Stop digging, just ask: get renewal-ready AI and SaaS reports in seconds
The information you need before a renewal meeting usually exists in SaaS Manager. Getting to it is another matter, because you have to know which report holds it, how to filter it, and whether the results actually answer the question you were asked. For an IT admin who works in the product daily, that's a minor detour. For a colleague in finance who opens SaaS Manager a few times a quarter, it can be the reason the question goes back to IT instead.
Today, we're announcing the general availability of an AI assistant in 1Password SaaS Manager. You can ask about your SaaS and AI environment in your own words and get a written answer based on your SaaS Manager data, along with a link to the relevant view with filters already applied. The practical effect is that finding an answer depends on knowing what you want to ask rather than knowing your way around the product, which matters as more finance and technology leaders get involved in decisions about software and AI spend. The assistant is included with existing SaaS Manager plans at no additional cost.
Opening that door raised a second set of questions for us. An assistant that can retrieve information about your applications and access needs clear limits on what it can reach and what should happen when someone tries to push it past those limits. We wanted customers to understand those decisions as clearly as they understand the feature itself, so this post covers both what the assistant helps you do and how we built its security and privacy controls.
Ask about your SaaS environment in your own words
Suppose you’re reviewing applications that may need closer attention because of their cost or access risk. You can ask:
“Which apps have spend over $100,000, high access risk, and no owner?”
The assistant provides a written answer based on your SaaS Manager data with a link to the relevant view, with filters and sorting already applied. You can then examine the underlying records and continue your review in the product.
If you’re unsure where to start, suggested prompts introduce common questions across areas such as Applications, Spend, and Contracts. These suggestions can also help you discover ways to use information you might not have considered.
The assistant helps you find and understand information while leaving changes to your environment in your hands. Its tools are read-only, so asking a question won’t create a workflow or delete an application. You can review results before deciding whether to take action.
Get answers without needing to be an expert on SaaS Manager
Even people who use SaaS Manager regularly don't know every corner of it. An admin might navigate the applications list from memory but rarely open contracts, while a finance lead preparing for a renewal may only sign in a few times a quarter. Both know what they're looking for, and both can lose time finding it.
People who need information from SaaS Manager don’t all spend the same amount of time using it. An IT admin may know exactly where to find an application report, while a colleague in finance preparing for a renewal discussion may only open the product occasionally. Both understand what they’re looking for, but they bring different levels of familiarity with the interface.
The assistant lets those colleagues start with their question rather than having to learn the reporting menus first. A finance team member with access could ask which AI tool is consuming the most tokens, then open a filtered view to reveal the cost per vendor details. As finance teams become more involved in managing AI and software costs, making SaaS Manager easier for them to navigate helps them participate directly in those decisions.
This also helps new customers. While your team learns SaaS Manager, suggested prompts can introduce questions the product can help answer, while links to the underlying reports show where to explore further. You can begin using the information available in your environment while building familiarity with the product, rather than needing to know your way around every view before starting.
The assistant works within your SaaS Manager permissions
SaaS Manager contains information about your organization’s applications and access, which means that an easier way to retrieve that information needs to respect the controls already in place.
Every assistant request runs in the context of the signed-in user, with SaaS Manager’s existing role-based access controls and tenant isolation applied. If a user can’t access certain information elsewhere, asking the assistant doesn’t grant access.
SaaS Manager’s APIs check authorization, and the tools available to the assistant, are filtered according to the user’s permissions. The service also validates tool selections and parameters against approved definitions, rejecting unsupported or unauthorized requests rather than attempting an operation outside its allowed scope.
This separation means the model can interpret a question and explain the results, while SaaS Manager remains responsible for deciding what information the user can retrieve.
Building security controls around the model
One of the challenges in building an AI assistant is that the text it processes can contain instructions intended to change its behavior. Someone might type a malicious request directly into the chat, or hide instructions in content the assistant retrieves. These attempts are known as prompt injection. We worked extensively with our internal security research team, Off-by-1 Labs, to harden our implementation before putting it in front of customers.
Instructions that tell a model to ignore malicious content can help, but we built additional controls around the model to limit what the system can access and do. Approved tools, permission checks, and parameter validation provide boundaries that operate independently of whether the model follows a particular instruction.
We developed the assistant in stages so our engineering and security teams could test those boundaries before expanding its capabilities. The first internal version accepted static prompts and returned links to existing views without sending customer data to the model. Later versions introduced natural-language input and responses grounded in data retrieved through approved SaaS Manager tools.
As the assistant’s capabilities expanded, the design added field-level controls over data passed to the model and sanitization of user-generated strings. Evaluation covered malformed requests, unauthorized tool calls, and checks for customer-data exposure, alongside security testing for prompt-injection attempts. Privacy and Security reviews were part of the architectural design and development processes from the start.
This approach gives us specific behavior to test as we develop the assistant further. It also reflects how we think about introducing AI into a 1Password product. Its usefulness depends in part on whether customers can understand and trust the controls around it.
Giving customers control over the AI experience
Because the customer-facing assistant can use retrieved SaaS Manager data to produce an answer, customers should understand how that access works and can choose whether to use it.
Requests operate under the current user’s permissions, with controls over data passed to the model. Admins decide whether to enable the assistant for their organization.
Individual users see consent terms before first use and can delete their chat history. That history is specific to each user, with a six-month retention period and the ability to delete individual conversations sooner.
These controls give organizations a way to manage access to the experience while allowing users to manage the conversations they retain.
Explore the AI assistant in 1Password SaaS Manager
The AI assistant is now generally available and included in existing SaaS Manager plans at no additional cost. If you’re already a customer, your admin can enable it in your organization’s settings. You can then review the consent terms and try a suggested prompt or bring a question from an upcoming application review. Your Customer Success Manager can help you get started.
If you’re evaluating SaaS Manager, the assistant gives your team a way to begin exploring the information the platform brings together, even before they’re familiar with its reports. SaaS Manager supports IT’s work to discover applications and govern access, while giving Finance and technology leaders visibility into software and AI spend to inform purchasing decisions.
Ready to get started?
Request a demo to see how your team can use 1Password SaaS Manager to manage access and spend, and how the AI assistant can help colleagues find the information they need.