Security & Audit
The enterprise login policy (and honest future-SSO state) plus the enterprise-wide audit log of administration changes.
Security & login policy
The Security tab holds the enterprise login policy and the verified-domain member restriction (the restriction itself is configured against your domains).
SSO is not enabled in this release. The login-policy groundwork (normal login, "SSO configured", "SSO required") exists so the model is ready for a future SSO feature, but no SSO/SAML/OIDC sign-in is wired up yet. Any SSO-required control is shown as unavailable and cannot lock anyone out. Normal email and Google/GitHub sign-in continue to work exactly as before.
Changes to enforceable policy fields are recorded in the enterprise audit log.
Audit
The Audit tab is the enterprise-wide administration history, newest first. It records enterprise creation and renames; member add / role-change / remove; workspace link / unlink; domain add / verify / verification-failure / remove; and login-policy and member-restriction changes.
Each row shows the event, the actor (with avatar — searchable and filterable for large teams), the affected object by name, an event-aware summary of what changed, and the timestamp. You can filter by event type, actor, and a date range.
Affected-object names are captured at the moment of the event, so the log stays readable even after a workspace or domain is later renamed, unlinked, or removed. The audit page shows administration history only — never raw server logs or internal operator diagnostics.
Actions IRSIK Integrity staff take on your behalf (provisioning, ownership fixes) appear here too, alongside your own — see Creating & linking → IRSIK provisioning.