Security
Sign-in activity, an audit log, active sessions, a security posture score, two-factor authentication and single sign-on.
Security blocks show who is getting in, what changed and how well the workspace is set up. Severities and check results each have an icon and a label, so colour never carries them alone. Pass fixed dates, so the blocks render the same on the server and in the browser.
Sign-in Activity
Succeeded, failed and blocked sign-ins per day, with the failure rate, spikes in blocked attempts and MFA coverage.
- Failed or blocked
- 6.8%
- 1,894 of 27,704
- Blocked
- 588
- Spike on Sep 19 and Sep 20
- Users with MFA
- 87%
- Succeeded
- Failed
- Blocked
| Day | Succeeded | Failed | Blocked |
|---|---|---|---|
| Sep 13 | 1820 | 96 | 12 |
| Sep 14 | 910 | 51 | 8 |
| Sep 15 | 2140 | 118 | 15 |
| Sep 16 | 2260 | 104 | 11 |
| Sep 17 | 2190 | 131 | 9 |
| Sep 18 | 2230 | 99 | 14 |
| Sep 19 | 2010 | 92 | 188 |
| Sep 20 | 980 | 48 | 242 |
| Sep 21 | 870 | 55 | 31 |
| Sep 22 | 2310 | 121 | 17 |
| Sep 23 | 2280 | 108 | 12 |
| Sep 24 | 2350 | 116 | 10 |
| Sep 25 | 2270 | 103 | 13 |
| Sep 26 | 1190 | 64 | 6 |
Audit Log
Changes to access, keys and settings, newest first, with a toggle to show warnings only.
- Info
Kenji Mori created an API key CI deploys
203.0.113.24 - Warning
Ana Lima changed the role of Dana Kim to Admin
198.51.100.7 - Critical
Ana Lima turned off SSO enforcement
198.51.100.7 - Info
Sara Okafor invited tom@example.com
192.0.2.61 - Info
Kenji Mori exported the audit log
203.0.113.24 - Warning
Sara Okafor revoked the API key Old staging token
192.0.2.61
Active Sessions
The devices signed in to an account, with where and when each was last active, and buttons to sign them out.
- Chrome on macOSThis deviceLisbon, Portugal · active now
- Safari on iOSLisbon, Portugal ·
- Firefox on WindowsPorto, Portugal ·
- Chrome on AndroidMadrid, Spain ·
Security Posture
A weighted score from workspace checks, with failing checks first and what to do about each.
- FailingSSO enforcedTurned off 35 minutes ago
- Needs attentionMulti-factor authentication87% of members, 4 admins without it
- Needs attentionAPI keys rotated2 keys unused for over 90 days
- PassingAudit log streamingLast 30 days exported to your SIEM
- PassingInvite restrictionsOnly from approved domains
- PassingSession timeoutSessions expire after 12 hours
Two-Factor Authentication
Set up an authenticator app with a QR code and a 6-digit code, add security keys and passkeys, and get recovery codes that are shown once. When the workspace requires two-factor, the last method can't be removed.
- Authenticator appCodes from an app like 1Password, Authy or Google Authenticator.
- Security keys and passkeysA hardware key, or your device’s fingerprint or face unlock.
- YubiKey 5CAdded
- MacBook Touch IDAdded
- Recovery codes8 left. Each works once, if you lose your other methods.
Single Sign-On
A SAML connection with the details to copy into your identity provider, domains verified by TXT record, and a switch to require SSO once a domain is verified.
Add these to your identity provider
https://app.acme.co/sso/saml/acshttps://app.acme.co/sso/saml/metadata/ws_4f9aDomains
People with an email at a verified domain sign in with SSO.
- acme.coVerified
- acme.ioNot verifiedAdd this TXT record to acme.io’s DNS, then verify.
acme-verify=b81d04c6fa