1Password Unified Access is the name 1Password uses for a platform that combines four enterprise products: Enterprise Password Manager, Device Trust, SaaS Manager and Privileged Access.[1] The platform can be bought as a whole, and each product can also be bought separately.[1] No list price is published. 1Password says Unified Access pricing “is tailored to your organization’s needs” and asks prospective customers to contact sales for a quote.[1] Each product adds Product-Specific Terms to the governing agreement, which for standard customers is the Subscription Terms for Business Customers.[11] These terms license software installed on customer devices and systems to connect them to the hosted service. They also make the customer responsible for telling the people whose devices or access are managed and for obtaining their consents.[2]
Editions
| Product | What 1Password describes | Product-Specific Terms |
|---|---|---|
| Unified Access | Enterprise Password Manager, Device Trust, SaaS Manager and Privileged Access in one platform[1] | Unified Access PSTs, v202604, last updated 2026-04-15[2] |
| Enterprise Password Manager | Credential protection and management for organizations; Unified Access builds on it[1] | Subscription Terms; no separate PST reviewed |
| Device Trust Core | Device checks enforced by the 1Password browser extension on work web apps, including apps without SSO[7] | Device Trust PSTs, last updated 2025-04-25[3] |
| Device Trust Connect | Everything in Core, plus enforcement in the identity provider’s SSO sign-in flow (Okta, Entra ID, Google Workspace)[7] | Device Trust PSTs[3] |
| SaaS Manager | Discovery and management of SaaS applications, access and spend[1] | SaaS Manager PSTs, last updated 2025-01-13[4] |
| Privileged Access | Just-in-time and just-enough privileged access[1] | Privileged Access PSTs, last updated 2026-07-31[5] |
The Device Trust Product-Specific Terms define 1Password Device Trust as any product sold under that name, “including Device Trust Core and Device Trust Connect”.[3] Device Trust was previously named Kolide. Existing Kolide customers keep the agents they have already installed.[7] The Slack application from the Kolide era is not part of 1Password Device Trust and is not sold to new customers.[7] Catalog: Device Trust Connect adds identity-provider enforcement to Core.
Extended Device Compliance is a feature of Device Trust. It enforces posture checks on web applications through the 1Password browser extension and is included in both Core and Connect.[8] It requires both Enterprise Password Manager and Device Trust, plus the browser extension.[8] A customer that buys Device Trust alone does not get this capability. Catalog: Extended Device Compliance requires both Enterprise Password Manager and Device Trust.
Metrics
- Managed Identity (catalog row Managed Identity). The SaaS Manager Product-Specific Terms define a Managed Identity as a non-service-account identity “listed with an ‘active’ status in the Customer’s primary identity provider (IdP) as integrated with the Services”.[4] The Partner Program Agreement requires reseller purchase orders for SaaS Manager to use Managed Identity as the item purchased. Where an order says Authorized Users or Users instead, those words are read as Managed Identities.[10] Catalog: SaaS Manager is purchased per Managed Identity.
- Authorized User. The Device Trust terms define an Authorized User as any individual associated with the customer who registers for an account and is granted access to Device Trust, including employees, agents and contractors.[3] The SaaS Manager terms repeat this definition with the Device Trust wording.[4] Neither document says that the Authorized User is the billing unit.
- User (catalog row User). Enterprise Password Manager falls under the business agreement, whose fees are based on the Number of Users in the Order Form.[11]
1Password publishes no licensing unit for Device Trust, Privileged Access or the Unified Access platform. The unit and quantity come from the quote and Order Form.[1]
Counting / floors
SaaS Manager counts the identity provider. Because a Managed Identity is defined by its status in the customer’s primary identity provider, the count follows the directory and not the users who sign in to SaaS Manager. Identities that are active in the directory count, and service accounts do not.[4] Disabling departed staff in the identity provider is therefore the step that reduces the SaaS Manager count.
Lapse affects the add-on products. If the 1Password account is frozen because the subscription lapsed, an organization that uses Device Trust or SaaS Manager loses access to those products. Reactivation goes through 1Password Sales and is not done in the self-service billing page.[9]
No published minimum quantity, floor or rounding rule exists for these products.
Agent and connector software
Each Product-Specific Terms document adds a licence for software that runs in the customer’s environment.
- Unified Access, Device Trust and XAM. 1Password grants “a limited, non-exclusive, non-transferable right to download, copy, and execute Integration Technology” only to enable communication between Customer Devices and the Services. The customer may not install it on a device for which it or the Device Owner lacks proper authority.[2][3][6] Customer Devices include browsers, computers, mobile devices and servers.[2] Catalog: Agent and integration software may be installed only for the subscribed service on authorized devices.
- Privileged Access. 1Password grants a limited, non-exclusive, non-transferable right during the Term to install, execute and use the Connector, only as needed to enable the customer’s authorized use of the Services.[5] When the Agreement ends, all Connector licences end and the customer must remove or disable the Connectors. Active access grants that have not expired or been revoked are not revoked automatically by 1Password, and the customer is responsible for revoking them.[5] Catalog: Privileged Access connectors must be removed at termination; grants are not auto-revoked.
These licences are tied to the subscription. They do not create a separately counted installation entitlement, and no reviewed document limits the number of devices on which the agent may run.
Consents and customer data
The Unified Access, Device Trust and XAM terms all require the customer to disclose to its Authorized Users that Integration Technology is downloaded onto their devices. The customer must also disclose that 1Password collects, uses and shares Customer Data under the Agreement and that sub-processors may have access, and it must obtain and store the necessary consents.[2][3] Catalog: Customer must disclose device data collection and obtain user consents.
For Privileged Access, Customer Data also includes metadata, identities, permissions, access requests, approval records and audit logs from the customer’s Connected Systems. The customer is responsible for exporting and keeping audit logs to meet its own retention obligations.[5] Where SaaS Manager uses third-party APIs, the customer must comply with the API providers’ terms.[4]
Relationship between XAM and Unified Access
The Subscription Terms for Business Customers make use of the “XAM Service” subject to Product-Specific Terms.[11] The XAM Product-Specific Terms (v202405) govern Customer’s use of Extended Access Management.[6] The Unified Access terms state that they apply only to Unified Access and not to other 1Password products, “including Extended Access Management (XAM), which are governed by separate terms”.[2] A customer that bought XAM therefore stays under the XAM terms unless it moves to Unified Access. Catalog: Unified Access PSTs do not govern legacy XAM.
All the Product-Specific Terms reviewed reserve 1Password’s right to change them. Material adverse changes are to be notified in advance by email, except in listed cases such as legal or security reasons, where they can take effect immediately. Continued use after a change counts as acceptance.[2]
Virtualization & partitioning
No reviewed document counts these products by host, core or virtual machine. Device Trust terms cover servers as Customer Devices,[3] but the commercial unit comes from the quote.
Cloud / BYOL
There is no bring-your-own-licence construct. Device Trust Customer Data is processed in the locations in the Data Processing Addendum. A customer may ask for Customer Data for a product to be hosted in a different region, subject to availability.[3]
Programs
Purchase of the platform or of individual products is through 1Password sales.[1] Catalog: Unified Access can be bought as a platform or product by product. Partner resale of these products is covered in 1Password MSP and partner licensing.
Out of scope
This article does not cover Credential Broker, AI-specific terms, the Data Processing Addendum, or agreements that former Kolide and Trelica customers signed before their products were renamed. Device posture checks and features are described only where they affect what must be bought. The self-service plans are covered in 1Password Business and Teams Starter Pack licensing.