How 1Password Extended Access Management is Securing the Future of Work
1Password is the leader in Extended Access Management, a new category of security that addresses the gaps in access management created by app, identity, and device sprawl. Our platform is composed of three products: our Enterprise Password Manager, Trelica by 1Password, and 1Password Device Trust. In this presentation, Jason Meller and Leya Leydiker explain the Access-Trust Gap facing modern organizations, and explore how our password manager acts as the foundation for our suite of solutions. This “Access-Trust Gap” is defined as the combination of unmanaged devices, shadow IT applications, and sprawling identities that fall outside the purview of traditional security tools like Identity Providers (IDPs) and Mobile Device Management (MDM). Because 1Password is used to store credentials that these other systems don’t cover (like API keys), the company has unique visibility into this growing problem. Their Extended Access Management platform aims to close this gap by providing unified visibility and complete control. The presentation demonstrated this by showing how 1Password Device Trust could detect an unencrypted SSH key on a developer’s laptop, block access to a sensitive app like GitHub, and then seamlessly guide the user to secure that key within their 1Password vault, thereby fixing the issue and training the user simultaneously.
The foundation of this strategy is 1Password’s Enterprise Password Manager (EPM), which secures every step of the user journey, not just the initial login. The platform’s success is rooted in its user-first design philosophy, which stems from its origins as a consumer application. This focus on making the secure way the easy way drives user adoption and reduces friction, which in turn minimizes help desk tickets for things like password resets. The EPM handles not only passwords but also API keys, SSH keys, passkeys, and one-time passcodes (OTPs), allowing it to serve as a single, secure vault for all types of credentials. This capability enables secure sharing among teams, such as a social media team sharing a single login with MFA. Crucially, all of this is built on a “zero knowledge” security model, meaning user data is encrypted locally on their device, and 1Password itself cannot access it, ensuring credentials remain secure even in the event of a breach.
Presented by Jason Meller, VP, Product Architecture, and Leya Leydiker, Senior Director, Product Management. Recorded live at Security Field Day 14 in Silicon Valley on September 25, 2025. Watch the entire presentation at https://techfieldday.com/appearance/1password-presents-at-security-field-day-14/ or visit https://techfieldday.com/event/xfd14/ or https://1password.com/extended-access-management for more information.
Transcript
I'm Jason Miller, VP of Product Architecture at One Password. We have a really fun presentation that we're gonna take you through today. We have a bunch of live demos, a bunch of prepared things to show you, and really the goal of today is to talk to you about our aspirations to be more than just a password manager.
Really quickly, I'm just curious how many folks have used one password, either for personal or business and not surprising? Uh, all, basically all the hands went up. So we're not gonna spend a lot of time today talking about what a password manager is.
This is a security field day and what we're gonna talk a little bit more about is how we're going to e effectively extend beyond what a password manager is to solve some really gnarly problems. So while you've all heard or used of one password, you may not know that one Password's been around for quite a while. This chart is obviously not to scale jumps from 2005 all the way to 2018.
But back in those days, we were just a humble Mac OS app that was just trying its best to, to solve, uh, a basic problem, which is we have all these passwords, what do we do with them? How do we make them secure? And we only did it for Mac jump ahead all the way to 2018.
That was when we decided, you know what, maybe businesses could use this and maybe we can make the process of actually storing those credentials in the cloud a lot easier. From there, we really became a fast growing SaaS startup and uh, we've grown tremendously since then. You know, really landing at 165,000 B2B customers, millions of users across both consumer and business.
And we are the number one password manager. And because of this, we have all of this incredible visibility along the way. We've actually acquired a number of companies.
For example, I actually came to One Password by way of an acquisition. I was the founder and CEO of a device trust company called The Collide, which we'll talk about a little bit more. We've, uh, also acquired a company called trca, which does app governance and SaaS management.
And, uh, we continue to invest pretty heavily in some of the use cases that go far beyond password management. So part of this presentation is gonna be kind of walking you through our vision for the future and then showing you some glimpses in the form of demos and, and, uh, some additional information that will give you some insight into where we're taking things. So really quickly, if you only think about one password as a password manager, um, it's only because password management is one of the most interesting problems to solve in this human-centric model that we like to approach.
So when we think about solving security issues at one password, we always start with the user first and the human being. And one password's always been a company that starts with how do we make this incredibly complicated concept something that my mom can actually use, and then can we pivot from there to bring all that goodness to a business or an enterprise and solve a problem at scale? This is where why we have the trusted reputation that we have.
