LICENSEWARE

1Password Unified Access, Device Trust and SaaS Manager licensing

This article is about the quote-based 1Password enterprise products, Enterprise Password Manager, Device Trust (formerly Kolide), SaaS Manager (formerly Trelica) and Privileged Access, sold separately or as the Unified Access platform, and about the Product-Specific Terms that apply to them, including those for the earlier Extended Access Management (XAM) offering.

On This Page

1Password Unified Access is the name 1Password uses for a platform that combines four enterprise products: Enterprise Password Manager, Device Trust, SaaS Manager and Privileged Access.[1] The platform can be bought as a whole, and each product can also be bought separately.[1] No list price is published. 1Password says Unified Access pricing “is tailored to your organization’s needs” and asks prospective customers to contact sales for a quote.[1] Each product adds Product-Specific Terms to the governing agreement, which for standard customers is the Subscription Terms for Business Customers.[11] These terms license software installed on customer devices and systems to connect them to the hosted service. They also make the customer responsible for telling the people whose devices or access are managed and for obtaining their consents.[2]

Editions

Product What 1Password describes Product-Specific Terms 
Unified Access Enterprise Password Manager, Device Trust, SaaS Manager and Privileged Access in one platform[1] Unified Access PSTs, v202604, last updated 2026-04-15[2] 
Enterprise Password Manager Credential protection and management for organizations; Unified Access builds on it[1] Subscription Terms; no separate PST reviewed 
Device Trust Core Device checks enforced by the 1Password browser extension on work web apps, including apps without SSO[7] Device Trust PSTs, last updated 2025-04-25[3] 
Device Trust Connect Everything in Core, plus enforcement in the identity provider’s SSO sign-in flow (Okta, Entra ID, Google Workspace)[7] Device Trust PSTs[3] 
SaaS Manager Discovery and management of SaaS applications, access and spend[1] SaaS Manager PSTs, last updated 2025-01-13[4] 
Privileged Access Just-in-time and just-enough privileged access[1] Privileged Access PSTs, last updated 2026-07-31[5] 

The Device Trust Product-Specific Terms define 1Password Device Trust as any product sold under that name, “including Device Trust Core and Device Trust Connect”.[3] Device Trust was previously named Kolide. Existing Kolide customers keep the agents they have already installed.[7] The Slack application from the Kolide era is not part of 1Password Device Trust and is not sold to new customers.[7] Catalog: Device Trust Connect adds identity-provider enforcement to Core.

Extended Device Compliance is a feature of Device Trust. It enforces posture checks on web applications through the 1Password browser extension and is included in both Core and Connect.[8] It requires both Enterprise Password Manager and Device Trust, plus the browser extension.[8] A customer that buys Device Trust alone does not get this capability. Catalog: Extended Device Compliance requires both Enterprise Password Manager and Device Trust.

Metrics

  • Managed Identity (catalog row Managed Identity). The SaaS Manager Product-Specific Terms define a Managed Identity as a non-service-account identity “listed with an ‘active’ status in the Customer’s primary identity provider (IdP) as integrated with the Services”.[4] The Partner Program Agreement requires reseller purchase orders for SaaS Manager to use Managed Identity as the item purchased. Where an order says Authorized Users or Users instead, those words are read as Managed Identities.[10] Catalog: SaaS Manager is purchased per Managed Identity.
  • Authorized User. The Device Trust terms define an Authorized User as any individual associated with the customer who registers for an account and is granted access to Device Trust, including employees, agents and contractors.[3] The SaaS Manager terms repeat this definition with the Device Trust wording.[4] Neither document says that the Authorized User is the billing unit.
  • User (catalog row User). Enterprise Password Manager falls under the business agreement, whose fees are based on the Number of Users in the Order Form.[11]

1Password publishes no licensing unit for Device Trust, Privileged Access or the Unified Access platform. The unit and quantity come from the quote and Order Form.[1]

Counting / floors

SaaS Manager counts the identity provider. Because a Managed Identity is defined by its status in the customer’s primary identity provider, the count follows the directory and not the users who sign in to SaaS Manager. Identities that are active in the directory count, and service accounts do not.[4] Disabling departed staff in the identity provider is therefore the step that reduces the SaaS Manager count.

Lapse affects the add-on products. If the 1Password account is frozen because the subscription lapsed, an organization that uses Device Trust or SaaS Manager loses access to those products. Reactivation goes through 1Password Sales and is not done in the self-service billing page.[9]

No published minimum quantity, floor or rounding rule exists for these products.

Agent and connector software

Each Product-Specific Terms document adds a licence for software that runs in the customer’s environment.

  • Unified Access, Device Trust and XAM. 1Password grants “a limited, non-exclusive, non-transferable right to download, copy, and execute Integration Technology” only to enable communication between Customer Devices and the Services. The customer may not install it on a device for which it or the Device Owner lacks proper authority.[2][3][6] Customer Devices include browsers, computers, mobile devices and servers.[2] Catalog: Agent and integration software may be installed only for the subscribed service on authorized devices.
  • Privileged Access. 1Password grants a limited, non-exclusive, non-transferable right during the Term to install, execute and use the Connector, only as needed to enable the customer’s authorized use of the Services.[5] When the Agreement ends, all Connector licences end and the customer must remove or disable the Connectors. Active access grants that have not expired or been revoked are not revoked automatically by 1Password, and the customer is responsible for revoking them.[5] Catalog: Privileged Access connectors must be removed at termination; grants are not auto-revoked.

