Rotation dashboard screen

The Rotation dashboard is a read-only prioritization view built from credential inventory, audit records, and Active Directory agent actions. It does not schedule rotation, generate a replacement password, change an account, or rotate a secret automatically.

Data source, access, and license boundary

Rotation SLA uses Credential records from the active vault. It does not include Password or API key records or records from other vaults. Figures are calculated in the browser from records the signed-in user can read.

Owner, Admin, and User see credential figures when they can read the active vault; these need no Integration license feature. Auditor can open the dashboard and see audit-based information but cannot read vault secrets, so credential counts and SLA rows stay empty for that role. Executions drilldowns require Owner, Admin, or Auditor. Opening the credential inventory from a drilldown also requires the Integration feature in the current license.

Active Directory provider and agent-action figures are Owner-only, and the Rotation view does not load them itself. They appear only when an Owner has already opened a screen that loads them, and they can be out of date when you return to Rotation.

The dashboard has no separate license gate. A read-only license allows viewing and layout changes in this browser but blocks credential changes on other screens. The table’s Owner column is the item’s owner, not necessarily the VaultPilot Owner role.

What you can do here

  • Compare credential inventory with directory password actions and matching audit records.
  • Separate 61–90 day review candidates, records older than 90 days, and records without a readable date.
  • Open prepared credential or execution filters from supported flow cards.
  • Review event evidence without exposing generated, current, or previous passwords.
  • Compare the top site groups without treating the displayed date range as an active filter.
  • Refresh the data or adjust widget layout from Dashboard tools; Refresh alone does not guarantee current directory-action data.

How to read the widgets

Password rotation flow

These cards are related signals, not stages in one funnel. Their numbers come from different sources and do not add up:

CardCurrent calculationClick behavior
TotalRecent matching audit entries plus all loaded directory password actions.Display only.
ManagedCredential records linked to the directory, synced from AD, or already rotated.Opens Credentials with Managed.
Not managedCredential records not counted as managed.Opens Credentials with Not managed.
UpdatedLoaded directory actions that successfully set a temporary password or required a password change.Opens Executions with Directory / Completed.
ExpiredCredentials with expired risk or a revoked or disabled status.Opens Credentials with Expired or inactive.
WaitingAll loaded directory actions still pending or running, including non-password work.Opens Executions with Directory / Active.
ErrorDirectory password actions that failed or need review.Opens Executions with Directory / Failed.

Matching audit entries are password changes, passwords set by the founding Owner, and directory agent actions. Because Total combines audit entries with actions, one change can be counted more than once; it is not a count of distinct credentials.

Rotation SLA

Every readable Credential record falls into one fixed password-age band:

Visible bandCalculation
0–30 days30 days or less.
31–60 daysMore than 30 and no more than 60 days.
61–90 daysMore than 60 and no more than 90 days; the dashboard’s due band.
90+ daysMore than 90 days; the overdue band.
No dateNo readable date.

Age uses the first available date in this order: the AD password-last-set date, the record’s import date, then its last update. It does not use a next-rotation date or an organization-specific SLA. A future date counts as zero days; an unreadable date goes to No date.

The table shows only the few oldest records, then sorts by title. Records without a date come after dated ones. User shows - when the username is empty. Owner comes from the record’s owner, then the directory account, then the username; if all are empty, the cell is blank. Bars and rows are not clickable.

Password rotations

  • Audit events counts only the recent matching audit entries, not all-time events.
  • AD actions shows successful directory password actions out of all loaded ones; failed and review-needed actions need attention.
  • Pending work counts every loaded pending or running directory action. For Owner, Admin, and Auditor it opens Directory / Active when non-zero or Directory / All when zero. It is disabled for User.

The timeline mixes recent audit entries with recent directory password actions, sorted by time. Rows are display-only and never show password values.

Rotation by site

Only the top site rows are shown, largest total first, then by site name. The widget combines:

  • Credentials not linked to the directory, counted as Not managed and grouped by domain, host, or Local.
  • Directory password actions grouped by provider site, domain, provider name, or target and shown as Updated, Waiting, or Error.
  • The same recent audit entries, grouped by target. Password changes add to Updated; directory agent actions can raise the total without adding a colored segment.

The visible 45-day range is only a label; it does not filter the site figures. Segment totals can therefore be smaller than the row total. This chart is not a full 45-day compliance report, and site rows are not clickable.

Filters, drilldowns, and layout

Rotation has no date, owner, age, site, or status filter. Supported cards leave the dashboard and prepare a filter on Credentials or Executions. SLA bars and rows, timeline rows, and site rows are display-only.

Credential drilldowns clear existing filters and search before applying Managed, Not managed, or Expired or inactive. Execution drilldowns open Directory with Completed, Active, or Failed. Normal role and license rules still apply; clicking does not prove that an action ran.

Dashboard tools opens this guide, refreshes data, or enters layout edit mode. Edit mode supports drag-and-drop or arrow-key reordering, hide and restore, save, cancel, and reset. Layout is stored in this browser and changes presentation only. If all widgets are hidden, use Restore category widgets.