This is why we have over 4 million consumers using our solution today. And as I mentioned earlier, 165,000 businesses. Alright?
So one of the benefits that you get when you are a password management company is you actually get visibility into problems that not many people know exist. So over the last 10 years, we've seen the outcome of the ification of business and we've seen what has happened as companies have, you know, reacted to COVID gone remote and bought solutions like iams and IDPs and SSO providers. And what we have seen is we get to be sort of this spillover of all the things that those solutions don't fully solve.
And that spillover includes this concept of application sprawl where there is all the shadow IT and shadow SaaS applications that are out there that really isn't under control. There's no visibility, there's no management, there's device sprawl where folks are actually leveraging personal and unaccounted for devices to access these sensitive applications. And now we have this growing problem of identity sprawl even before the advent of Ag agentic AI and AI based identities.
You had that third party contract that just kind of got that side door into your SaaS application or you do a big m and a and then suddenly you have a federation problem. You know what's funny about one password is we're sort of this bucket that had to absorb a lot of this stuff. If you buy an SSO provider, what do you do with your API keys that use access to those same apps?
Well, guess what? They go into a solution like one password. And this is what has given us this visibility into this problem.
So we've named this problem and we call it the access trust gap. It's really important to name problems by the way, because you have to re-explain it over and over again. You sort of lose the momentum.
And we felt that this problem was so important that it deserved a name. And the way that we define the access trust gap is the combination of the unmanaged devices, applications, and identities and their intersection in the authentication space. What I mean by that is you have what is known, you have your managed devices, you have your trusted applications, you have the identities that are in your IDP, these are in the known managed area.
But just like on a university campus, when you have these nice paved paths, you have those desire paths that kind of go off the road. And it's this, these desire paths that represent the user's desire to be productive and work outside of the bounds of that golden path that the security nights team has paid for them. It is the summation of all of this stuff, which is growing by the way that represents this gap that we want to help enumerate and effectively close.
And we're gonna be talking a little bit more about the access trust gap a little bit later. So the reason we created Extended Access Management was to directly address the access trust gap. And it is our objective to go from effectively this before picture, which is represented by most organizations.
They are in this state effectively. And to create a model of unified visibility, really complete control of act across sign-ins, apps, and devices, and make it as easy to use as possible and not have to actually sacrifice the productivity. And the shortest way of saying is on the sign that's next to me is secure every sign-in to every app from every device.
This sounds like something that every vendor is already offering today, but the truth is there's an asterisk, there's an exception. You can't do it for everything. And that's what we wanna solve.
We wanna solve the really hard problems that we have the visibility into. I think that's why we might be the first ones on the scene to solve it is because of that unique visibility that we have across 165,000 businesses. So just as a high level framework, this is sort of our Bento box sort of based perspective on extended access management.
And there's a lot of acronyms here, but I wanna just talk about some of the three pillars that we see as part of the scope of this offering. So what you'll see on the top there is you'll have what's typical solution sets for managing the problems across identities, applications, and devices, right? You wanna manage devices, you get an MDM, oh, you know, application access and governance.
I get an IGA solution identities, oh that's an IDP and we'll throw a little SSO on top of that problem solve, right, wrong, right? And we know that because our whole business exists because SSO and IDP doesn't fully solve the identity and access problem. Application governance is what we call now Tika by one Password is effectively our ability to enumerate that shadow SAS and IT problem Device Trust takes a fact-based approach to actually looking at what's really going on in the device and not just simply assume that a managed device is a secure device.
The idea that you could just throw an MDM on there and then wipe your hands of the device management problem is, is not correct. There are so many things that can go wrong and it is our goal with Extended Access Manage to solve all these problems holistically while bringing our unique perspective on user experience and productivity. So we actually make it fun and easier to get your work done and to access these applications.
So this is a little backup video in case, uh, I didn't wanna do my live demo, but this is field day, so we're gonna do a live demo. So let me kind of set it up because part of the goal of these all these investments that we've made is we wanna solve real problems that we see. So part of the problem that we see most folks struggle with with one password is this, the simple lack that they don't actually use it, right?
