Executive Summary
Identity and access management (IAM) has become a critical security function because organizations must protect access to sensitive applications and data without compromising employee productivity, business agility, or user experience.1 At the same time, IAM responsibilities are expanding beyond workforce identities to include SaaS applications, machine identities, and emerging AI-powered systems that depend on secure credential management and access to applications, data, and services.2 Password managers can help organizations reduce credential-related risk, improve IT operational efficiency, and enable employees and developers to work more efficiently while preparing for an increasingly complex identity environment.
1Password Enterprise Password Manager (EPM) can help organizations securely store, access, share, and govern credentials across employees, contractors, and development teams. The solution centralizes credential management, supports secure sharing and access controls, and provides capabilities that can help organizations reduce reliance on insecure credential practices and improve visibility into credential usage. Organizations can also use EPM to support developer and automation workflows through secure secrets management and runtime credential retrieval, helping integrate credential security into existing development and operational processes.
1Password commissioned Forrester Consulting to conduct a Total Economic Impact™ (TEI) study and examine the potential return on investment (ROI) enterprises may realize by deploying Enterprise Password Manager.3 The purpose of this study is to provide readers with a framework to evaluate the potential financial impact of Enterprise Password Manager on their organizations.
Key Statistics
155%
Return on investment (ROI)
$2.0M
Benefits PV
$1.2M
Net present value (NPV)
To better understand the benefits, costs, and risks associated with this investment, Forrester interviewed four decision-makers with experience using Enterprise Password Manager. For the purposes of this study, Forrester aggregated the experiences of the interviewees and combined the results into a single composite organization, which is a global enterprise with 3,000 employees operating across North America, EMEA, and APAC.
Interviewees said that prior to using Enterprise Password Manager, their organizations relied on a fragmented mix of legacy password managers, browser-stored credentials, spreadsheets, shared documentation, and manual processes to manage employee, developer, and shared-account access. However, this prior state resulted in limited success, leaving them with poor credential visibility, inconsistent governance, high support burdens, low user adoption, and difficulty securing developer credentials and workflows. These limitations led to credential-related security risks, inefficient access management processes, reduced productivity, and limited control over credentials used across employees, applications, and development environments.
After the investment in Enterprise Password Manager, the interviewees’ organizations centralized credential management, standardized access controls, and improved governance across workforce and developer credentials. Key results from the investment include reduced credential-related security risk, lower IT support effort, streamlined employee access to applications, and improved developer productivity through more secure and efficient credential-management workflows.
Key Findings
Quantified benefits. Quantified benefits for the composite organization include:
-
Improved IT operational efficiency. The composite organization reduces credential-related support workloads through centralized credential management, simplified permissions administration, and automated lifecycle controls. This drives a 70% reduction in credential-related tickets and a 35% reduction in credential-related ticket-handling effort, allowing IT personnel to redirect time from routine credential support to higher-value priorities. This benefit is worth approximately $190,000 in present value over three years.
-
Improved employee productivity. The composite organization gives employees faster, more reliable access to credentials for shared and non-single sign-on (SSO) applications. Easier credential retrieval, entry, and secure sharing reduce workflow interruptions and save employees an average of 55 minutes per month through streamlined credential access. These gains are particularly valuable for employees who regularly access multiple applications or shared accounts. This benefit is worth approximately $748,000 in present value over three years.
-
Improved developer productivity. The composite organization integrates secure credential access into development tools and workflows, reducing manual credential handling and reliance on locally stored or hardcoded secrets. Centralized vaults, command-line workflows, and runtime secrets retrieval streamline continuous integration and continuous delivery (CI/CD) processes and save developers an average of 165 minutes per month on credential-related activities, allowing them to spend more time building, testing, and deploying software. This benefit is worth approximately $864,000 in present value over three years.
-
Reduced credential-related security risk. The composite organization improves credential governance by centralizing password storage, increasing visibility into credential risks, and strengthening access controls. Improved credential hygiene, monitoring, and governance reduce exposure associated with password reuse, plaintext storage, unmanaged sharing, and credentials used for applications outside of single sign-on. The composite organization realizes a 20% reduction in addressable credential-related breach exposure. This benefit is worth approximately $158,000 in present value over three years.
Unquantified benefits. Benefits that provide value for the composite organization but are not quantified for this study include:
-
Increased readiness for AI, automation, machine identities, and democratized development. The composite organization establishes a more scalable foundation for securely managing and retrieving credentials as AI agents, automated workflows, nonhuman identities, and a broader population of application builders require access to sensitive resources.
-
Enhanced employee experience and security culture. The composite organization makes secure credential management easier to incorporate into employees’ daily work, encouraging adoption without creating unnecessary friction. Included personal and family accounts extend the value to employees’ personal lives and help reinforce stronger security habits beyond the workplace.
-
Improved developer experience. The composite organization reduces friction between development workflows and security requirements by integrating credential and secrets management into existing tools and processes. Development teams can follow secure practices without treating security as a separate or disruptive step.
-
Stronger compliance, audit, and regulatory support. The composite organization improves visibility, governance, and oversight of credential access. Centralized controls make it easier to validate credential ownership and access to relevant systems while reducing the effort required to support recurring compliance and audit activities.
Quantified costs. Quantified costs for the composite organization include:
-
Annual license costs. The composite organization licenses 1Password Enterprise Password Manager to support employee password management, shared credential management, and developer-focused use cases such as secrets management and secure credential automation. This cost is worth approximately $658,000 in present value over three years.
-
Implementation, training, and ongoing management. The composite organization dedicates internal IT, security, and business resources to deployment planning, testing, migration, employee communications, training, and ongoing administration. This cost is worth approximately $111,000 in present value over three years.
The financial analysis that is based on the interviews found that a composite organization experiences benefits of $2.0 million over three years versus costs of $769,000, adding up to a net present value (NPV) of $1.2 million and an ROI of 155%.
