Security Center

Workspace-level controls for authentication strength, session lifetime, network restrictions, and audit visibility.

Posture overview

The top of /app/security shows four tiles:

  • SSO — connected / not connected.
  • MFA enforcement — on / off, with the count of members currently enrolled.
  • Member count — quick view of the workspace size.
  • Audit activity — events recorded in the last 30 days.

Policies

Require MFA

When on, members without an active TOTP enrollment cannot access workspace resources until they enroll. Owners are exempt to prevent lockout.

Session lifetime

  • Idle timeout — minutes of inactivity before re-auth. Default 60, range 5–1440.
  • Maximum session length — hours before a full re-sign-in is required. Default 24, range 1–720.

IP allowlist

Optional CIDR list. When non-empty, API calls and sign-ins from outside the allowed ranges are blocked. Use with care — misconfiguration locks out the whole workspace.

Audit feed

Recent security events appear at the bottom of the page. Filterable by event type and actor. Full retention is plan-dependent — see Billing & credits.

What we record
Member invites, role changes, secret rotations, policy edits, package downloads, sign-ins, and failed sign-in attempts.

Best practices

  • Enable MFA enforcement before adding members outside your core team.
  • Use SSO for any workspace above ~10 members.
  • Restrict IPs only after testing from every office you have, including VPN exit points.
  • Review the audit log monthly; export to CSV from Settings → Activity.
Was this page helpful?Send feedback →