I can't tell you how many companies we talk to that decide, I love using one password for my home, for my family, I wanna roll it out to everybody. And so they buy licenses for the entire company, but one password doesn't work if you actually don't use it. And so what's really fascinating about the intersection of device and applications to identity is that we can start creating opportunities to induce users know where they have this Access trust gap, enumerate it, and then get them to use that and understand the tools that are available, including one password itself.
So what we're gonna talk about really quickly is a demo where we do this for a developer persona. Developers have all sorts of plain text credentials littered all throughout their laptops. I have a feeling if I looked at a couple laptops here, I'd be able to find a a few nice things.
And, uh, one of the worst is SSH keys. If you've never, uh, done development before, SSH Keys is as good as a username and password together, you present it to a server and if it's not encrypted, you just get in and without that encrypted pass key on top of it, anybody who gets that file can access that SSH server. It's effectively giving, it's a key to any kingdom that has that, that other SSH key on the public key side on, on the actual server itself.
So what we're gonna show very quickly is a demonstration of how not only do we detect this, but we induce end users to use one password to mitigate this part of the access trust gap. So what we're looking at right now is, uh, the administrative console for one Password Device Trust, also known as Collide. It was the original name of the, the product when it was acquired.
Um, and we're looking at a number of registered devices that are running the one password, uh, device agent. This agent is able to detect a number of different compliance signals across, uh, a myriad of of operating systems, windows and Mac, of course Linux, which is, uh, surprisingly effective. There's a ton of developers that that use Linux now and, uh, across all the different, you know, uh, distributions and and flavors.
And then of course, uh, iOS and Android, which we have, uh, uh, a specific app for to get those signals across to us. So if I look up my device right now, we could see a number of, of, of, of information about this, about this device. We could see that it's online right now, and then we could see a number of issues that it has.
And I could see that I have an unencrypted SSH key on my device. Uh, the way that this works under the hood is that the agent is able to look for known locations where SSH Keys reside and it's actually able to enumerate and detect whether or not they have any encryption on them at all. It'll also do SSH key discovery by looking at the local SSH agent that you use to register keys against.
So basically if this key is useful and it's in a folder that commonly holds SSH keys, not only we're gonna be able to find it, but we'll be able to numerate all the high level properties about it and we'll be able to even do things like Detective two devices are sharing the same underlying SSH key, which is really cool because you don't want people sharing stuff like that across multiple devices unless there's some intentional reason to do so. So checks are great and it's great that we have that detection, but how do we put it to use? So I'm gonna go to this failing check really quickly and I'll actually go to its configuration which will pop up over on the right here, minimize the zoom thing.
And you'll see that every check comes with what's called a remediation strategy. So what's cool about device trust is when your users fail a check, we can tell them about it and we can offer a consequence that prevents them from doing something dangerous related to this idea. So this remediation strategy, if I could click configure here right now, it's set to block immediately.
And this effectively means the moment that I am failing this check on my device, I'm no longer able to authenticate or use any applications that are protected by Device Trust. But there's more if you wanna warn than block or notify only. There's way more gentler ways of introducing the fact that they will eventually be blocked.
For the purposes of this demo, we're just gonna go all in and, and start with the block 'cause it's easiest to look at. Now, really important is we don't just tell people that they're blocked and say sorry, you know, call a help desk, right? This is the number one reason anything related to zero trust ends up failing is you become afraid of even leaving your own office.
You don't know how the signals are all gonna come together and then suddenly you're locked out and you don't even know why. We always tell you why. And not only do we tell you why, we give you the opportunity to fix it, and this is where we give you the opportunity to, to enhance that capability with your own custom instructions.
And you can even tell people why you're asking them to fix it. Why is this important? Convey the underlying rationale for the policy's existence.
So this isn't just an opportunity to get your users to fix something and to protect your most critical resources. It's an opportunity to train them on why a specific policy exists, scope to just the people that actually need to hear it. This is incredibly po this is incredibly powerful in way more effective than just giving someone a big PowerPoint training when they start working at the company.
This is specific customized instructions to things that your users are actively getting wrong right now with an avenue to fix it and with consequences that are going to be implemented if they don't. So are these, are those aligned to controls that we might have in place? Or are they defaults that you have?
This is my favorite part because this is one of the most customizable pieces of the solution. So under the hood in the agent, we use an open source project called OS Query, which was created by Meta slash Facebook about 10 years ago. And what's great about OS Query is it allows you to write in a custom language your own checks that effectively allow you to build almost anything that you could imagine.