$1.2 million
Total risk-adjusted net present value over three years
Benefits (Three-Year)
Spotlight: A Unified Approach With Enterprise Password Manager And SaaS Manager
Prior to using Password Enterprise Password Manager, interviewees’ organizations frequently managed SaaS visibility and credential security through separate processes, creating a gap between the applications employees use and the credentials that provide access to them. Interviewees whose organizations used both 1Password Enterprise Password Manager and SaaS Manager described complementary roles for the products: SaaS Manager helped identify actual application usage, while Enterprise Password Manager helped secure and govern credentialed access. Together, these capabilities gave interviewees’ organizations a more connected foundation for understanding application access, strengthening lifecycle controls, and managing SaaS and credential risk. Forrester found the following synergistic benefits:
-
More complete visibility into application access. Interviewees said SaaS Manager helped identify which applications employees accessed, including applications outside established identity systems, while Enterprise Password Manager helped secure and govern credentials stored within the platform. Connecting application-use data with credential visibility gave IT and security teams a more complete understanding of where access existed and how it was managed. The CIO at a professional services organization explained, “The combined visibility improves because we can see both the credentials a user has and the applications they actually use.”
-
Stronger access lifecycle management. The combined visibility was particularly valuable during employee offboarding. SaaS Manager helped surface applications that employees used even when their credentials were not stored in Enterprise Password Manager, while Enterprise Password Manager helped govern known credentials and shared access. This reduced the risk that accounts or credentials remained active because IT did not know they existed. The CIO at a professional services organization said: “You could not achieve the same deprovisioning results with only one of the products. The combination is what gives us confidence.”
-
Simplified portfolio expansion and vendor management. For some interviewees, their organizations had an existing relationship with 1Password, which made SaaS Manager easier to evaluate, procure, and manage alongside Enterprise Password Manager. One interviewee described the products as operationally distinct but said the broader relationship improved the commercial case through vendor consolidation and bundled pricing. The CISO at an e-commerce organization explained: “When we evaluated SaaS management tools, our existing relationship with 1Password was a factor. It improved the business case and helped move SaaS Manager to the top of the list.”
Forrester’s analysis of interviewees’ experiences indicated that Enterprise Password Manager and SaaS Manager could operate as complementary layers of a broader access-governance strategy. Together, they helped the interviewees’ organizations connect application visibility with credential governance, providing greater confidence in access visibility, lifecycle management, and SaaS oversight. An established relationship with 1Password also simplified product evaluation, procurement, and portfolio management for some interviewees’ organizations. The study does not independently quantify incremental value attributable specifically to deploying the two products together.
Forrester also evaluated the Total Economic Impact™ of 1Password SaaS Manager as a standalone solution. While the value described in this spotlight relates specifically to how Enterprise Password Manager and SaaS Manager complement one another, interviewees also reported independent benefits from SaaS Manager related to rationalized SaaS application spending, increased IT efficiency, and reduced compliance-related security risk. Additional quantified findings for those capabilities are detailed in the separate study.
To see the full study, please register below.
The 1Password Enterprise Password Manager Customer Journey
Drivers leading to the Enterprise Password Manager investment
Interviews
| Role | Industry | Region | Employees |
|---|---|---|---|
| AI and security leader | Financial services | Global (headquarters: North America) | 44,000+ |
| CISO | Technology | Global (headquarters: North America) | 2,500+ |
| CISO | E-commerce | Global (headquarters: North America) | 2,400+ |
| CIO | Professional services | Global (headquarters: North America) | 1,200+ |
Key Challenges
Before adopting 1Password, interviewees’ organizations used a fragmented mix of legacy password managers, browser-stored credentials, spreadsheets, shared documentation, and manual processes to manage employee, developer, and shared-account access. These approaches provided limited visibility and governance while creating friction for end users and additional work for IT and security teams. Interviewees noted how their organizations struggled with common challenges prior to investing in Enterprise Password Manager, including:
-
Fragmented credential management. Interviewees described credentials spread across legacy tools, browsers, local storage, and informal tracking systems. Without a consistent approach, their employees managed passwords independently, and IT and security teams lacked assurance that sensitive credentials were stored securely. The AI and security leader at a financial services organization explained: “Before 1Password, there was no formal way to manage passwords for standard user accounts. People were remembering them or storing them locally, which created significant security risk. We brought in 1Password to eliminate those risks and provide a secure place to vault credentials.”
-
Limited visibility into credentials and applications. Interviewees lacked centralized visibility into credentials used for applications outside of single sign-on, including which employee had access and whether credentials were securely managed. This made it difficult to identify unmanaged access, enforce policies, and maintain ownership of third-party accounts. The CIO of a professional services organization explained: “Before 1Password, many third-party accounts were effectively invisible to us. Now, we have visibility, governance, and ownership.”
-
High levels of IT effort. The interviewees’ organizations’ prior solutions created recurring support requests related to usability, account access, permissions, and vault administration. Credential-related issues could prevent employees from accessing the applications they needed, making password management one of IT’s most persistent sources of support demand. The CISO of an e-commerce company said, “Before the move, [password-manager-related tickets] were consistently one of the top ticket drivers for IT.”
-
Low employee adoption of existing password management tools. Interviewees described challenges driving consistent adoption of previous password management solutions due to usability issues, employee resistance, and poor user experiences. As a result, their employees sometimes developed their own credential management habits outside approved tools, increasing governance and security challenges while limiting the effectiveness of password management programs. The CISO of an e-commerce organization explained: “We were struggling with usability issues in our previous password manager. Adoption was mandated, but people didn’t love using it. When I looked at what employees were choosing on their own, 44% were already paying for 1Password personally. That told me it had the product-market fit we wanted.”
-
Difficulty securing developer credentials and workflows. Development teams lacked a consistent way to retrieve, rotate, and distribute secrets without storing credentials locally, embedding them in scripts, or sharing them through insecure channels. These practices increased manual effort and created security concerns as interviewees’ organizations expanded their use of application programming interfaces, automated pipelines, and lightweight development workflows.
-
Growing security and governance risks. Credential sprawl increased the risk of weak or reused passwords, unauthorized access, and sensitive information being stored or shared outside controlled systems at the interviewees’ organizations. Interviewees’ organizations also needed stronger auditability and governance as they adopted more software-as-a-service applications and expanded the number of human and nonhuman identities requiring access.
