Dashboardblocks
Components

Security

Sign-in activity, an audit log, active sessions, a security posture score, two-factor authentication and single sign-on.

Security blocks show who is getting in, what changed and how well the workspace is set up. Severities and check results each have an icon and a label, so colour never carries them alone. Pass fixed dates, so the blocks render the same on the server and in the browser.

Sign-in Activity

Succeeded, failed and blocked sign-ins per day, with the failure rate, spikes in blocked attempts and MFA coverage.

Sign-in activity
Sign-in attempts per day, last 14 days
Failed or blocked
6.8%
1,894 of 27,704
Blocked
588
Spike on Sep 19 and Sep 20
Users with MFA
87%
  • Succeeded
  • Failed
  • Blocked
Sign-in activity: Sign-in attempts per day, last 14 days.
DaySucceededFailedBlocked
Sep 1318209612
Sep 14910518
Sep 15214011815
Sep 16226010411
Sep 1721901319
Sep 1822309914
Sep 19201092188
Sep 2098048242
Sep 218705531
Sep 22231012117
Sep 23228010812
Sep 24235011610
Sep 25227010313
Sep 261190646

Audit Log

Changes to access, keys and settings, newest first, with a toggle to show warnings only.

Audit log
Changes to access, keys and settings
  1. Info

    Kenji Mori created an API key CI deploys

    203.0.113.24
  2. Warning

    Ana Lima changed the role of Dana Kim to Admin

    198.51.100.7
  3. Critical

    Ana Lima turned off SSO enforcement

    198.51.100.7
  4. Info

    Sara Okafor invited tom@example.com

    192.0.2.61
  5. Info

    Kenji Mori exported the audit log

    203.0.113.24
  6. Warning

    Sara Okafor revoked the API key Old staging token

    192.0.2.61

Active Sessions

The devices signed in to an account, with where and when each was last active, and buttons to sign them out.

Active sessions
Devices signed in to your account
  • Chrome on macOSThis deviceLisbon, Portugal · active now
  • Safari on iOSLisbon, Portugal ·
  • Firefox on WindowsPorto, Portugal ·
  • Chrome on AndroidMadrid, Spain ·

Security Posture

A weighted score from workspace checks, with failing checks first and what to do about each.

Security posture
Workspace settings checked against recommended practice
At risk1 failing, 2 to look at
  • Failing
    SSO enforcedTurned off 35 minutes ago
  • Needs attention
    Multi-factor authentication87% of members, 4 admins without it
  • Needs attention
    API keys rotated2 keys unused for over 90 days
  • Passing
    Audit log streamingLast 30 days exported to your SIEM
  • Passing
    Invite restrictionsOnly from approved domains
  • Passing
    Session timeoutSessions expire after 12 hours

Two-Factor Authentication

Set up an authenticator app with a QR code and a 6-digit code, add security keys and passkeys, and get recovery codes that are shown once. When the workspace requires two-factor, the last method can't be removed.

Two-factor authentication
A second step at sign-in, so a password alone can’t get into your account.
On
  • Authenticator appCodes from an app like 1Password, Authy or Google Authenticator.
  • Security keys and passkeysA hardware key, or your device’s fingerprint or face unlock.
    • YubiKey 5CAdded
    • MacBook Touch IDAdded
  • Recovery codes8 left. Each works once, if you lose your other methods.

Single Sign-On

A SAML connection with the details to copy into your identity provider, domains verified by TXT record, and a switch to require SSO once a domain is verified.

Single sign-on
Let people sign in with your company’s identity provider over SAML.
Connected

Add these to your identity provider

ACS URL
https://app.acme.co/sso/saml/acs
Entity ID
https://app.acme.co/sso/saml/metadata/ws_4f9a

Your identity provider

Domains

People with an email at a verified domain sign in with SSO.

  • acme.coVerified
  • acme.ioNot verified
    Add this TXT record to acme.io’s DNS, then verify.
    acme-verify=b81d04c6fa
Require SSOEveryone at acme.co must sign in with Okta. Owners can still use a password.

On this page