Administration

Security centre for your workspace

Administration ▸ Security centre shows how safe your workspace is, what to fix first, and who is signed in where. Owners and admins can open it on every plan; nobody else can.

  1. 1

    Overview: your score and to-do list

    A score out of 100 and a list of what would raise it, most important first. Each item says what it means and links to where it is fixed: owners and admins without two-step sign-in (25 points), two-step sign-in not required for admins (15), other members without it (10), open security alerts (15), people who have not used this workspace for 90 days (10) or never signed in (5), API keys nothing is using (not used for 90 days, or never used in their first month) (10) or that are more than a year old (5), and invitations that have waited more than 3 days (5). Guests of your client portal are not counted. 90 or more is Strong, 75 Good, 50 Needs attention, below 50 At risk.

  2. 2

    Alerts: what WorkBOS noticed about your workspace

    Password guessing on a member’s account, somebody made an owner or admin, two-step sign-in switched off for the workspace or removed from an admin, very large exports or deletions, and an API key working far harder than usual. Owners and admins are told in their notifications, and by email for high and critical alerts (one email per kind of alert per hour). Open an alert to read what it means and what to do, then mark it Seen, Handled or Not a problem; the last two need a short note, and an alert about you is closed by somebody else. An alert never shows your workspace the full internet address behind it.

  3. 3

    Devices: who is signed in where

    Every member with the devices they have used in this workspace, the country each one is in, and when they last used it here. Open a person to see their devices, or to sign them out everywhere: they have to sign in again, any AI assistant they connected to this workspace is disconnected, and WorkBOS emails them that an admin of your workspace did it (once a day at most). The reason you type is kept in the activity log, which owners and admins can read, and is not put in the email.

  • Who can sign out whom: owners and admins can sign out members whose account this workspace manages; only an owner can sign out an owner; nobody can sign out, from a workspace, somebody who also runs another workspace, or a WorkBOS administrator; and you sign your own other devices out from Settings ▸ Security instead. Guests of your client portal are not listed here.
  • Why some devices do not appear: a device shows once it has been used in this workspace, from the day this page arrived. A person who also works in other workspaces may have more sign-ins; you see how many, never where, what they are or when they were used, and signing them out everywhere closes those too.
  • Signing out is quick but not instant everywhere: a device that is open is signed out the next time it opens or switches to WorkBOS, and within the hour at most.
  • Where your workspace requires two-step sign-in, this page asks for the code as well as the password, and your role must include Security centre in Roles & permissions (read to look, update to act).

The fastest way to a strong score: turn on two-step sign-in for yourself (Settings ▸ Security), then require it for owners and admins on the same card.

Was this page useful?