These licences are tied to the subscription. They do not create a separately counted installation entitlement, and no reviewed document limits the number of devices on which the agent may run.

Consents and customer data

The Unified Access, Device Trust and XAM terms all require the customer to disclose to its Authorized Users that Integration Technology is downloaded onto their devices. The customer must also disclose that 1Password collects, uses and shares Customer Data under the Agreement and that sub-processors may have access, and it must obtain and store the necessary consents.[2][3] Catalog: Customer must disclose device data collection and obtain user consents.

For Privileged Access, Customer Data also includes metadata, identities, permissions, access requests, approval records and audit logs from the customer’s Connected Systems. The customer is responsible for exporting and keeping audit logs to meet its own retention obligations.[5] Where SaaS Manager uses third-party APIs, the customer must comply with the API providers’ terms.[4]

Relationship between XAM and Unified Access

The Subscription Terms for Business Customers make use of the “XAM Service” subject to Product-Specific Terms.[11] The XAM Product-Specific Terms (v202405) govern Customer’s use of Extended Access Management.[6] The Unified Access terms state that they apply only to Unified Access and not to other 1Password products, “including Extended Access Management (XAM), which are governed by separate terms”.[2] A customer that bought XAM therefore stays under the XAM terms unless it moves to Unified Access. Catalog: Unified Access PSTs do not govern legacy XAM.

All the Product-Specific Terms reviewed reserve 1Password’s right to change them. Material adverse changes are to be notified in advance by email, except in listed cases such as legal or security reasons, where they can take effect immediately. Continued use after a change counts as acceptance.[2]

Virtualization & partitioning

No reviewed document counts these products by host, core or virtual machine. Device Trust terms cover servers as Customer Devices,[3] but the commercial unit comes from the quote.

Cloud / BYOL

There is no bring-your-own-licence construct. Device Trust Customer Data is processed in the locations in the Data Processing Addendum. A customer may ask for Customer Data for a product to be hosted in a different region, subject to availability.[3]

Programs

Purchase of the platform or of individual products is through 1Password sales.[1] Catalog: Unified Access can be bought as a platform or product by product. Partner resale of these products is covered in 1Password MSP and partner licensing.

Out of scope

This article does not cover Credential Broker, AI-specific terms, the Data Processing Addendum, or agreements that former Kolide and Trelica customers signed before their products were renamed. Device posture checks and features are described only where they affect what must be bought. The self-service plans are covered in 1Password Business and Teams Starter Pack licensing.

References

  1. Enterprise Pricing & Plans | 1PasswordUndated pricing page with FAQ. Catalog: 1Password Enterprise pricingRetrieved 2026-10-06.
  2. Unified Access Product-Specific Terms1PW PSTs v202604, last updated April 15, 2026. Catalog: 1Password Unified Access Product-Specific TermsEffective 2026-04-15. Retrieved 2026-10-06.
  3. 1Password Device Trust Product-Specific TermsLast updated April 25, 2025. Catalog: 1Password Device Trust Product-Specific TermsEffective 2025-04-25. Retrieved 2026-10-06.
  4. SaaS Manager Product-Specific TermsLast updated January 13, 2025. Catalog: 1Password SaaS Manager Product-Specific TermsEffective 2025-01-13. Retrieved 2026-10-06.
  5. 1Password Privileged Access Product-Specific TermsLast updated July 31, 2026. Catalog: 1Password Privileged Access Product-Specific TermsEffective 2026-07-31. Retrieved 2026-10-06.
  6. 1Password Product-Specific Terms (Extended Access Management)1PW PSTs v202405, last updated May 2, 2024. Catalog: 1Password Product-Specific Terms: Extended Access Management (v202405)Effective 2024-05-02. Retrieved 2026-10-06.
  7. Frequently asked questions (Device Trust) | 1Password SupportPublished September 29, 2026. Catalog: 1Password Device Trust frequently asked questionsEffective 2026-09-29. Retrieved 2026-10-06.
  8. Extended Device Compliance: Secure Apps Beyond SSO | 1PasswordUndated product page. Catalog: Extended Device Compliance product pageRetrieved 2026-10-06.
  9. If your 1Password account is frozen | 1Password SupportPublished August 3, 2026. Catalog: If your 1Password account is frozenEffective 2026-08-03. Retrieved 2026-10-06.
  10. 1Password Partner Agreement | 1PasswordPartner Program Agreement, last updated January 13, 2026. Catalog: 1Password Partner Program AgreementEffective 2026-01-13. Retrieved 2026-10-06.
  11. Terms & Conditions of Service | 1PasswordSubscription Terms for Business Customers; last updated September 12, 2024. Catalog: 1Password Terms of ServiceEffective 2024-09-12. Retrieved 2026-10-06.

See also

Catalog Rows Cited

8Rules2Metrics6SKUs

Esc