Security screen

The Security screen shows which record, behavior, or access signal deserves investigation rather than reducing security to one score. Every role can open it, while the data, drill-downs, and actions shown depend on the role.

The cards are built from vault, audit, license, update, integration, and execution data. Not every visual is interactive: button-shaped rows and metrics route to source screens, while chart bars and Risk breakdown are read-only. The single Dashboard tools menu opens documentation, refreshes data, and controls edit mode. There is no per-widget menu; hide and reorder controls appear only in edit mode.

Reading the dashboard

  • Security coverage: all ten weighted factors behind Command Center: 2FA, license, extension, update, password exposure, AD risk, completeness of certificate expiry-date metadata, execution history, directory-provider sync errors, and vault content. The certificate row is not a live validity test, and the directory row is not a general connectivity test. Each row shows earned/total weight and routes to its source.
  • Leak check: passwords grouped as exposed, clear, or not yet checked.
  • Risk breakdown: mixes three different counts: Healthy signals counts healthy score factors, while Watch items and Critical actions count recommendations by severity. They are not one incident or signal population, and the segments are not buttons.
  • Behavior analysis: the chart compares access, session, and administrative events. The Risk access rows beside it are clickable and open the specific Audit Log event.
  • Audit summary: the latest few events with actor, target, risk, and time. Only the button in the Event column opens that audit event.
  • Access trend: a read-only seven-day count of unlock, view, copy, fill, and integration-sync events. Day bars do not open a time filter.

Access and data requirements

Owner, Admin, Auditor, and User can open the dashboard, but some data and drill-down destinations stay empty, restricted, or disabled for roles without access. Auditors cannot open vault records. Revealing or copying requires a non-Auditor role with readable vault access; writing a vault record also requires Editor or Manager membership in the active vault and a writable license. System destinations apply their own role gates.

Investigation workflows

Respond to exposed passwords

  1. Select the exposed count, donut, or matching status row in Leak check.
  2. On Passwords, confirm the prepared exposure filter and the record owner.
  3. Change the credential in its source system first, update the VaultPilot record, and run the check again.

Completion means the old value is invalid and the replacement returns a clear result. Stop if the source system cannot be changed or ownership is unknown; changing only the vault copy does not contain the exposure.

Explain an access spike

Identify the day and total behind the increase. The chart does not split event types and its bars are not clickable. Because Audit summary contains only the latest few events, use the main navigation to open Audit Log for detailed time and action filters; use a Risk access row or Event button for a specific event. The increase should match an approved task or an explainable user action; otherwise review session and account security through your incident process.

Correlate a critical risk with audit activity

Risk breakdown is summary-only, so its critical segment does not open detail. Note the count, then use a Behavior analysis > Risk access row or the Audit summary event button to open the source. Do not assume both cards describe the same event; compare redacted time, action class, and target type. If they disagree, refresh once and pause further changes until the source is verified.

Screen states

StateOperator response
LoadingDo not interpret scores, ratios, or trends until all relevant widgets settle.
HealthyConfirm coverage and unchecked records, then record the review; there is no single global last-refresh timestamp on this screen.
WatchOpen the card, verify the destination record or event, and assign follow-up.
CriticalContain potentially affected access first, then investigate record and audit detail privately.
EmptyBefore reporting no activity, check the active vault, time window, filters, and widget visibility.
Unchanged after refreshDo not look for a global freshness timestamp; check the widget’s source and the destination screen’s data.
Permission limitedVerify role and vault membership when drill-down is unavailable; do not grant broad access as a shortcut.
ErrorPreserve the message and time, and do not report a partial widget as full coverage.

Before you act

  • Confirm the time window and source represented by the widget.
  • Do not treat exposure status as a risk label, or access trend as an audit event; verify each at its source.
  • Before clearing a prepared filter, note which dashboard signal opened it.
  • Confirm vault role and writable license state before editing a record.
  • Hiding a widget in edit mode does not remove its data or risk; restore the hidden component from that mode when needed.

Safe evidence

  • Safe to share: broad risk level, signal category, redacted event class, time range, last check time, and remediation steps taken.
  • Keep private: usernames, vault names, real record titles, URLs, internal hosts and domains, full access timelines, and any image showing secret material.
  • Never include a value found by the exposure check as an example. If a real password is exposed, change it in the source system before discussing the case.

When to stop or escalate

Escalate when a critical signal survives refresh, access trends conflict with audit records, several users or vaults may be affected, or dashboard data remains stale. Send support@vaultpilot.io the version, timezone-qualified time, widget name, redacted error, and attempted steps.

Operator notes

This dashboard supports investigation; the authoritative detail remains in the underlying record or Audit Log. A healthy color does not prove that every password was checked. Exposure coverage is incomplete while unchecked records remain.

Back to Documentation