So if I go here and I go to the ad you checks, uh, section, you can see we have a catalog of, of hundreds of checks here that we sort of pre-baked in. But if you want to build your own, we give you these templates. If you don't know how to write the OS, query SQL yourself for very common use cases.
So if you wanna prohibit like a specific browser extension or you wanna make, verify the presence of an app and make sure it's at a minimum version or one of my favorites is find potentially sensitive files on, on the system itself. This is great for a use case. For example, let's say you have a customer support staff and as part of their job they often interact with information that users sent them, like log files and things like that.
Well, you can use this to detect that those log files have been lingering on their computer for too long and then ask them to delete it or else we're not gonna let them log into the support system anymore. So it's really up to you, it's basically limited by your imagination. And even if these templates aren't enough, uh, there's over 250 virtual tables that you use to write your own queries on top of that really cover every aspect of the computer from the process model to the networking model to the applications are installed.
You can almost write anything that you want and turn it into a check with remediation instructions. So the, um, that's pretty awesome. The, the, the instruction instructions in particular.
Um, can they reference our, can we write them and tell them what they need To say? Or are they Oh yeah. Okay.
Oh yeah, it's really great. So I'll, I'll go a little bit off the rails here, sorry. And, uh, no, it's, it's fine.
Um, so let's say for example, we want to verify the presence of a required browser extension. And of course you wanna make sure one password's on there. So we'll put that in there really quickly, create a new draft.
So what's cool about this is this gives you, this is the rule that effectively you're writing, but if you go to the notification text, this will give you an opportunity to write your own fixed instruction. So you can link to your own documents If you have an MDM that has scripts in it, you can also create buttons and other things and links in here so that if you want to have this self remediation, just be like, click this link and then Jamf pops up and kind of auto remediates it for you. That's also an option.
And you can see everything that you're writing and you have variables and you can reference things that are part of the failure. So if you want to talk about the specific browser that this isn't installed on, you can reference that variable and it's actually really powerful. It's sort of like the pride and joy of this whole thing.
So I just showed you us making the check blocking. One of the other things that we have the ability to do is we have a little bit of a like discovery here and we can choose which applications we want to enable this capability on. For example, I see that there are folks that are using GitHub, uh, we'll talk about this a little bit more later, but we can tell that folks are using GitHub within the organization, uh, by reading all of this discovery information.
And so we can see things like how frequently they're browsing to specific, uh, GitHub websites, desktop apps, OAuth grants. And this gives us confidence that GitHub is an application that's used and I can set it to an accepted app, uh, which shows that this is an app that we want to kind of keep track of a little bit more. I enable something called extended device compliance on it.
This is what enables that end user remediation experience. And so what we'll do now is we're gonna, I'm gonna take off my admin hat and we're gonna look at this through the lens of a new user that's trying to sign up me. com and you can see right away it's blocking me from actually getting access to GitHub.
It's telling me exactly why and I need to fix this issue before I get into GitHub. So I'm gonna click into that and that's gonna take me to the customized remediation instructions that we've set. And what's cool about this is that we have an if statement in here and we know if they have one password installed, we can get this done in one click.
So I'm gonna click this link here. It's gonna instantly open up one password with the path already pre-populated to import this SSH key. I'm gonna click save.
It's gonna now ask me to delete this SSH key from disc 'cause we don't need it anymore. 'cause now it's safe and secure in one password and I can click, I fix, I've fixed it. Recheck now.
And this is actually running a live query using the agent. One more time. You can see that I'm all good and if you go back here, I'm ready to use GitHub and think about just what happened.
We just got an end user to fix a very nuanced issue by getting them to understand a policy before they used an app that's related to that policy that was a GitHub SSH key, now safe and secure in one password, an app that they now are able to use and we are now at 'em on the path of reducing the access trust gap. Pretty cool, huh? I like it.
I have a question for you. Yes. So my business relationship managers meet with my agencies on a monthly basis.
I suppose I wanted to give a monthly or quarterly report to say your people are in compliant X number, your people have had y number of incidents. Can I do a summary of this? I love it on an individual a little bit.
Can I summarize it by unit division agency? Yes, absolutely. We have a great reporting tool.
This um, it gives you custom, uh, reporting SQL queries that you could write and we also roll it up as well by check, like you said by ou, things like that. And we import all that information from your IDP. Nice.
