Anyone can save credentials in 1Password for accounts they have access to. Therefore, we need a unified system for naming and organizing those credentials.We have used several systems and titling strategies in the past and have never had a chance to consolidate. So you will notice as you use the system that this strategy is not consistently applied. Any time you are digging through 1pass and notice an opportunity to fix a login that’s not in the right format, do it! And please enforce these standards with all new logins.
When you join Cantilever, HR (Chris) will send you an invite to our 1password account. Your manager will send access to any relevant vaults you need for your projects. If you have not been oriented and set up by the time you’re reading this, contact HR.
Your 1password master password must be very, very strong. Keep in mind that clients entrust us with crucial business information, and we should take that very seriously.
As a part of your orientation, you should have downloaded/printed a 1password "emergency kit" which contains secret keys you can use to recover your data in case you forget your password.The vault can be located at: cantilever.1password.com
More likely, you will want to use the 1password app on your computer and phone. You can log in there with the same credentials you use online.
Any credentials associated with a single client should go in the client’s vault. If you are working with a client which does not yet have a vault, please ask Legal to make one.
Any credentials you need for work, but should NOT be shared with the full team (such as your Cantilever email credentials) should go in your personal 1pass vault in the Cantilever account.Any credentials you need in general which are not private and could benefit the full team should go in the Cantilever "Shared" vault.
Do not store any Cantilever data outside of the Cantilever vault. This is important for legal reasons, but also for safety. If your computer burns to a crisp, we need to know our data is still available to anyone in the company who needs it.
All vaults should be named by client, not project.
Names should be capitalized except in special cases like "eBeam". Slashes should be used without any spaces between them.
Credentials appear in list format in the 1Password app, website, and quick access Chrome extension. So they must be named in a way that makes sense for each of those venues.Some sites may have multiple credentials assigned to them. So, it is important to list the client name in the credential name. Additionally, some clients have multiple projects, so we may need to redundantly identify logins associated with their main projects.
The general format is:
[Account Owner] Account Description]
- In other words:"[Who] What"
- Or, in other-other words:"[Owner] Thing"
- Or, if you prefer a more drawn-out des:"[Person/Company logging in] Thing they are logging in to"Note that Person/Company means person or company.
So, if Cantilever is the 'account owner' of a password for a particular client, the naming might go as follows:
- [Cantilever] Droga5 Imgix
The specific person is not important unless there are multiple accounts associated with a given service, in which case it would be:
- [Andrew] Droga5 Imgix
- [Ty] Droga5 Imgix
For any given password, the default owners are generally Cantilever or the client.Using Droga5 as an example, other naming conventions might look like:
- [Droga5] WordfenceThis is an account and service that the client uses, but we have access to.
There is no need for the bracket notation for anything other than logins. Anything that is NOT a login (like a PDF, credit card, or note) should not use the login syntax ("[Owner] Thing").
Notes & Docs
Notes are only visible in the 1pass app or web interface, not the widget, so we can be more relaxed about their naming conventions.
(From the Esquire vault):
What account is this? If you’re using the chrome extension, or don’t know the mailchimp monkey, you couldn’t tell in advance.This should be [Esquire] Mailchimp.(From the Kode with Klossy vault)
This should be [KWK Blog] Cantilever WP(from the TWC Vault)
This should be [Watson Advertising] WP Admin