Security Overview
Security overview
Your organization's security posture at a glance.
MFA adoption
5 / 6
1 member without MFA
Email verified
6 / 6
all members
Active sessions
9
across 6 members
Failed logins
3
last 24 hours
Attention
MFA
Priya Tanaka has no MFA
Billing manager — recommend enforcing MFA.
Session
New sign-in from a new device
Dan Kowalski · San Diego · 18 hrs ago.
Quick links
About this page
Your account’s security posture in one view: who has two-factor on, whose email is verified, active sessions, and recent failed sign-ins. It’s the page to check when something feels off — and the jump-off to fixing it.
Behind this page/security · CanManageSecurity
Retrieve
One read fromsp_Builder_GetSecurityOverview (gated on CanManageSecurity): member MFA and email-verification posture plus every active session account-wide. Personal-plane session listing stays on sp_Builder_ListMySessions; recent events from sp_Builder_ListAuditLog.Save
Read-only. Revoking any listed session routes tosp_Auth_RevokeSession, which already permits admins with CanManageSecurity to revoke another member’s session.Success
- Posture aggregates three real readers.
- Failed-login and session data are live.
- MFA gaps are surfaced per member.
CLI handoff
Implement this scaffold from the structured contract, then remove hard-coded preview rows. The source of truth is CLI Handoff and admin-cli-manifest.json.
Page IDsecurity-overview
Route/security
AccessCanManageSecurity
Statusschema-backed-scaffold
Server-inject identity and scope values; never trust browser-supplied account, app, tenant, user, entitlement, price, or permission identifiers. Preserve the loading, empty, forbidden, failed, retrying, and completed states shown by the preview.