1Password SaaS Manager

by 1Password SaaS Manager Team
1Password SaaS Manager Team
Updated to #916 on
SaaS Manager
 
1Password SaaS Manager #916

New

  • (beta) AI Spend and Consumption: This feature is now available in public beta for all 1Password SaaS Manager customers. This feature gives IT and Finance teams unified visibility into AI tool usage and spend across the organization, helping them track consumption, manage budgets, and stay ahead of cost overruns.
    • Integrations and data
      • Integration support: Supported integrations at launch include Cursor, OpenAI Platform, Anthropic Claude Enterprise, and Amazon Bedrock.
      • Integration connection status: The dashboard displays the connection status of relevant integrations, making it easier to diagnose data gaps at a glance.
      • API key management: Admins can edit and delete API keys directly from the API key table. All key changes are captured in the audit log for full traceability.
    • Dashboard and navigation
      • AI Spend and Consumption page: The feature is accessible as a top-level page in SaaS Manager, accessible from the “AI Consumption” sidebar label.
      • Overview and Budgets tabs: The dashboard features dedicated tabs for Overview and Budgets, making it easier to navigate between consumption data and budget management.
      • Breakdown views: Usage can be broken down by app, model, API key, and individual people, giving teams granular visibility into what’s driving costs.
      • Drill-down navigation: Select any entity in the chart or table to apply contextual filters and drill into related data automatically. For example, select a day in the chart to filter the table to that date’s usage.
      • Search in consumption table: A search bar filters table rows in real time by the primary identifier for the current view (account name, model, API key, and so on).
      • Expandable chart: The AI usage chart can be expanded to fill the screen for easier analysis.
      • Estimated spend column: The spend column is labeled “Est. Spend” and includes a tooltip clarifying that values are estimates. A sorted-descending icon makes the default sort order visible at a glance.
      • App consumption tab: The App view includes a dedicated Consumption tab with a stacked area chart, detailed table, and cached token columns for more granular cost visibility.
      • Hide leaderboard view setting: A new admin setting lets organizations hide the leaderboard-style breakdown of consumption by accounts and people.
    • Budgets
      • Budget management: Admins can set vendor-level spend budgets. Budgets tab improvements include filtering support, a detail view for individual budgets, and URL-synced tab state for easier navigation and sharing.
      • Budget date quick pickers: Quick-pick date shortcuts make it faster to define and update budget date ranges without manually entering dates.
      • Fixed-term budgets: Admins can manually create fixed-term budgets for customer apps for more flexible spend management.
    • Alerts and notifications
      • Budget alerting: Admins receive alerts when AI spend approaches or exceeds configured budgets. Alert thresholds are set at 75% and 90% by default, with a notification when the budget is fully exhausted.
      • Notification settings: Admins can configure notification settings for AI data gaps and over-budget spend, including customizable alert frequency, by email and Slack.
      • Alert history and spike details: Administrators can view a history of AI consumption alerts and drill into details for individual usage spikes directly from the dashboard.
  • App catalog – Resource-level access requests: When requesting access to an app, users can now specify the exact resources they need within that app, such as a particular GitHub repository or a Salesforce permission set. Available resources appear in the access request form based on the access levels configured for the app, and selected resources are included in the request summary.
  • App catalog – No limit on approval levels for “Other” requests: Approvers can now add any number of additional approval stages to “Other” access request types. Previously, there was a limit on how many approval levels could be configured for this request type.
  • OneLogin – Role mapping for teams: The OneLogin integration now supports mapping Roles as a source for SaaS Manager Teams, in addition to Departments and Groups. This gives organizations more flexibility when aligning their OneLogin access structure with their SaaS Manager team hierarchy.
  • Lark – Readable location names: The Lark integration now resolves employee work country codes to readable location names, improving the quality and readability of people data synced to SaaS Manager.

Fixed

  • App catalog – Access level drawer confirmation: Fixed an issue where the confirmation prompt shown when closing the access level drawer did not clear after selecting OK. The confirmation now dismisses correctly.
  • App catalog – “Other request” account count mismatch: Fixed a discrepancy where the account count shown in the “Other Request” summary did not match the number of accounts visible when drilling into the request.
  • App catalog – Unexpected apps in App Launcher: Fixed an issue where apps not assigned to a user in Okta could appear in the App Launcher due to a mismatch between EPM and Okta assignment data.
  • Workflow exports – Organization names with emoji: Fixed an issue that prevented exporting workflow run history when the organization’s name contained an emoji. Exports now complete successfully regardless of the characters in the organization name.
  • Access requests – Cancelled request reactivation: Fixed a race condition that could allow an integration action to incorrectly update an access request that had already been cancelled or completed.
  • Notifications – Icon colors: Fixed an issue where success and error icons in notification messages were not displaying in the expected colors.
  • EPM – Managed credential “account not found” error: Fixed an error that caused an “account not found” message to appear after enforcing a managed credential for a single user in EPM.
  • EPM – Accessor sync after initial uplift: Fixed an issue where accessors were not continuing to sync after the initial access grant on a managed credential.
  • EPM – Managed credential username: Fixed an issue where the username for an enforced managed credential was derived from the policy configuration rather than the source vault item, which could result in the wrong username being used.
  • EPM – Accessor grant imports owner: Fixed an issue where granting a new user access to a managed credential would incorrectly re-import the credential owner’s account instead of creating an entry for the intended grantee.
  • Paylocity – Intermittent SSL connection errors: Fixed intermittent SSL connection failures that could interrupt Paylocity integration runs.
  • Anthropic Claude Enterprise – AI Consumption data: Fixed two issues affecting AI Consumption data for the Anthropic Claude Enterprise integration. A missing required scope prevented usage data from loading correctly, and token counts were not being summed accurately, which caused usage totals to appear lower than expected on the AI Consumption dashboard.
  • (beta) AI Consumption – Anthropic Claude Enterprise and Cursor historical data: Fixed an issue where AI Consumption data for Anthropic Claude Enterprise and Cursor was not backfilled before the initial connection date. Both integrations now fetch up to three months of historical usage data on first connection.
  • Integrations panel – Error display: Fixed an issue where integration connection errors displayed poorly in the integrations panel. Errors now show a concise status message with a link to view full details.