Investment Objectives
Interviewees’ organizations sought to replace fragmented credential-management practices with an approach that improved visibility, strengthened security, and reduced friction for employees and developers. Their investment decisions reflected the following priorities:
-
Improving visibility and control over credentials. Interviewees wanted centralized oversight of credentials used by employees, developers, shared accounts, and automated workflows. They sought stronger controls over credential ownership, permissions, sharing, and offboarding, particularly for applications outside of single sign-on. As the CIO at a professional services organization told Forrester: “SSO solved most use cases, but many applications either did not support SSO or required costly licensing upgrades. We needed a secure, sustainable way to manage those credentials across the business.”
-
Improving user experience while strengthening security. Interviewees prioritized a solution that employees would consistently adopt rather than circumvent. They wanted to make secure credential management easier for users while reducing weak passwords, password reuse, and local credential storage. As the CISO at an e-commerce organization explained: “Our goal was to provide a password manager people actually wanted to use. 1Password’s user experience drove adoption in a way our previous solution never did.”
-
Supporting modern development and automation workflows. Interviewees needed to secure developer secrets, application programming interface keys, and other nonhuman credentials without slowing development teams. They sought to enable teams to retrieve and inject credentials programmatically rather than managing them manually or hard-coding them into scripts and automated pipelines. Interviewees also saw secure credential management becoming increasingly important as AI-powered development, automation, and agentic workflows continue to expand.
-
Preparing for emerging AI and machine identity requirements. Interviewees recognized that identity and credential management needs are expanding beyond employees and traditional applications. As the interviewees’ organizations increased their use of automation, AI-powered development, machine identities, and agentic workflows, they sought a solution that could provide secure credential management, secrets retrieval, and governance at scale. Interviewees viewed these capabilities as important for supporting future development models while maintaining security and control across increasingly complex identity environments.
-
Strengthening governance, compliance, and risk management. Interviewees wanted more auditable and controlled credential-management processes that supported internal policies and compliance requirements. They prioritized improved reporting, access controls, secure credential sharing, and greater visibility into potential exposures. As the AI and security leader at a financial services organization stated: “If passwords are saved locally or outside a secure vault, there is always a risk they can be compromised or stolen. Addressing that risk was one of the main reasons we adopted 1Password.”
Composite Organization
Based on the interviews, Forrester constructed a TEI framework, a composite organization, and an ROI analysis that illustrates the areas financially affected. The composite organization is representative of the interviewees’ organizations, and it is used to present the aggregate financial analysis in the next section. The composite has the following characteristics:
-
Description of composite. The composite organization is a global enterprise with 3,000 employees headquartered in North America and operating across North America, EMEA, and APAC. The organization has a mature identity and access management strategy and uses SSO for many core business applications but continues to rely on password management for shared credentials, non-SSO applications, privileged access, and developer secrets. Prior to adopting 1Password EPM, the composite’s employees used a combination of browser-stored passwords, legacy password managers, spreadsheets, documents, shared messages, and homegrown repositories to manage credentials.
-
Deployment characteristics. The composite organization deploys 1Password EPM to all 3,000 employees. The platform serves a broad range of users, including business employees, IT administrators, and software developers. Approximately 300 developers use 1Password to manage developer credentials and secrets, while the broader employee population uses the solution for personal, shared, and business application credentials. The composite organization standardizes credential management on 1Password and uses the platform to secure shared credentials, non-SSO applications, privileged access, and developer secrets across global operations.
KEY ASSUMPTIONS
-
3,000 employees use 1Passowrd EPM
-
Headquartered in North America with global operations
-
300 developers use 1Password EPM
Analysis Of Benefits
Quantified benefit data as applied to the composite
Total Benefits
| Ref. | Benefit | Year 1 | Year 2 | Year 3 | Total | Present Value |
|---|---|---|---|---|---|---|
| Atr | IT operational efficiency lift | $76,423 | $76,423 | $76,423 | $229,268 | $190,052 |
| Btr | Improved employee productivity | $300,713 | $300,713 | $300,713 | $902,138 | $747,827 |
| Ctr | Developer productivity lift | $347,490 | $347,490 | $347,490 | $1,042,470 | $864,156 |
| Dtr | Reduced credential-related security risk | $63,510 | $63,510 | $63,510 | $190,529 | $157,939 |
| Total benefits (risk-adjusted) | $788,135 | $788,135 | $788,135 | $2,364,405 | $1,959,974 |
IT Operational Efficiency Lift
Evidence and data. Interviewees reported that credential-related support activities consumed significant IT time before adopting 1Password Enterprise Password Manager. According to interviewees, password access issues, vault administration requests, onboarding and offboarding tasks, and credential-related troubleshooting generated recurring support workloads and delayed routine operational activities. Multiple interviewees connected centralized credential management, simplified permissions administration, and automated lifecycle controls with fewer support requests and faster resolution times. Interviewees also said improved usability reduced the volume of urgent access-related tickets, allowing IT teams to spend less time managing routine credential issues and more time on higher-value operational priorities.
-
The CISO at an e-commerce organization estimated that password-manager-related support activity previously represented approximately $120,000 annually in help desk effort. Following deployment, password-related tickets became negligible, reducing the operational burden associated with supporting employees’ credential-management needs.
-
The CIO at a professional services organization reported that password-related ticket resolution time decreased by 38%, response time improved by 49%, and first-contact resolution rates increased by 55%. Average closure times for password-related tickets fell from approximately 12 hours to 8 hours. Interviewees also noted that support requests became less urgent and less disruptive. The CISO at an e-commerce organization explained: “The nature of our tickets changed dramatically. Previously, users were opening urgent tickets because they couldn’t access passwords and couldn’t do their jobs. Today, most requests are routine permission or vault-management tasks.”
-
The CISO at a technology organization reported a 70% reduction in credential-management-related support requests following deployment and estimated a 30% to 40% reduction in post-offboarding credential access requests because credential access became directly tied to lifecycle management processes.
-
Interviewees also reported reducing the administrative burden associated with managing and supporting previous password management solutions. The CISO at an e-commerce organization noted: “The maintenance cost of our previous password manager was actually higher than the licensing cost. With 1Password, that support burden largely disappeared.”
Modeling and assumptions. Based on the interviews, Forrester assumes the following about the composite organization:
-
3,000 employees generate credential-related support requests annually.
-
Each employee generates an average of two credential-related support requests per year.
-
After EPM, credential-related support requests decrease by 70%.
