The Domain dashboard brings four widgets with different data sources into one view. They draw on the DC Agent sync and selected directory scope, RDP/SSH records in the vault, credential-access audit events, directory work, and browser sessions that may already be loaded. These sources do not share one scope or refresh time, and their totals are not a full inventory of Active Directory.
Domain is mainly a review view. Some cards open a filtered destination, while other figures are read-only. A populated widget has no general Open related view menu; that link may appear only in a compact empty state. In populated views, use a card shown as a button or navigate to the destination from the sidebar.
The four widgets
Domain inventory
Shows the live-agent ratio, user, group/OU, and risk figures together with provider name, last seen and sync time, and selected sign-in and credential counts. Its data loads only for Owners. Topology, figures, and provider rows inside this widget are read-only; use the sidebar for Integrations > Active Directory.
Domain sync health
Clickable Users, Groups, and OUs rows open the matching directory-tree filter under Integrations; they are disabled when the count is zero or you are not an Owner. Computers, Privileged, and Stale rows are read-only. The Agent queue card counts pending and running directory actions and opens Executions when non-zero and you may view system screens. Other scope cards and agent-health rows are informational.
Remote sessions
Clickable RDP and SSH cards combine vault credential counts with audit access events and open Active Directory Records with the matching protocol filter. AD login is a read-only count of the selected scope. Agent queue comes from directory actions and may open Executions. The access chart comes from audit events; browser-session rows appear only if an authorized security screen already loaded them, because Domain does not load sessions itself. Use Sign-In Security for a current session review.
Credential lifecycle
This widget comes from Active Directory credential records in the vault and their audit access events, not from selected directory scope. Credentials, Managed, Expired, and Information cards open Active Directory Records with the matching filter. In use and Updated cards are read-only. There is no Unmanaged lifecycle figure. Access charts and the device, credential, last-view, and total table are also read-only.
Access, data, and agent capabilities
Directory-provider data loads only for Owners. If an Admin, Auditor, or User opens the dashboard, empty or zero values mean data was not loaded because of permission, not “no agent exists.” Even as Owner, wait for loading to finish before reading an empty state.
The capabilities the agent reports limit both data and actions. Inventory needs the agent’s inventory capability; password-state information needs Password state. Unlock, require-password-change, and random-password actions need Unlock account, Require password change, and Assign random password now respectively. When a capability is missing, zero or missing data does not mean healthy; it may not have been collected. Account actions also need a CONNECTED agent, a writable license, the Owner role, and a target that is not marked privileged.
Recommended review workflows
Verify agent health
- Read the live-agent ratio, provider state, and last seen and sync times in Domain Inventory.
- Read the state in order: when the agent is not CONNECTED, labels such as STALE, OFFLINE, AWAITING, or REVOKED are shown. For a connected agent, ERROR comes first, then SYNCING; only a connected, error-free, idle agent with a waiting request shows SYNC QUEUED.
- For a disconnected or error state, open Integrations > Active Directory from the sidebar and inspect the provider card.
A healthy agent shows CONNECTED with advancing last-seen and sync times. Stop imports and scope changes while those times stay old.
Reconcile selected scope with counts
Open a clickable Users, Groups, or OUs row in Domain Sync Health and inspect the prepared filter under Integrations. Computers are read-only; go to Integrations for computer scope. For an unexpected increase or decrease, compare the last successful sync and the reported capabilities. You are done when the change is explained by an approved scope update or a confirmed problem in Active Directory.
Investigate an RDP/SSH signal
Select a non-zero RDP or SSH card and confirm the protocol filter on Active Directory Records. Review source, risk label, and last sync time there. Browser-session rows and the access chart do not open detail; they are summaries only.
Review lifecycle state
Open only Credentials, Managed, Expired, or Information, then confirm the filtered list. In use, Updated, and the access table are summaries only. Do not manually recreate a record synced from Active Directory. When the record and directory object disagree, pause bulk work until sync completes.
Screen states
| State | Operator response |
|---|---|
| Loading | Do not read totals or empty states until the Owner data finishes loading. |
| CONNECTED | When no error, sync, or request is active, confirm the times advance and the needed capabilities are reported. |
| ERROR | On a connected agent, error is shown before sync and queue labels; inspect the provider’s latest error. |
| SYNCING | Appears only for a connected, error-free agent; wait for the current sync. |
| SYNC QUEUED | Appears only for a connected, error-free, idle agent with waiting work; follow it in Executions. |
| AWAITING | Do not import or run account actions before the agent first checks in. |
| STALE | Check the agent service, whether VaultPilot is reachable, and the latest provider error. |
| OFFLINE | Stop new directory work and collect service and connection evidence privately. |
| REVOKED | Do not reuse the old agent token; follow the Owner-approved enrollment or repair path. |
| Empty by permission | For a non-Owner role, never report zero as no agent; hand the review to an Owner. |
| Capability missing | Treat the data or action as unsupported, not as a healthy zero. |
| Error | Keep the last successful sync time and avoid repeated scope changes that hide the first failure. |
Before you act
- Confirm you are the Owner, the provider data finished loading, and the times are current.
- Judge agent health together with the last successful sync.
- Confirm the agent reports the capability needed for the data or action.
- Tell a read-only figure apart from a clickable filter card.
- For credential import, confirm the active vault is unlocked and writable.
- Do not force account actions against privileged accounts; use the approved Active Directory administration path.
Safe evidence
- Safe to share: agent health, age of last seen and sync, anonymized totals by object type, queue state, reported capability name, and an error message without personal data.
- Keep private: domain and domain-controller names, distinguished names, OU and group paths, bind account, agent token, real user lists, RDP/SSH targets, and directory-tree screenshots.
- If logs are required, remove user, domain, IP, token, and LDAP detail. If full redaction is not possible, do not send the logs.
Escalation
Escalate to directory operations when an agent cannot return to CONNECTED, SYNCING or the queue does not advance, selected scope changes unexpectedly, a needed capability disappears, or this screen disagrees with Active Directory Records. Include the agent version, broad health state, times with their time zone, the redacted error, and the preflight steps you tried.
Operator notes
Object counts are capacity and health signals, not an identity inventory. Active Directory and the agent are the source of truth for directory-synced credential records. Creating the same record manually risks duplicates and wrong rotation.