Security

View as Markdown

Security settings configure organization-level guardrails. Manage them together with single sign-on, user roles, tracing, and query history so security decisions can be verified.

Management Boundary

AreaGuidance
IdentityDefine login methods, session policy, and administrator scope.
AccessUse roles, groups, and sharing scopes to control resource visibility.
OperationsAdd approval or extra validation to high-impact actions, bots, and hooks.
AuditRetain security changes, denial events, and abnormal requests.

Before Configuration

  • Identify which accounts have administrator permissions.
  • Confirm SSO, user sync, and local account policy are aligned.
  • Evaluate security boundaries for bots, service accounts, and hooks separately.

Verification

  • Validate menu visibility with admin and regular users.
  • Test unauthorized resources, tools, and configuration changes.
  • Confirm denial events can be found in tracing or query history.