Read the dashboard
The administrator landing page — system overview, security metrics, service health, detection charts and the newest security and audit events.
- Version: 0.4
- Role: admin_user, viewer
- Type: task
The dashboard is the landing page for administrative roles. It answers three questions in one screen: how much the appliance is being used, what its detection pipeline is catching, and whether its services are healthy.
What do I need?
- Licence
- Any
- Role
admin_userviewer
Prerequisites
- You are signed in as an admin_user, the superadmin, or a viewer. A normal_user is sent to the chat instead, and an auditor to Compliance.
The subtitle under the title states the scope you are looking at — Security overview, then the time range, then all tenants.
/assets/screenshots/dashboard@0.4.pngChoose the time range
Open the range menu
Select Time range in the page header.
Four ranges are offered: last 24 hours, last 7 days, last 30 days and all time.
Pick one
Select a range.
The ranged cards re-read against it and the subtitle updates. Three figures are not windowed and do not move: Total Tenants, Compliance, and the whole Recent activity card. The choice is remembered in this browser and is last 30 days until you change it.
Note
The Compliance figure on Security Metrics is cumulative and ignores the range — it counts violations prevented over the life of the appliance.
Read the cards
The page ships with seven cards, in this order.
| Card | What it answers |
|---|---|
| System Overview | Total Tenants across all time, then Active Sessions and API Requests for the range, with a link to Tenants |
| Security Metrics | Detections, Compliance violations prevented, and Threats Rejected — outright blocks, highlighted when above zero |
| System Health | A Healthy or Warning summary of the error rate, then a row per service: API gateway, ML detector (NER), Detections API and Event logging, each Healthy, Degraded or Unreachable |
| Detections by action | A donut splitting detections into Flagged, Masked and Rejected, with the prompt/response split underneath |
| Top entity types | Detections by entity type, split into PII types and Security, with the share of detections the top entries account for |
| Security & Audit | The newest policy, access and configuration events, with Category, Event, Detail, Actor and When |
| Recent activity | The newest detections, with User, Status, Entities, Source and When |
Every card refreshes itself once a minute.
Follow a card to its page
Select the link at the foot of a card, or select a row.
Go to Tenants, Go to All Detections and Go to Event Logs open the corresponding page. Selecting a Security & Audit row opens Event logs already filtered to that category.
Rearrange the dashboard
Enter customise mode
Select Customise.
A banner explains the controls: Drag a card by its grip, or focus the grip and use the arrow keys. Use the eye to hide or show a card. Saved in this browser only.
Reorder and hide cards
Drag a card by its grip, or focus the grip and use the arrow keys. Each card's edit bar carries its own move and hide controls.
Outside customise mode the same three actions are on a card's own menu — Move up, Move down, Hide. That menu is not rendered while customise mode is on.
Hidden cards are counted in a Hidden cards dropdown with a Show all action.
Finish
Select Done, or press Escape.
The layout is stored in this browser only. It does not follow you to another device and it is not shared with other administrators.
To undo everything, select Reset to default and confirm Reset this dashboard? — Every card comes back in the order it ships in, and the arrangement you made is discarded. This cannot be undone.
Print or export the view
Select Export report. This opens your browser's print dialog on the current dashboard, so the output is whatever is on screen — the range you chose and the cards you left visible. It is not a generated CSV or PDF; for those, use the exports on Compliance reports and Token cost and savings.
Fields reference
| Control | What it does |
|---|---|
| Time range | Switches every ranged card between last 24 hours, last 7 days, last 30 days and all time. Remembered per browser; default last 30 days |
| Export report | Opens the browser print dialog on the current view |
| Start chat | Opens the chat playground |
| Customise / Done | Enters and leaves layout editing |
| Reset to default | Restores the shipped card order and unhides every card |
| View all | Opens the full list behind a card |
| Tab | Opens |
|---|---|
| Overview | This page |
| All Detections | All detections |
| Compliance | Compliance |
| Event Logs | Event logs |
Verify
- The subtitle names the range you selected, and the figures change when you switch range.
- System Health reports Healthy for all four services. Anything else names the service that is degraded or unreachable.
- Send a message through the chat that your filters catch, wait for the next refresh, and confirm it appears in Recent activity — a masked message as Masked, a blocked one as Request rejected.
- Security & Audit lists the events behind your recent administrative changes; a user edit
shows as a
RESOURCE_UPDATEDrow, a login asAUTH_SUCCESS.
If it fails
- The page redirects to the chat as soon as you open it — your role is
normal_user, which has no dashboard. This is the registry's decision, not an error. - No recent activity — no detection has been recorded at all. This card is not windowed by the time range, so widening the range will not populate it.
- No security or audit events in the
{range}— the same, for the audit feed. - No detection data on Top entity types — no detections in the range to chart.
- Warning on System Health with an error percentage — the event log holds errors in this window. Open Event logs and filter to the error category.
- A service row reads Unreachable — that container is down or unhealthy. Check the service and its logs before trusting any figure that depends on it.
- Cards show stale numbers — the page refreshes once a minute; reload if you need the answer now.
Next steps
- All detections — the full feed behind the detection cards.
- Event logs — the audit trail behind Security & Audit.
- Tenant analytics — the same usage figures broken down per account.
Last updated on