Auth
Login visibility
Track logins and token usage.
Review sign-ins, access changes and device session events. Remote session opens are recorded; terminal contents and keystrokes are not.
See auth events and admin actions in one timeline.
login - jane@acme.comtoken used from new ASNrole change - support -> adminAuth
Track logins and token usage.
Admin
Monitor role changes and policy updates.
Audit
Use activity logs for compliance evidence.
Detect suspicious activity without a separate SIEM.
Detections
Detect unexpected access patterns.
Ops
Tie detections into incident response.
Policy
Enforce policy when detections trigger.
Keep the proof needed by enterprise customers and internal reviewers.
Compliance
Provide access and admin evidence without reconstructing it from several tools.
Customers
Explain who accessed a device, when, and why during support or warranty work.
Governance
Use activity history to refine roles, SSO, MFA, and customer scopes.
See security activity across your workspace.