Security Command Center Screen

The Security Command Center screen brings the security score, priority recommendations, server readiness, and operational signals into one workspace. Every system role can open it; visible data and destination actions narrow by role. It is not an incident report or change approval by itself.

Command Center is primarily a routing surface. Selecting a recommendation or factor opens the relevant Passwords, Active Directory Records, Sign-In Security, Integrations, License, or Update Center view and applies a filter when one is available.

What you can see

  • Security score: calculated from ten weighted factors: 2FA, license mode, browser extension, Update Center, password exposure checks, Active Directory risk, completeness of certificate expiry-date metadata, failed executions, sync errors reported by directory providers, and vault content. The certificate factor is not a live validity/expiry test, and the directory factor is not a general connectivity test. A score is not a verdict.
  • Critical and watch recommendations: the main surface shows two critical and two watch rows. More recommendations (n) opens the rest of the prioritized queue; its rows also route to their source screens.
  • Score sources and dashboard sections: direct routes into Security, Domain, Certificates, and Rotation dashboards.
  • Current operation signals: live summaries such as file quota, execution state, and update readiness.
  • Screen tools: refresh live data, open this documentation, and manage the dashboard view.

Access and prerequisites

Owner, Admin, Auditor, and User can open the screen, but some data, destinations, and actions stay empty, restricted, or disabled for roles without access. Opening vault records requires an unlocked vault and access to its secrets; Auditors cannot open secret records. Read-only mode blocks creating and changing vault records. License and Integrations are Owner-only; Owner, Admin, and Auditor can view Server Settings, but only the Owner can change them.

Run the daily security review

  1. Read the score, earned/total weight, and open recommendation count together; this screen has no independent score-freshness indicator.
  2. Open the first item under Critical; VaultPilot routes to the relevant screen and applies a focused filter where appropriate.
  3. Confirm the underlying condition, complete the work on that screen, return, and refresh Command Center.

You are done when the signal is healthy or the follow-up has an owner. If the same recommendation remains after refresh, do not make repeated blind changes. Inspect the source screen’s error and timestamp first.

Explain a score decrease

Select the lowest or warning-toned score source. Separate 2FA, license, extension, update, exposure, AD risk, certificate expiry metadata, execution history, directory-provider errors, and vault-content causes, then verify the source screen. Stop and check Server Settings or Executions if the score loss cannot be tied to one concrete control.

Turn a recommendation into owned work

Open the recommendation, verify the affected record or subsystem, and capture its owner and due time in the organization’s change process. Command Center recommendations have no hide or dismiss control. Completion means the source control is corrected and the recommendation leaves the queue after refresh.

Screen states

StateOperator response
LoadingWait for the cards to settle before interpreting a score or count; refresh once if loading is unusually long.
82–100The score is in the green band; still inspect open recommendations and each factor’s weight.
62–81The score is in the warning band; verify the highest-impact row at its destination.
0–61The score is in the critical band; contain direct access risks first and move the case to your incident process.
More recommendationsOpen the hidden queue; the first four rows may not represent all outstanding work.
Readiness signal missingOpen Profile, Active vault, 2FA, License, Extension, or Update Center and verify the source.
Permission limitedIf a destination or action is unavailable, verify the role and vault membership through the normal access process.
ErrorPreserve the message, time, and affected component; avoid repeated refreshes that erase the first useful evidence.

Before you act

  • Determine whether a signal concerns one vault, a user session, licensing, or a server subsystem.
  • Use the card’s own route so exposure and risk filters carry into the destination screen.
  • Before writing a vault record, confirm the active vault role is Editor or Manager and the license is not read-only. Server, license, and integration destinations apply their own system-role and license rules instead of this vault-role gate.
  • When several items are critical, handle direct access risks such as missing 2FA and known exposure first.
  • Treat Command Center counts as orientation, not final audit evidence; verify the relevant record, audit event, or execution result.

Safe evidence

  • Safe to share: the broad score band, recommendation category, affected VaultPilot component, redacted error code, observation time, and destination screen name.
  • Keep private: usernames, vault names, real record titles, internal domain and host names, customer counts, access timelines, and any screenshot that could reveal a secret.
  • If a screenshot is necessary, capture only the relevant card and redact navigation, user, host, and record context. Do not send what cannot be fully de-identified.

When to stop or escalate

Escalate internally when a critical signal returns after a verified fix, score sources cannot load, dashboard summaries conflict with audit evidence, or a risk affects several users. A support request should contain version, timezone-qualified timestamps, component, steps taken, and redacted errors—never secret values.

Operator notes

Command Center points to the work; it does not replace the destination screens and offers no recommendation-card hide control. Confirm the outcome in the target screen and, where relevant, in the Audit Log.

Back to Documentation