Review who accessed your fleet.

Review sign-ins, access changes and device session events. Remote session opens are recorded; terminal contents and keystrokes are not.

  • Security activity logs auth and admin events.
  • Detections surface suspicious behavior.
  • Audit trails stay tied to the same org context.

Security activity timeline

See auth events and admin actions in one timeline.

Security activityauth + audit
SSOlogin - jane@acme.com
DETECTtoken used from new ASN
ADMINrole change - support -> admin

Auth

Login visibility

Track logins and token usage.

Admin

Admin changes

Monitor role changes and policy updates.

Audit

Exportable logs

Use activity logs for compliance evidence.

Security detections

Detect suspicious activity without a separate SIEM.

Detections

Suspicious access

Detect unexpected access patterns.

Ops

Incident workflow

Tie detections into incident response.

Policy

Access policy checks

Enforce policy when detections trigger.

Audit evidence

Keep the proof needed by enterprise customers and internal reviewers.

Compliance

Exportable history

Provide access and admin evidence without reconstructing it from several tools.

Customers

Support accountability

Explain who accessed a device, when, and why during support or warranty work.

Governance

Review access over time

Use activity history to refine roles, SSO, MFA, and customer scopes.