-
IT personnel spend an average of 20 minutes resolving each credential-related support request.
-
For the remaining credential-related tickets, the composite reduces average handling effort by 35%.
-
The composite has a 15% average employee attrition rate.
-
The composite organization recaptures 75% of the time saved by avoided and streamlined support activities.
-
The fully burdened hourly rate for an IT employee is $62.
-
Credential-related offboarding effort decreases by 40%.
Risks. The scale of this benefit may vary from organization to organization based on the following:
-
The volume of credential-related support requests prior to deployment.
-
Existing efficiency of password and access-management processes.
-
The degree of adoption and active use across employees.
-
Employee turnover rates and offboarding volumes.
-
IT labor costs and productivity recapture rates.
Results. To account for these risks, Forrester adjusted this benefit downward by 5%, yielding a three-year, risk-adjusted total PV (discounted at 10%) of $190,000.
70%
Reduction in credential-related tickets
35%
Reduction in handling effort for credential-related tickets
IT Operational Efficiency Lift
| Ref. | Metric | Source | Year 1 | Year 2 | Year 3 | |
|---|---|---|---|---|---|---|
| A1 | Employees generating credential-related support requests annually | Composite | 3,000 | 3,000 | 3,000 | |
| A2 | Credential-related tickets per employee per year | Composite | 2 | 2 | 2 | |
| A3 | Annual credential-related tickets | A1*A2 | 6000 | 6000 | 6000 | |
| A4 | Reduction in credential-related tickets | Interviews | 70% | 70% | 70% | |
| A5 | Average IT handling time per ticket (minutes) | Composite | 20 | 20 | 20 | |
| A6 | Productivity recapture rate | Composite | 75% | 75% | 75% | |
| A7 | Fully burdened hourly rate for an IT employee | Composite | $62 | $62 | $62 | |
| A8 | Subtotal: IT help desk time saved from avoided tickets | A3*A4*(A5/60)*A6*A7 | $65,100 | $65,100 | $65,100 | |
| A9 | Remaining credential-related tickets | A3-(A3*A4) | 1,800 | 1,800 | 1,800 | |
| A10 | Reduction in handling effort for remaining credential-related tickets | Interviews | 35% | 35% | 35% | |
| A11 | Subtotal: Reduction in handling effort for remaining credential-related tickets | (A5/60)*A6*A7*A9*A10 | $9,765 | $9,765 | $9,765 | |
| A12 | Annual employee departures | 3,000*15% | 450 | 450 | 450 | |
| A13 | Credential-related offboarding effort per employee (minutes) | Composite | 30 | 30 | 30 | |
| A14 | Reduction in credential-related offboarding effort | Interviews | 40% | 40% | 40% | |
| A15 | Subtotal: IT time saved from streamlined offboarding | A7*A12*(A13/60)*A14 | $5,580 | $5,580 | $5,580 | |
| At | IT operational efficiency lift | A8+A11+A15 | $80,445 | $80,445 | $80,445 | |
| Risk adjustment | ↓5% | |||||
| Atr | IT operational efficiency lift (risk-adjusted) | $76,423 | $76,423 | $76,423 | ||
| Three-year total: $229,268 | Three-year present value: $190,052 | |||||
Improved Employee Productivity
Evidence and data. Interviewees reported that employees frequently lost time locating passwords, accessing shared credentials, navigating non-SSO applications, waiting for credential-related support, and recovering access when credentials were unavailable. According to interviewees, broader deployment of 1Password Enterprise Password Manager reduced these workflow interruptions by making credentials easier to find, enter, and share securely. Multiple interviewees connected improved usability and automated credential access with fewer disruptions, lower friction, and faster access to the applications employees needed to perform their jobs. Interviewees emphasized that productivity improvements were most pronounced among employees who regularly interacted with multiple applications, shared credentials, or systems not integrated with single sign-on.
-
The AI and security leader at a financial services organization reported that employees typically saved 30 to 40 seconds per credentialed login because they no longer needed to locate, remember, or manually enter passwords. The interviewee noted that employees routinely accessed multiple non-SSO applications each day — often two to four times daily — allowing these savings to accumulate over time. This interviewee explained: “With the browser extension and app, credentials are populated automatically. Employees don’t have to remember passwords, search for them, or risk locking themselves out.”
-
The CIO at a professional services organization reported that approximately 20% of their employees were power users who regularly accessed a larger number of SaaS applications and shared credentials. This interviewee estimated that these employees saved about 5 hours per month through simplified credential management and reduced dependency on IT support. The same interviewee noted, “The user experience is as simple as the browser tools people were already familiar with but with enterprise-grade security behind it.”
-
The CISO at an e-commerce organization reported that credential-related usability issues in the prior environment frequently prevented employees from accessing required applications and generated support requests. The interviewee noted that when those complaints disappeared after deployment, it represented a meaningful improvement in day-to-day employee workflows.
-
Interviewees also described improvements in collaboration and authentication experiences. The CISO at a technology organization noted: “The passkey workflow is extremely clean and removes a lot of friction, especially on mobile devices.”
Modeling and assumptions. Based on the interviews, Forrester assumes the following about the composite organization:
-
2,700 nondeveloper employees use 1Password Enterprise Password Manager. Developers are accounted for in the next benefit section.
-
Employees save an average of 55 minutes per month through more efficient credential access and management with 1Password
-
Employees recapture 25% of the time saved as productive work.
-
The fully burdened hourly rate for nondeveloper employees is $45.
-
Productivity gains remain consistent throughout the three-year analysis period
Risks. The scale of this benefit may vary from organization to organization based on the following:
-
The number of employees routinely accessing non-SSO applications.
-
The frequency of credential-related activities and password lookups.
-
Existing availability of single sign-on and password-management tools.
-
Employee adoption and active usage rates.
-
Productivity recapture rates across employee populations.
Results. To account for these risks, Forrester adjusted this benefit downward by 10%, yielding a three-year, risk-adjusted total PV (discounted at 10%) of $748,000.
