slug: 1password provider: 1Password generated_by: planning/capability-mapping/scripts/classify_capabilities.py model: claude-opus-5 frame: - Software & Technology min_confidence: 0.7 capability_model: source: https://github.com/vincentmakes/turbo-ea-capabilities license: CC-BY-4.0 attribution: Turbo EA Capabilities by Vincent Verdet — Turbo EA, https://github.com/vincentmakes/turbo-ea-capabilities, CC BY 4.0 notice: NOTICE edge_count: 2 edges: - tag: Audit Events spec_file: 1password-audit-events-api-openapi.yml capability_id: BC-620.30 capability_id_l1: BC-620 capability_name: Threat Detection & Response Management confidence: 0.72 evidence: It enables security teams and administrators to retrieve sign-in attempts, item usage records, and audit events for monitoring, compliance, and security analysis reason: Audit event streaming explicitly aimed at security monitoring feeds SOC/SIEM threat detection and response. - tag: Accounts spec_file: 1password-accounts-api-openapi.yml capability_id: BC-4240.30 capability_id_l1: BC-4240 capability_name: Subscription Provisioning confidence: 0.7 evidence: The 1Password Partnership API enables partners to manage the provisioning and deprovisioning of third-party partner billing accounts for customers reason: Operations create, update expiration, and delete partner billing accounts — i.e. provisioning/termination of customer subscriptions via a partner channel. Sub-capability choice between provisioning and cancellation is somewhat ambiguous.