BookNovi keeps no vault of passwords. A business's passwords, its bank's, its suppliers', its carriers', its Wi-Fi's and its social accounts', live in 1Password, which is built for exactly that: everything in it is encrypted end to end, so not even 1Password can read it, and every look at an item is recorded. What BookNovi keeps is where each password is: a login on the record it belongs to, with the 1Password item's private link and who on the team should know it exists. If BookNovi were ever broken into, there would be no password in it to take.
Logins on your records
A login can be kept on the business itself, a location (its alarm, its Wi-Fi), a vendor (its portal, its ordering site), a room or piece of equipment, a carrier account or a freight carrier. A location's, a vendor's and a carrier's own screens have a Logins panel: Admin, Locations, open a location; Inventory, Purchasing, Vendors, open a vendor; Shipping, Setup, Logins beside a carrier account or a freight carrier. Admin, Passwords lists every login you may see, on every record, with a search: type wifi, ups or bank.
Each login says its name, what kind of item it is (a login, a Wi-Fi network, a bank account, an API key, a secure note), what it is for, and who sees it. Open in 1Password opens the item in the 1Password app or website, and 1Password decides whether you may see it: its private link opens only for someone who already has that vault. A login on a room or a piece of equipment is added from Admin, Passwords for now.
Add a login
- In 1Password, open the item and choose Copy Private Link.
- In BookNovi, choose Add a login on the record, or under Admin, Passwords.
- Give it the item's name, paste the link, and say what it is for if that helps.
- Tick who sees that it exists, and choose Add the login.
A share link (one from 1Password's Share) is refused: it opens the item itself for whoever has the link. So is anything that looks like a password, a code or a key, in any box, and a link with a name or a password in it. BookNovi says where it belongs instead: in 1Password.
Who sees a login
Owners see every login. Anyone else sees the ones shared with their place on the team (admins, managers, the front desk, staff), while their Passwords switch is on: an owner turns it off for one person under Settings, Logins. Adding, changing and removing logins takes Add and change logins too, which admins and managers start with. Someone who is not an owner keeps their own place among who sees a login they change, since a login they cannot see they cannot change; an owner can keep one to the owners alone.
Seeing that a login exists is not seeing the password. 1Password still decides who opens the item, by its vault.
Connect your 1Password
With the business's 1Password connected, whoever adds a login picks the item from a list instead of pasting its link. BookNovi reads the names and kinds of the items in the vaults you choose, and nothing else: never a password, never what is in an item, never a share link. Only an owner connects it.
- In 1Password, open Developer, Service Accounts, and choose New Service Account.
- Give it read access to only the vaults whose items your team should link: a vault of shared logins, say, and not your personal one.
- Copy its token, which starts with ops_.
- Open any item in one of those vaults and choose Copy Private Link.
- In BookNovi, open Admin, Apps, then 1Password, paste the token and the link, and choose Check and connect.
BookNovi lists the vaults with the token before it keeps it, sealed; it is never shown again. The link tells BookNovi which 1Password account the items are in, so it can make each picked item's private link. To stop, choose Disconnect in Apps, then delete the service account in 1Password.
1Password activity in Compliance
With 1Password Business, an owner can connect its Events API as 1Password activity under Admin, Apps: in 1Password, open Integrations, Events Reporting, add one for BookNovi with item usage and sign-in attempts, and paste its token with where your account is (1password.com, ent.1password.com, 1password.ca or 1password.eu). Admin, Compliance, Access Review then shows who opened, filled or copied each shared item over the last week, and every attempt to sign in to your 1Password with how it went, beside the review of who can sign in to BookNovi.
Ask the assistant
Ask the assistant, by text or by voice, "What's the Wi-Fi password?" and it answers with where it is: "It is in 1Password under “Studio Wi-Fi”; open it there," with the link to open. It finds only the logins you see, with your Passwords switch on, and there is never a password for it to say, because BookNovi has none.
Best practices
- Keep shared logins in a shared vault of their own in 1Password, and give the service account that vault alone.
- Name a login as its 1Password item is named, so a search in either finds it.
- Share a login with the fewest places on the team that need it; the bank's and the payroll's can stay with the owners.
- Remove a login when its item is gone from 1Password, and remove the person from the vault in 1Password the day they leave.
- With 1Password Business, connect its activity and read it with each quarter's access review.