55 minutes
Time saved per employee per month due to streamlined credential access
Improved Employee Productivity
| Ref. | Metric | Source | Year 1 | Year 2 | Year 3 | |
|---|---|---|---|---|---|---|
| B1 | Nondeveloper employees using 1Password EPM | Composite | 2,700 | 2,700 | 2,700 | |
| B2 | Time saved per employee from streamlined credential access (minutes per month) | Interviews | 55 | 55 | 55 | |
| B3 | Productivity recapture rate | TEI methodology | 25% | 25% | 25% | |
| B4 | Fully burdened hourly rate for a nondeveloper employees | Composite | $45 | $45 | $45 | |
| Bt | Improved employee productivity | B1*(B2/60)*12*B3*B4 | $334,125 | $334,125 | $334,125 | |
| Risk adjustment | ↓10% | |||||
| Btr | Improved employee productivity (risk-adjusted) | $300,713 | $300,713 | $300,713 | ||
| Three-year total: $902,138 | Three-year present value: $747,827 | |||||
Developer Productivity Lift
Evidence and data. Interviewees described credential access as a recurring source of friction that extended beyond password management and into the software development lifecycle. Manual requests, locally stored secrets, and credentials embedded in scripts could slow development work and introduce avoidable security concerns into CI/CD pipelines. Interviewees said 1Password Enterprise Password Manager allowed development teams to bring secure credential access into the workflows and tools they already used. Developers could access approved credentials through centralized vaults and command-line workflows, while applications and automation could retrieve secrets at runtime through Connect Server. Interviewees noted that this reduced the need to stop development work to locate, distribute, or manage credentials manually, helping teams create more streamlined CI/CD workflows and maintain development velocity without treating security as a separate step.
The resulting value extended beyond credential management itself. Interviewees described more streamlined CI/CD workflows, reduced dependency on manual credential distribution, improved adherence to secure development practices, and less disruption to development teams when managing secrets and application credentials. Several interviewees emphasized that developers could spend more time building and deploying software and less time managing access logistics. They also highlighted the growing importance of these capabilities as AI-assisted development, agentic workflows, and nonengineering application builders become more common, noting that controlled credential retrieval and secrets management will be increasingly important for securing these emerging environments. Interviewees provided the following evidence:
-
The AI and security leader at a financial services organization reported that development teams used 1Password to programmatically retrieve credentials and secrets at runtime rather than managing them manually. The interviewee explained: “Developers can retrieve credentials dynamically at runtime without storing them locally, sending them through email, or embedding them into scripts. That improves both productivity and security.”
-
The CIO at a professional services organization estimated that developers saved between 2 and 6 hours per month because credential access and distribution workflows became more automated, reducing time spent managing access to development resources and secrets.
-
The CISO at an e-commerce organization reported that command-line integrations unlocked workflows that development teams could not perform with their organization’s previous password management solution. The interviewee explained: “Some teams use the CLI [command-line interface], which wasn’t available in our previous solution. For those users, 1Password unlocked functionality they simply didn’t have before.”
-
The AI and security leader at a financial services organization explained that development teams integrated secrets retrieval directly into CI/CD workflows. The interviewee noted: “For CI/CD pipelines, teams use 1Password to fetch and inject secrets programmatically. They no longer have to hard-code credentials, which was both a development burden and a security concern.”
Modeling and assumptions. Based on the interviews, Forrester assumes the following about the composite organization:
-
300 developers regularly use 1Password Enterprise Password Manager for credential and secrets management activities.
-
Developers save an average of 165 minutes per month on credential-related activities, including retrieving, managing, and accessing credentials required for development and automation workflows.
-
Only 50% of the recovered time is recaptured for productive work, consistent with Forrester’s standard productivity recapture methodology.
-
The fully burdened hourly rate for a developer is $78.
Risks. The scale of this benefit may vary from organization to organization based on the following:
-
The number of developers actively using credential and secrets management capabilities.
-
Existing maturity of development workflows and automation processes.
-
The frequency of credential-related activities performed by developers.
-
Adoption rates of developer-focused capabilities such as runtime credential retrieval and workflow integrations.
-
The degree of existing standardization across development, DevOps, and automation teams.
Results. To account for these risks, Forrester adjusted this benefit downward by 10%, yielding a three-year, risk-adjusted total PV (discounted at 10%) of $864,000.
165 minutes per month
Time saved per developer on credential-related activities
Developer Productivity Lift
| Ref. | Metric | Source | Year 1 | Year 2 | Year 3 | |
|---|---|---|---|---|---|---|
| C1 | Developers regularly using 1Password EPM for credentials and secrets | Composite | 300 | 300 | 300 | |
| C2 | Time saved per developer on credential-related activities (minutes per month) | Interviews | 165 | 165 | 165 | |
| C3 | Productivity recapture | TEI methodology | 50% | 50% | 50% | |
| C4 | Fully burdened hourly rate for a developer | Composite | $78 | $78 | $78 | |
| Ct | Developer productivity lift | C1*(C2/60)*12*C3*C4 | $386,100 | $386,100 | $386,100 | |
| Risk adjustment | ↓10% | |||||
| Ctr | Developer productivity lift (risk-adjusted) | $347,490 | $347,490 | $347,490 | ||
| Three-year total: $1,042,470 | Three-year present value: $864,156 | |||||
Reduced Credential-related Security Risk
Evidence and data. Interviewees reported that limited visibility into credential usage, password reuse, credentials stored outside approved systems, and unmanaged access to third-party applications increased their exposure to credential-related security incidents. According to interviewees, deploying 1Password Enterprise Password Manager improved credential governance by centralizing password storage, increasing visibility into credential risks, strengthening access controls, and reducing reliance on insecure practices such as password reuse, plaintext credential storage, and unmanaged password sharing. Multiple interviewees also connected credential monitoring capabilities, breach detection, and stronger authentication practices with a measurable reduction in credential-related exposure. Rather than eliminating security incidents, interviewees said the solution improved their ability to identify, govern, and reduce credential risks across employees and third-party applications.
-
The CIO at a professional services organization reported a 60% reduction in reused passwords and a 40% increase in MFA adoption across third-party accounts. The interviewee said these improvements increased visibility into credential security and reduced exposure within applications outside their organization’s SSO environment. The same interviewee reported that credential-related exposure events declined from approximately 12 per year to roughly one annually after gaining visibility into third-party credentials and strengthening governance processes. As the interviewee noted, “Watchtower alerted us to exposed credentials before they turned into a breach of our internal systems.”
