Author: info@1password.com (Dennis Kromhout van der Meer and Scott Lougheed)

Published: 2026-07-30T00:00:00Z

Content type: release

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [cursor](<https://devfeed.tech/topics/cursor.md>), [AI-assisted coding](<https://devfeed.tech/topics/ai-assisted-coding.md>), [AI Bots](<https://devfeed.tech/topics/ai-bots.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-agent](<https://devfeed.tech/tags/ai-agent.md>), [ai-coding](<https://devfeed.tech/tags/ai-coding.md>), [api-keys](<https://devfeed.tech/tags/api-keys.md>), [cursor](<https://devfeed.tech/tags/cursor.md>), [developers](<https://devfeed.tech/tags/developers.md>), [mcp](<https://devfeed.tech/tags/mcp.md>), [mcp-server](<https://devfeed.tech/tags/mcp-server.md>), [news](<https://devfeed.tech/tags/news.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

1Password announces that its Environments MCP Server is available through the Cursor Marketplace. The article focuses on using the integration to help AI coding agents access developer secrets more securely when working with production APIs and infrastructure.

### Source excerpt

AI agents are doing more than just generating code. Increasingly, they are working autonomously on complex coding challenges, touching production APIs, databases, and infrastructure across development environments, often without thorough human review. To perform these operations and access multiple systems, agents rely on developer secrets and non-human identities (NHI). But often, developers lack a secure way to share these secrets, leading to overprivileged, invisible access. The growth in autonomous agentic workflows changes what secure credential management needs to look like. The problem posed by hardcoded secrets is not new. Developers have managed API keys in .env files, tokens committed to repos, and credentials sitting in plain text across codebases for decades. The conventional response has typically been reactive: rotate after an incident, clean up after a review, catch secrets when you find them. That approach was built for workflows where a human reviews each step, but the model breaks when agents are involved. When an AI agent runs code containing a hardcoded credential, that credential can pass through an AI agent's context window and be logged, cached, or forwarded downstream, making tracking and governance extremely difficult. The potential security impact of a plaintext secret expands disproportionately once an agent accesses it. Expanding into Cursor Marketplace Cursor is a multi-modal AI coding platform helping developers and engineering teams build software across complex codebases. Cursor allows developers to use an agent for complex coding tasks involving production APIs, services, and infrastructure. 1Password Environments MCP Server is designed so developers can take advantage of this increased velocity without compromising on security. The existing 1Password plugin on Cursor Marketplace now makes 1Password Environments capabilities, inclusive of the MCP Server, available directly through Cursor. This is the same MCP server available to deve

## Scaling security reviews at 1Password: Solving the context and nondeterminism problems

DevFeed: [Scaling security reviews at 1Password: Solving the context and nondeterminism problems](<https://devfeed.tech/articles/scaling-security-reviews-at-1password-solving-the-context-and-nondeterminism-problems-1954.md>)

Original publisher: [Read original article](<https://1password.com/blog/scaling-security-reviews-solving-context-and-nondeterminism>)

Author: info@1password.com (Megan Barker)

Published: 2026-07-30T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Code review](<https://devfeed.tech/topics/code-review.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [long-context](<https://devfeed.tech/topics/long-context.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Python](<https://devfeed.tech/topics/python.md>), [Go Language](<https://devfeed.tech/topics/go-language.md>), [pull-requests](<https://devfeed.tech/topics/pull-requests.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [building-1password](<https://devfeed.tech/tags/building-1password.md>), [code](<https://devfeed.tech/tags/code.md>), [context-window](<https://devfeed.tech/tags/context-window.md>), [developers](<https://devfeed.tech/tags/developers.md>), [github](<https://devfeed.tech/tags/github.md>), [go](<https://devfeed.tech/tags/go.md>), [llm](<https://devfeed.tech/tags/llm.md>), [nondeterminism](<https://devfeed.tech/tags/nondeterminism.md>), [python](<https://devfeed.tech/tags/python.md>), [review](<https://devfeed.tech/tags/review.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

1Password describes how it evolved SAGE to scale security code reviews across large repositories. The v2 design addresses limited LLM context and nondeterministic outputs by generating directory-level scaffolding that compresses structural security context, with a Python proof of concept being productionized in Go.

### Source excerpt

In our last post, we shared how we began to scale our security code review process with SAGE. We discussed how we gathered historical Product Security (ProdSec) review records to create a 1Password-specific ruleset, the three-stage Finder/Critic/Judge pipeline, and the limitations of our v1 implementation. Above all, human ProdSec reviewers still had to bring full context to the findings: where the trust boundaries lie, which directories are sensitive, and whether mitigations exist elsewhere in the codebase. Our goal for v2 was to help SAGE understand our entire codebase. Many of our GitHub repositories are huge, including our client and server monorepos. That means we have way too much information to fit within any LLM's context window. We had to find a way to let SAGE perform deeper reasoning about the PR diffs it reviews without the codebase itself. There was another hurdle. As we built v2, we ran into a fundamental LLM trait: they can't reliably produce the same output twice. We knew we had to do our best to manage this nondeterminism so we could trust SAGE to be a relatively consistent security reviewer. We had two things to figure out: how to fit a lot of data into a context window, and how to get consistent output from inherently inconsistent tools. If we could solve those riddles, SAGE wouldn't just know 1Password, it would finally understand it. And it would earn the name SuperSAGE. Compressing context with scaffolding As it turns out, our Security Research team had already developed a Python proof of concept designed to compress our code context. It was a set of LLM prompts that generated one SCAFFOLDING.md file per source directory. Those scaffolding files carried compressed structural context like sensitivity ratings, attack surfaces, trust boundaries, and file summaries. It was a great foundation; we just had to productionize it as a Go rewrite on top of SAGE v1's model-agnostic llm.Client harness. To start, the PoC took inventory of our code structure.

[Next page](<https://devfeed.tech/sources/blog-on-1password-blog.md?cursor=WyIyMDI2LTA3LTMwVDAwOjAwOjAwKzAwOjAwIiwgIjEzYWNmZjRmLWU5MmUtNDcxYS1hMzRmLWEyM2JjMWMzYzQwZiJd>)