And not only can we use the one password extension to do that enforcement, you can also integrate into your existing, uh, IDP or SSO. So if you want to gate this at the Okta level, for instance, we can be part of that MFA flow so that in order for you to actually sign in, you need to pass the device trust checks as well. So if you don't wanna have the one password extension be part of this, you could also do it through saml, which is really, really cool.
Building on Wolfgang's question about, um, reporting, does it integrate with continuous compliance platforms like DTA or Vanta or Dell? Yeah, that's a good point. Yeah, we actually have, uh, two bespoke integrations or Vanta and specifically it'll import all of the device compliance signals.
And we will also be able to contribute data to vta. 'cause there's extraneous data that we collect that's just these big lists like here's all your Chrome extensions, here's all your apps. They can use that raw list to also perform their own calculations without you needing to deploy to Vota agent as well, which is really neat.
My name is Le Ledr and I head product management for our EPM Password Manager product that I'll be telling you about. It's our flagship product that many of you have already seen. And this is, uh, many of you may already be familiar with our EPM product, as Jason said.
One more time for me, show of hands, if you've used one password before. Thank you. And, um, many of our business customers actually started out as consumer customers first, and then they brought the one password into their organization.
And that is because it's built for how the work actually gets done across tools, across people, and across devices. And these are devices that oftentimes your identity provider can't reach themselves. And it really marries that bridge between security and productivity, which is really what we're trying to do here and what Jason was demonstrating with some of those compliance checks as well.
But we don't just stop at the login screen, we help you secure everything that happens after that login screen as well. So where the credentials live and how they're shared and who's actually using them. And so with our enterprise password manager, we really start in three main focus areas.
The first is, uh, that where we, where you can see and secure every credential. And by credential of course we mean username and password, but we also mean from every browser and shadow scripts. And, um, it really stops them from floating around in, in Slack in your notes app or post-it notes.
Has anyone done this? No, not that we'd admit. Not that you admit.
And, uh, we really help build that habit of turning secure access into just general practice. And once this starts happening with the end users, our admins are able to craft policies and help identify some of those risky behaviors and really start making the, what we call the make the secure way the easy way. And as we're doing this, we still need to be able to make sure that we check all those compliance boxes at the end of the year.
So we got some good questions about, um, are things, do we have robust audit logging can do we integrate with SIM tools? And the answer is yes, absolutely, because all of us need to check those compliance requirements requirement acronyms at the end of the year, and we need to be able to do so seamlessly and easily. So when password helps you do that, and so really it's about being with the customer on every step of the journey depending on where they are.
So for some of our smaller customers who are just starting out, they might just want to start saving some credentials and getting the users to use a password manager period. Or they might be a little bit more robust in their journey and now they're the administrators are starting to craft policies or identifying some risks. And finally they might be a super user who says, I just wanna plug all this into my SIM tool and start making decisioning.
And one password is with you every single step of the way along that journey. But what truly sets one password apart is actually what's underneath the hood. And uh, this is where we can say something that many of our competitors cannot say, which is, we can't see your data.
It's true we can't. And this is because of our, uh, two secret key derivation model with the password and the secret key, which means that the data is encrypted locally on your device and we can't see it. So in the event that there were to be a breach, because I would never, ever, ever tell a room of security professionals that we will n never be breached, that is a death sentence.
But in the event that there were to be a breach, um, the attackers wouldn't actually be able to see the credentials and they would walk away with nothing. So this is what truly sets us apart from, uh, from our competition. Um, and this is what we call zero knowledge security or zero trust security really in, in form here.
Um, but now there's something new that's coming in addition to just the way that we secure that and that is how we are going to secure AI agents. It's something that Anand will be talking about a bit later in the presentation. And um, as we're all thinking about how we're doing that, we need to understand how um, some of these API tokens and SSH keys are going to be encrypted and centrally stored, that the access is controlled by a team or a script and that things are still auditable in the same way that your credentials are as well.
So the same way that we're applying our thought process around security credentials, we're applying that model through secrets automation and how we're planning to secure AI agents, which Anod will walk you through as well. So this is where it's really important to understand that password manager, password management is really just the start and some of the things that Jason was showing you on how we're building the access trust gap and really closing that with our extended device compliance and extended access management is how we're going beyond what folks already know about one password with credential management and how we're planning on really becoming a more broad security tool that can help protect the applications and the devices and the AI agents beyond the credentials themselves. So now we've established why you might need a password manager, but none of this actually does anything unless the end users are actually using the password manager.