-
The AI and security leader at a financial services organization reported that prior to 1Password there was no formal process for managing standard-user credentials, leading employees to store passwords locally or in plaintext locations. The interviewee estimated that onboarding more than 20,000 employees onto 1Password substantially reduced organizational exposure to credential compromise and explained: “With more than 20,000 employees onboarded, we’ve significantly reduced the risk associated with passwords being stored outside a secure vault. Our goal is to extend that protection across the organization.”
-
The CISO at a technology organization reported that credential hygiene improved because employees had a simpler way to generate and store strong, unique credentials. The interviewee explained, “The things you stop worrying about are weak passwords and password reuse because users have an easy way to generate strong, unique credentials.”
Modeling and assumptions. Based on the interviews, Forrester assumes the following about the composite organization:
-
The organization faces an average annual breach exposure of nearly $2.1 million.4
-
Seventy-seven percent of breach exposure is associated with external attacks, remote-environment attacks, and internal incidents that involve credentials.5
-
Twenty-five percent of that credential-related exposure is addressable through enterprise password management.
-
Improved credential governance, password hygiene, visibility, and access controls reduce addressable credential-related risk by 20%.
Risks. The scale of this benefit may vary from organization to organization based on the following:
-
Existing credential governance and password management maturity.
-
The percentage of applications operating outside single sign-on environments.
-
The frequency of password reuse and unmanaged credential storage.
-
Adoption rates and credential-management policy compliance.
Results. To account for these risks, Forrester adjusted this benefit downward by 20%, yielding a three-year, risk-adjusted total PV (discounted at 10%) of $158,000.
20%
Reduction in addressable credential-related breach exposure
| Ref. | Metric | Source | Year 1 | Year 2 | Year 3 | |
|---|---|---|---|---|---|---|
| D1 | Total annual risk exposure to security breaches for the composite organization | Forrester research | $2,062,000 | $2,062,000 | $2,062,000 | |
| D2 | Percentage of breaches originating from external attacks targeting organizations, external attacks targeting remote environments, and internal incidents | Forrester research | 77% | 77% | 77% | |
| D3 | Percentage of those attacks addressable with 1Password EPM | Interviews | 25% | 25% | 25% | |
| D4 | Annual risk exposure addressable with 1Password EPM | D1*D2*D3 | $396,935 | $396,935 | $396,935 | |
| D5 | Reduced risk of exposure to breach costs from addressable attacks with 1Password EPM | Interviews | 20% | 20% | 20% | |
| Dt | Reduced credential-related security risk | D4*D5 | $79,387 | $79,387 | $79,387 | |
| Risk adjustment | ↓20% | |||||
| Dtr | Reduced credential-related security risk (risk-adjusted) | $63,510 | $63,510 | $63,510 | ||
| Three-year total: $190,529 | Three-year present value: $157,939 | |||||
Unquantified Benefits
Interviewees described additional benefits from 1Password Enterprise Password Manager that were valuable to their organizations but were not quantified for this study. These benefits extended beyond the operational and productivity improvements included in the financial analysis and contributed to broader security, governance, and employee outcomes.
-
Increased readiness for AI, automation, machine identities, and democratized development. Interviewees anticipated that the growth of AI systems, automation platforms, low-code development, and nonhuman identities would create new credential-management requirements. As more employees, business users, and AI-powered systems build applications and workflows, their organizations may need a scalable way to securely manage, retrieve, distribute, and govern access beyond traditional workforce use cases. Interviewees discussed the potential to expand 1Password EPM beyond password management to support AI agents, automated workflows, and emerging development environments that depend on secure access to credentials and sensitive resources. As the AI and security leader at a financial services organization explained, “As we develop our agentic AI framework, 1Password is expected to play a role in securely managing and retrieving credentials for those environments.”
-
Enhanced employee experience and security culture. Interviewees reported that 1Password EPM made secure credential management easier and more intuitive for employees, reducing frustration while improving access to business applications. Several interviewees noted that strong usability drove adoption and helped employees embrace secure practices without disrupting their day-to-day work.
Beyond workplace productivity, interviewees also highlighted the value of extending password management capabilities into employees’ personal lives through EPM’s included personal and family accounts. They explained that these accounts helped employees build stronger security habits outside of work while increasing the perceived value of the investment as an employee benefit. The CISO at a technology organization told Forrester: “The personal and family accounts are a bigger value than most people realize. They help employees build better security habits beyond work.” -
Improved developer experience. Interviewees reported that 1Password Enterprise Password Manager reduced friction between security requirements and development workflows. They described improved developer satisfaction because secure credential and secrets management could be integrated into existing tools and processes rather than creating additional work. Several interviewees noted that the solution helped developer teams adopt secure practices without feeling constrained by security controls.
-
Stronger compliance, audit, and regulatory support. Interviewees said that centralized credential management improved visibility, governance, and oversight of credential access across their organizations. This strengthened support for audit processes and compliance initiatives while reducing the effort required to validate access controls and credential ownership. A CISO at an e-commerce organization reported reducing the effort associated with quarterly compliance and audit activities by several hours.
Flexibility
The value of flexibility is unique to each customer. There are multiple scenarios in which a customer might implement Enterprise Password Manager and later realize additional uses and business opportunities, including:
-
Just-in-time credential access and credential brokering. Several interviewees described continuing to mature their organizations’ identity and access strategies beyond traditional password management. Their organizations may expand the use of 1Password EPM to support more dynamic credential distribution, temporary access scenarios, secure runtime credential retrieval, and credential brokering across employees, applications, and automated workflows. As their organizations reduce reliance on static credentials, interviewees saw opportunities to extend 1Password’s role in securely delivering access when and where it is needed.
-
Support for passwordless authentication strategies. Several interviewees described passwordless authentication as a strategic priority over the coming years. Their organizations may expand their use of 1Password EPM to support passkey management, distribution, and adoption as they reduce reliance on traditional passwords. Interviewees viewed passwordless authentication as an opportunity to further improve user experience while strengthening security controls. The AI and security leader at a financial services organization explained, “As we move toward a passwordless strategy, 1Password is one of the key technologies being considered to securely manage and distribute passkeys.”
