> ## Documentation Index
> Fetch the complete documentation index at: https://docs.vibely.sh/llms.txt
> Use this file to discover all available pages before exploring further.

# Workspace security center

> Monitor your workspace security posture, scan results, dependencies, secrets, scheduled scans, and audit logs across every project.

The security center gives workspace owners and admins one place to watch security across every project, instead of opening projects one by one.

<Frame>
  <img src="https://cdn.vibely.sh/doc/v1/workspace-security-center.webp" alt="Workspace security center" width="1200" height="675" />
</Frame>

It has two parts:

* **Settings → Security center**: your workspace's security posture, SSO and SCIM status, scheduled scans, invitation restrictions, and recent activity.
* **The security dashboard** at `vibely.sh/security-center`: findings, dependency vulnerabilities, and secrets across all your projects, plus [Workspace Insights](/features/workspace/insights).

<Note>
  The security center and [audit logs](#audit-logs) are available on the **Business** plan, to workspace **owners and admins**.
</Note>

## Security posture

The top of **Settings → Security center** shows a score based on three checks:

| Check | Passes when |
| - | - |
| Workspace owner assigned | The workspace has an owner. |
| Single sign-on enabled | SSO is turned on. See [SSO](/features/workspace/sso). |
| Invitations restricted to allowed domains | **Restrict workspace invitations** is on with at least one allowed domain. See [Privacy & security](/features/workspace/privacy-security#restrict-workspace-invitations). |

Below the score you'll find:

* **Single sign-on**: the same SSO controls as the [Identity](/features/workspace/identity) page.
* **SCIM provisioning**: the SCIM base URL, the active token, and the default role for provisioned users. See [SCIM](/features/workspace/scim).
* **Scheduled scans**: see [Schedule security scans](#schedule-security-scans).
* **Invitation restrictions**: which email domains invitations are limited to, if any.
* **Workspace Insights**: click **Open Workspace Insights** to go to the security dashboard. See [Workspace Insights](/features/workspace/insights).
* **Audit log**: the 20 most recent significant actions in the workspace. Click an entry to see its details.

## The security dashboard

Open `vibely.sh/security-center`, or click **Open Workspace Insights** in **Settings → Security center**, to see scan results for every project in your workspace. The dashboard shows the workspace selected in the workspace switcher. It has four tabs, and **Export CSV** downloads whichever tab you're on.

### Workspace Insights

Every active project ranked by how urgently it needs a review, based on findings, publish status, ownership, activity, secrets, and credit use. See [Workspace Insights](/features/workspace/insights).

### Code Analysis

Open security findings for each active project (up to 200, most recently edited first), from every scanner: database access rules, database, code, dependencies, and sensitive data.

* **Summary cards**: number of projects, and open errors, warnings, and info findings across them.
* **Project list**: each project with its web or mobile type, when it was last scanned (or **Never scanned**), and its open findings by severity, sorted with the most severe first.
* **Triage**: opens that project's [security view](/features/security/project-view) to review and fix its findings.

### Supply Chain

Known vulnerabilities in the npm packages your projects depend on, with each advisory's severity and the affected project. The list fills in from deep scans, so run one on a project to populate it.

### Secrets

Every secret stored in the workspace's projects, with its name, whether it's a workspace or project secret, the project it belongs to, and its environment.

Secret values are never shown or exported, only names and where they live.

## Run security scans

Scans run per project. Open a project's security view to run one, or let the workspace run them on a schedule. See [Security view](/features/security/project-view).

### Schedule security scans

Under **Scheduled scans** in **Settings → Security center**:

| Setting | Options |
| - | - |
| **Frequency** | **Off**, **Weekly**, or **Monthly** |
| **Projects** | **All projects** or **Published only** |

Scheduled scans are deep scans. Vibely checks for due workspaces every few hours and scans up to 50 projects per workspace each run.

## Audit logs

<Note>
  Audit logs require the **Business** plan. Owners and admins can read them, unless **Read audit logs** is taken away from admins in **Settings → Permissions**.
</Note>

Audit logs are a searchable record of who did what in your workspace. Open them from **Settings → Security → Audit logs**.

### Audit log events

Vibely records events such as:

| Area | Examples |
| - | - |
| Membership | Invitations sent and accepted, members removed or leaving, role changes, ownership transfers, join requests |
| Projects | Publishing, remixing, collaborators added or removed, group access granted or revoked, share links revoked |
| Identity | SSO settings changed, domain verified, SSO sign-ins and automatic joins, SCIM users provisioned or removed, SCIM tokens rotated |
| Groups | Groups created, renamed, deleted, and membership changes |
| Workspace | Settings and knowledge updated, connectors and custom connectors changed, skills and templates changed, usage limits changed, MCP policy changed |
| Security | Security scans and audit log exports |

### Audit log table

| Column | What it shows |
| - | - |
| **Actor** | Who did it. Automated actions show **System**. |
| **Action** | What happened. |
| **Target** | What it happened to. |
| **IP address** | Where the request came from, when known. |
| **When** | When it happened. |

The table shows 50 events per page; use **Previous** and **Next** to move through them.

### Filter audit logs

Filter by **Actor**, by **Action**, and by **From date** and **To date**. **Clear filters** resets them.

### Export audit logs

Click **Export CSV** to download the events that match your filters. One export holds up to 10,000 events; if there are more, narrow the date range and export the rest separately. Each export is itself recorded in the audit log.

### Audit log retention

Vibely keeps audit events for 400 days, and security events for three years.

## Best practices

* Turn on **Block publishing with critical issues** and **Require basic security scan before first publish** in [Privacy & security](/features/workspace/privacy-security#publishing).
* Schedule weekly scans of published projects, so live apps are checked even when nobody's editing them.
* Review [Workspace Insights](/features/workspace/insights) regularly, starting with **High** and **Not scanned** projects.
* Check the **Supply Chain** tab after major dependency updates.

## FAQ

<AccordionGroup>
  <Accordion title="Who can see the security center?">
    Workspace owners and admins on the Business plan.
  </Accordion>

  <Accordion title="Why is a project missing from the dashboard?">
    Only active projects appear, up to 200 of the most recently edited. Archived and deleted projects aren't listed.
  </Accordion>

  <Accordion title="Can I see secret values?">
    No. The security center shows only secret names and where they're used.
  </Accordion>

  <Accordion title="Why can't I open audit logs?">
    They need the Business plan and the owner or admin role. A workspace on a lower plan sees an upgrade screen.
  </Accordion>
</AccordionGroup>

## Related

<CardGroup cols={2}>
  <Card title="Workspace Insights" icon="chart-simple" href="/features/workspace/insights">
    Which projects need a security review first.
  </Card>

  <Card title="Security view" icon="shield" href="/features/security/project-view">
    Scan one project and fix its findings.
  </Card>

  <Card title="Privacy & security" icon="lock" href="/features/workspace/privacy-security">
    Publishing gates and data protection.
  </Card>

  <Card title="Build secrets" icon="key" href="/features/build/build-secrets">
    Credentials that exist only during a build.
  </Card>
</CardGroup>


## Related topics

- [Workspace admin settings](/features/workspace/admin-settings.md)
- [Privacy & security settings](/features/workspace/privacy-security.md)
- [Workspace Insights](/features/workspace/insights.md)
- [Project security view](/features/security/project-view.md)
- [Glossary](/glossary.md)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.