And this is where many of the security tools fall apart because they're built originally for the administrators and they're not built with the end user in mind. But we all know that when a security tool is built without the end user in mind, what happens, use it. I don't use it, you don't use it or you go around it.
I have never done that. I will not, I've 100% done that. Um, but this is where it's important to note that one password didn't actually start out as this enterprise tool, but it started out as the consumer tool that has been used and loved by, um, millions of customers as we, and we've grown up through that.
So everything that we've done, we've done through the lens of the end user and every additional company that we've, uh, acquired or product that we've built has been done in that same lens of what's in it for the end user first and how can we ensure that things are done seamless and easily for that end user so that the administrator can focus on, on securing the users and doing their job. And so some of the ways that we have helped some of our enterprise customers is in the reduction of help desk tickets or, um, password resets as well. So again, this is about making sure that the secure way is the productive way and that those two things are in concert with each other and not in conflict with each other, but there's even more that sets us apart, what we talked about a bit.
And uh, this is where Jason started talking a little bit about the developer. And for our enterprise password manager, the developer is one of our, um, early adopters in the space. And the reason is because they're doing all kinds of crazy things with their SSH keys that you saw Jason demonstrate and finding cha he challenged that he, he might find some crazy keys lying around somewhere.
And, um, the truth is that every minute that the developer is spending not actually coding and looking up those keys or firing up their terminal is um, a minute that they're losing the productivity and the opportunity to build. So we introduced something that's relatively simple but also really helpful, which is the SSH bookmarking. And this allows our developers to, um, connect to the hosts in a simpler way.
Uh, it significantly reduces the number of clicks for the developers so that they're able to just get right into the terminal and get to get into what they need. And they know that their credentials are saved securely in one password with the same level of credential management that they're already accustomed to. And this helps avoid server key limitations that often slow the developers down and instead of running into errors, they can just go ahead and contracts seamlessly.
So again, marrying that security and productivity so there's fewer manual stops, fewer mistakes, and they can focus on building all the cool stuff that we like to see, uh, in the world. Any question? Quick question for you.
Yeah. Is there a difference between the enterprise version and the consumer version? So what I'm asking is, um, I don't have an enterprise version, I have the personal, you know, I buy it for my family.
I have lots of SSJ so I wanna understand like, where is this available? Is this just in the enterprise version of the, of, of the software or do your regular consumers get this as well? If, uh, you, your regular consumers can absolutely get this.
Okay. There's a, in a, in a teams account and also for every enterprise, uh, customer, if you were getting it with your business, then uh, we provision you a free family account as well. So that's a huge benefit as well.
And that helps to build that habit because we know, um, you know, here in a room of security professionals, many of you are already using a password manager and we know that, um, for many folks who are not, it's a new habit that they have to build and once they build it, it's, it becomes second nature and you're not even thinking about it. But they have to get over that hump. So that's why we give everybody a free family account so that they can continue to do that.
A good question for you, please. So obviously roots and password management, but also obviously, uh, passwords are not the only thing, right? We've got a multifactor, we've got passwordless.
Uh, are you able to store and share OTP in this? So could I use this as my second factor? Yes, absolutely.
So there you can scan the, the OTP directly, uh, into the password manager. So it becomes your one stop shop there. You can save your pass keys, you can share, you can save, uh, all different kinds of credentials directly in the, in one password as well.
Secure documents, uh, for personal use, you can create, um, different profiles for family members. Like for myself, I have, uh, all my, my family set up with their passports and things. It makes it really easy to, to travel and buy tickets and do things of that nature.
Nice. I'm thinking like, uh, social media, right? So you have a enterprise and you got like 20 people who are sharing social media.
Yes. And five of 'em are external agencies and trying to get one of the arguments of why people didn't do MFA on the social media was there's no easy way to share that. So I'm thinking I could do what you're saying.
One password. That's exactly right. So you can use the OTP directly into one password and you can use the share credential.
Um, and so you can share it within the group and the entire social media team can have access to that credential and the OTP. So nobody has to text each other or call each other and say, you know, what's the token? I think we, we were, um, talking and like one of my other favorite examples is my husband and I share that our Amazon account.
And, uh, we used to have to like call each other every time somebody wanted to buy something because the OTP would go to his phone or my phone or whatever, and now it's in one password. And I can't tell you how many phone calls and how much time it has saved just in my personal life for that in itself.