Analysis Of Costs
Quantified cost data as applied to the composite
Total Costs
| Ref. | Cost | Initial | Year 1 | Year 2 | Year 3 | Total | Present Value |
|---|---|---|---|---|---|---|---|
| Etr | Annual license cost | $0 | $264,600 | $264,600 | $264,600 | $793,800 | $658,021 |
| Ftr | Implementation, training, and ongoing management | $79,895 | $12,499 | $12,499 | $12,499 | $117,392 | $110,978 |
| Total costs (risk-adjusted) | $79,895 | $277,099 | $277,099 | $277,099 | $911,192 | $768,999 |
Annual License Cost
Evidence and data. Interviewees said their organizations incurred ongoing subscription costs for 1Password Enterprise Password Manager. Licensing covered employee password management, shared credential management, and, where deployed, developer-focused capabilities such as secrets management and secure credential automation. Interviewees generally viewed licensing as a recurring operational expense that scaled with user adoption and deployment scope. Pricing varies based on contract terms, licensed users, and purchased capabilities. Contact 1Password for additional details.
Modeling and assumptions. Based on the interviews, Forrester assumes the following about the composite organization:
-
The composite organization licenses 1Password Enterprise Password Manager for all 3,000 users at a 100% adoption rate. This includes 300 developers.
-
Licensing costs begin in Year 1 and continue through Year 3.
-
License costs include employee credential management and developer-focused use cases.
-
Pricing reflects enterprise subscription licensing as modeled for the composite organization.
Risks. The impact of this cost may vary by organization depending on the following:
-
The number of licensed users.
-
Contract structure and negotiated pricing.
-
Purchased product mix and functionality requirements.
-
Adoption rates across employee and developer populations.
-
Volume discounting and enterprise purchasing arrangements.
Results. To account for these risks, Forrester adjusted this cost upward by 5%, yielding a three-year, risk-adjusted total PV (discounted at 10%) of $658,000.
3,000
Number of users licensed across employee and developer use cases
Annual License Cost
| Ref. | Metric | Source | Initial | Year 1 | Year 2 | Year 3 |
|---|---|---|---|---|---|---|
| E1 | 1Password EPM license cost | Composite | $252,000 | $252,000 | $252,000 | |
| Et | Annual license cost | E1 | $0 | $252,000 | $252,000 | $252,000 |
| Risk adjustment | ↑5% | |||||
| Etr | Annual license cost (risk-adjusted) | $0 | $264,600 | $264,600 | $264,600 | |
| Three-year total: $793,800 | Three-year present value: $658,021 | |||||
Implementation, Training, And Ongoing Management
Evidence and data. Interviewees dedicated internal IT, security, and business resources to implementing, rolling out, and managing 1Password. Effort typically included deployment planning, testing, user communications, training, migration support, and ongoing administration.
-
Several interviewees described relatively streamlined deployments due to the product’s ease of use and strong employee adoption. A CISO at an e-commerce organization noted that their organization migrated approximately 2,000 employees within 60 days and that much of the effort centered on user enablement and change management.
-
Similarly, interviewees emphasized that communications, onboarding support, and targeted training helped drive adoption, while a small number of administrators continued to manage permissions, reporting, and ongoing user support following deployment. The CIO at a professional services firm said: “Most users became comfortable with 1Password within 20 to 30 minutes. Many were productive much faster than that.”
Modeling and assumptions. Based on the interviews, Forrester assumes the following about the composite organization:
-
Two IT and security professionals dedicate time to implementation, rollout, and adoption activities.
-
Implementation activities require approximately 160 hours per resource during deployment.
-
The composite organization trains 3,000 employees during the initial rollout.
-
Each employee spends approximately 25 minutes completing onboarding and training activities.
-
Ongoing administration requires approximately 16 hours per month across the analysis period.
-
Ongoing management activities include user administration, permissions management, reporting, and support.
-
Labor costs reflect fully burdened employee and administrator rates as modeled for the composite organization.
Risks. The impact of this cost may vary by organization depending on the following:
-
The organization’s size and deployment scope.
-
The number of employees requiring onboarding and training.
-
Existing familiarity with password management solutions.
-
Internal resource availability and administrative staffing models.
-
Complexity of identity, access management, and deployment requirements.
Results. To account for these risks, Forrester adjusted this cost upward by 5%, yielding a three-year, risk-adjusted total PV (discounted at 10%) of $111,000.
Implementation, training, and ongoing management
| Ref. | Metric | Source | Initial | Year 1 | Year 2 | Year 3 |
|---|---|---|---|---|---|---|
| F1 | Total time dedicated to implementation and adoption enablement per person (hours) | Composite | 160 | |||
| F2 | FTEs deploying 1Password | Composite | 2 | |||
| F3 | Fully burdened hourly rate for an IT employee | Composite | $62 | $62 | $62 | $62 |
| F4 | Subtotal: Implementation costs | F1*F2*F3 | $19,840 | |||
| F5 | Employees requiring training | Composite | 3,000 | |||
| F6 | Training time per employee (minutes) | Interviews | 25 | |||
| F7 | Fully burdened hourly rate for an employee | Composite | $45 | |||
| F8 | Subtotal: Employee training time | F5*(F6/60)F7 | $56,250 | |||
| F9 | IT time dedicated to ongoing management per month (hours) | Composite | 16 | 16 | 16 | |
| F10 | Subtotal: Ongoing management costs | F3*F9*12 | $11,904 | $11,904 | $11,904 | |
| Ft | Implementation, training, and ongoing management | F4+F8+F10 | $76,090 | $11,904 | $11,904 | $11,904 |
| Risk adjustment | ↑5% | |||||
| Ftr | Implementation, training, and ongoing management (risk-adjusted) | $79,895 | $12,499 | $12,499 | $12,499 | |
| Three-year total: $117,392 | Three-year present value: $110,978 | |||||
Financial Summary
Consolidated Three-Year, Risk-Adjusted Metrics
Cash Flow Chart (Risk-Adjusted)
Cash Flow Analysis (Risk-Adjusted)
| Initial | Year 1 | Year 2 | Year 3 | Total | Present Value | |
|---|---|---|---|---|---|---|
| Total costs | ($79,895) | ($277,099) | ($277,099) | ($277,099) | ($911,192) | ($768,999) |
| Total benefits | $0 | $788,135 | $788,135 | $788,135 | $2,364,405 | $1,959,974 |
| Net benefits | ($79,895) | $511,036 | $511,036 | $511,036 | $1,453,212 | $1,190,975 |
| ROI | 155% | |||||
| Payback | <6 months |
Please Note
The financial results calculated in the Benefits and Costs sections can be used to determine the ROI, NPV, and payback period for the composite organization’s investment. Forrester assumes a yearly discount rate of 10% for this analysis.