Rotation policy and monitoring

Configure rotation on an Active Directory record supports daily, weekly, monthly, and custom intervals. A custom interval is 1–365 days, 1–52 weeks, or 1–12 months and needs a start date. Monthly runs can use day 1–31 or the last day; a day a shorter month lacks moves to that month’s last day. The policy keeps its time zone, does not run twice across daylight-saving changes, and does not catch up missed runs in bulk.

Optional triggers can run 5–1440 minutes after a secret is revealed, or when the AD password reaches an age of 1–365 days. With several triggers on, whichever comes first runs. The agent encrypts the new password for the user; only an authorized browser with the vault unlocked can store it in the vault record. An uncertain result is not retried blindly.

This dashboard is not a bulk policy editor. Open the policy from its record and follow current and upcoming runs under Tasks > Scheduled, including next run, last outcome, related execution, and logs.

Data freshness and limits

Refresh updates only the visible Rotation figures and drilldowns. It does not reload the browser or refresh Integrations, Active Directory actions, Tasks, or other dashboards. For current directory evidence, open Integrations > Active Directory or Tasks > Scheduled and refresh there.

There is no single last-updated time; values can change as data finishes loading.

The dashboard does not prove that a credential is still used, that a target accepted a new password, or that rollback works. A succeeded agent action and an audit entry each prove only that the step was recorded. Neither is a real sign-in test on the target.

Review due, overdue, and missing-date credentials

  1. Read 61–90 days, 90+ days, and No date separately.
  2. Use the oldest-records table only as a starting point.
  3. On Credentials, confirm owner, account, target, source, the real last-change evidence, dependencies, and rollback.
  4. Use the organization’s approved change process; open the policy from the record and follow its run in Tasks.
  5. After an authorized change elsewhere, refresh and confirm the date and evidence changed.

Investigate failed or waiting directory work

  1. Select Error, Waiting, or Pending work.
  2. In Executions, check category, state, provider, target, times, and the general error.
  3. Compare execution and audit evidence without counting the same change twice.
  4. Retry, cancel, or create work only from the authorized screen.

Repair missing owner or date metadata

  1. Treat No date, -, or a blank owner as incomplete evidence, not a healthy state.
  2. Open the credential and find the missing date or owner field.
  3. When the vault is writable and access permits, correct the details without putting secrets in notes.
  4. Refresh and confirm the expected band and responsible person.

Screen states

StateOperator response
RefreshingWait; parts of the data can finish at different times.
No credential recordsCheck the active vault and vault-read access. The Integration feature is not required for these figures; Password and API key records do not count toward SLA.
61–90 daysTreat as due for review, then check the organization’s actual policy.
90+ daysTreat as overdue for review; do not rotate without owner, dependency, and rollback context.
No dateCheck the AD password-last-set date, import date, and update date. There is no next-rotation-date field.
Missing ownerFill in the owner, directory account, or username before assigning work.
Failed / stale reviewOpen Failed executions and inspect the general error.
WaitingOpen Active directory executions and separate password actions from other queued work.
No activityNo matching evidence is loaded; this does not prove credentials are current.
No site dataCheck the credential inventory. Owner-only directory figures may be missing or out of date because Rotation does not load them. This is not a live scan.
Hidden widgetsRestore individual widgets in edit mode or restore the category.
AuditorAudit-based information can appear; credential inventory and SLA rows stay empty.
Read-only licenseViewing and layout in this browser stay available; credential changes stay blocked.

Before you act

  • Confirm the active vault and your role. If directory-action evidence matters, have an Owner refresh it from Integrations or Tasks before relying on the counts.
  • Treat the widgets as different evidence sets, not one reconciled total or sequential flow.
  • Check the real date before relying on a due or overdue band.
  • Confirm owner, target, dependencies, maintenance window, rollback, and recovery route.
  • Use Executions and Audit Log for action evidence; use the credential record for inventory details.
  • Clicking a card never rotates, retries, approves, or schedules anything.

Safe evidence

  • Safe to share: age band, broad action state, redacted site type, general error, and broad time window.
  • Keep private: title, username, owner, directory account, domain, host, provider, site, audit target, action ID, exact time, and customer dependencies.
  • Never share: current, previous, temporary, or generated passwords; tokens; recovery codes; command output that contains credentials; or screenshots showing secrets.
  • Mask rare site labels and exact counts that could identify a customer or account. Cropping alone is not enough.

When to stop and escalate

Stop when ownership is unknown, dates conflict, a future or malformed date changes priority, action and audit evidence disagree, a generated password may be exposed, the target cannot be tested safely, or rollback is unknown. Email support@vaultpilot.io with the broad age band, redacted action state, general error, broad time window, and last safe step, without secret material.

Operator notes

Rotation is a monitoring and drilldown dashboard. Its age bands are fixed calculations in the browser, not a configurable SLA engine or next-rotation scheduler. Its cards do not rotate passwords, create directory actions, test sign-ins on the target, or certify compliance.

Back to Documentation