Last verified: 2026-05-19
Security overview
Tenant security settings, auditability, device trust, and network controls.
Hub route
/admin/security — Security Dashboard
Staff mirrors under /staff/security/* when permitted.
Sub-areas
| Area | Route | Plan feature | Purpose |
|---|---|---|---|
| Settings | /admin/security/settings | — | Password policies, session rules |
| Audit logs | /admin/security/audit | enableSecurityAuditLogs | Who did what, when |
| Trusted devices | /admin/security/devices | — | Device registration/trust |
| Network restrictions | /admin/security/network | enableNetworkRestrictions | IP allow/block lists |
| Network exemptions | /admin/security/network-exemptions | enableNetworkRestrictions | Exceptions to rules |
Steps — review audit activity
- Open Security → Audit (or
/admin/security/audit). - Filter by user, action, or date.
- Investigate suspicious changes (staff role edits, payout setting changes).
Steps — restrict by IP (optional)
- Enable
enableNetworkRestrictionson plan. - Configure rules at
/admin/security/network. - Add exemptions for roaming admins at
/admin/security/network-exemptions.
Per-screen steps
Security settings (/admin/security/settings)
- Open Security → Settings.
- Review password complexity, session timeout, and MFA requirements.
- Save changes; notify staff if policies tighten.
Audit logs (/admin/security/audit)
- Requires
enableSecurityAuditLogson plan. - Filter by actor, resource, or date range.
- Export or screenshot entries for compliance tickets.
Trusted devices (/admin/security/devices)
- List devices that accessed the dashboard.
- Revoke trust for lost or unknown devices.
- Ask affected users to sign in again and re-register.
Network restrictions (/admin/security/network)
- Add allowlist CIDRs for office IPs.
- Test from allowed and blocked networks before enforcing block mode.
- Document fallback access via exemptions.