These risk-adjusted ROI, NPV, and payback period values are determined by applying risk-adjustment factors to the unadjusted results in each Benefit and Cost section.
The initial investment column contains costs incurred at “time 0” or at the beginning of Year 1 that are not discounted. All other cash flows are discounted using the discount rate at the end of the year. PV calculations are calculated for each total cost and benefit estimate. NPV calculations in the summary tables are the sum of the initial investment and the discounted cash flows in each year. Sums and present value calculations of the Total Benefits, Total Costs, and Cash Flow tables may not exactly add up, as some rounding may occur.
From the information provided in the interviews, Forrester constructed a Total Economic Impact™ framework for those organizations considering an investment in Enterprise Password Manager.
The objective of the framework is to identify the cost, benefit, flexibility, and risk factors that affect the investment decision. Forrester took a multistep approach to evaluate the impact that Enterprise Password Manager can have on an organization.
Due Diligence
Interviewed 1Password stakeholders and Forrester analysts to gather data relative to Enterprise Password Manager.
Interviews
Interviewed four decision-makers at organizations using Enterprise Password Manager to obtain data about costs, benefits, and risks.
Composite Organization
Designed a composite organization based on characteristics of the interviewees’ organizations.
Financial Model Framework
Constructed a financial model representative of the interviews using the TEI methodology and risk-adjusted the financial model based on issues and concerns of the interviewees.
Case Study
Employed four fundamental elements of TEI in modeling the investment impact: benefits, costs, flexibility, and risks. Given the increasing sophistication of ROI analyses related to IT investments, Forrester’s TEI methodology provides a complete picture of the total economic impact of purchase decisions. Please see Appendix A for additional information on the TEI methodology.
Total Economic Impact Approach
Benefits
Benefits represent the value the solution delivers to the business. The TEI methodology places equal weight on the measure of benefits and costs, allowing for a full examination of the solution’s effect on the entire organization.
Costs
Costs comprise all expenses necessary to deliver the proposed value, or benefits, of the solution. The methodology captures implementation and ongoing costs associated with the solution.
Flexibility
Flexibility represents the strategic value that can be obtained for some future additional investment building on top of the initial investment already made. The ability to capture that benefit has a PV that can be estimated.
Risks
Risks measure the uncertainty of benefit and cost estimates given: 1) the likelihood that estimates will meet original projections and 2) the likelihood that estimates will be tracked over time. TEI risk factors are based on “triangular distribution.”
Financial Terminology
Present value (PV)
The present or current value of (discounted) cost and benefit estimates given at an interest rate (the discount rate). The PVs of costs and benefits feed into the total NPV of cash flows.
Net present value (NPV)
The present or current value of (discounted) future net cash flows given an interest rate (the discount rate). A positive project NPV normally indicates that the investment should be made unless other projects have higher NPVs.
Return on investment (ROI)
A project’s expected return in percentage terms. ROI is calculated by dividing net benefits (benefits less costs) by costs.
Discount rate
The interest rate used in cash flow analysis to take into account the time value of money. Organizations typically use discount rates between 8% and 16%.
Payback
The breakeven point for an investment. This is the point in time at which net benefits (benefits minus costs) equal initial investment or cost.
Appendix A
Total Economic Impact
Total Economic Impact is a methodology developed by Forrester Research that enhances a company’s technology decision-making processes and assists solution providers in communicating their value proposition to clients. The TEI methodology helps companies demonstrate, justify, and realize the tangible value of business and technology initiatives to both senior management and other key stakeholders.
Appendix B
Endnotes
1 Source: Making The Business Case For Identity And Access Management, Forrester Research, Inc., March 20, 2025.
2 Source: The Forrester Tech Tide™: Identity And Access Management, Q1 2026, Forrester Research, Inc., January 29, 2026.
3 Total Economic Impact is a methodology developed by Forrester Research that enhances a company’s technology decision-making processes and assists solution providers in communicating their value proposition to clients. The TEI methodology helps companies demonstrate, justify, and realize the tangible value of business and technology initiatives to both senior management and other key stakeholders.
4 Cumulative breach costs are computed using the composite organization’s size (revenue or number of employees) as an input to a regression analysis of reported total cumulative costs for all breaches experienced by organizations that experienced at least one breach in the past 12 months. Source: Forrester’s Security Survey, 2025, “Using your best estimate, what was the total cumulative cost of all breaches experienced by your organization in the past 12 months?” Base: 1,740 global security decision-makers who have experienced a breach in the past 12 months. The cumulative breach cost is then multiplied by a 67% likelihood for organizations to experience one or more breaches in a given year. Source: Forrester’s Security Survey, 2025, “How many times do you estimate that your organization’s sensitive data was potentially compromised or breached in the past 12 months?” Base: 2,643 global security decision-maker.
5 Percentage of breaches by primary attack vector for breaches, as reported by security decision-makers whose organizations experienced at least one breach in the last 12 months. Source: Forrester’s Security Survey, 2025. “[Of the times that your organization’s sensitive data was potentially compromised or breached in the past 12 months, please indicate how many of each fall into the following categories below.]” Base: 1,766 global security decision-makers who have experienced a breach in the past 12 months.
Disclosures
Readers should be aware of the following:
This study is commissioned by 1Password and delivered by Forrester Consulting. It is not meant to be used as a competitive analysis.
Forrester makes no assumptions as to the potential ROI that other organizations will receive. Forrester strongly advises that readers use their own estimates within the framework provided in the study to determine the appropriateness of an investment in Enterprise Password Manager.
1Password reviewed and provided feedback to Forrester, but Forrester maintains editorial control over the study and its findings and does not accept changes to the study that contradict Forrester’s findings or obscure the meaning of the study.
1Password provided the customer names for the interviews but did not participate in the interviews.
Consulting Team:
Luca Son
Published
September 2026