Skip to main content
The Security page collects what SRE Agent finds about your estate in one place, split into tabs. You read a finding, decide what it means, and mark it so the next person on call knows it was seen. Security is part of the infrastructure suite, together with Efficiency, Teams and the Network Map. Every role can read the page. Acknowledging findings, running scans and adding monitors needs the member role. Deleting a monitor and managing suppression rules needs org admin.

Open the page and pick a tab

1

Open Security

Click Security in the Infrastructure section of the sidebar. The page opens on Secrets. Times on the page are shown in your organization’s time zone, and the page says which one.
2

Choose a tab

The tabs are Secrets, Certificates, API Anomalies, Retention, AI Governance, K8s Security, CVE / Vulnerabilities, Config Drift, IAM and Access Denials. Org admins also see Compliance, which is covered in Compliance evidence.
3

Open a finding

Click Details on a row, or click the row on API Anomalies. The panel shows the description, severity, status and the evidence behind it. Each panel has its own link, so you can paste it into a ticket or chat.
4

Triage it

Click Acknowledge to record that somebody read it. The finding stays in the table with its badge changed. On Secrets you can also click False Positive. Reopen puts an acknowledged finding back to open.

What each tab shows

Triage summary and suppression rules

On API Anomalies, the Triage summary card reads the latest window and groups related findings with one sentence each. A group marked worth paging deserves attention soon. Click the finding count on a group to narrow the table to it, and Show all findings to widen it again. To acknowledge many findings at once, tick the open rows, add an optional note and click Acknowledge selected. When a pattern is expected, for example a CI role that always creates access keys, an org admin can stop it filing findings. Open the finding and click Suppress similar…, or fill in the form under Suppression Rules: an actor pattern, a rule or anomaly type, an expiry date and a reason. Creating a rule resolves the open findings it covers. Deleting the rule makes them file again.
A suppression rule hides future findings, not only the one you opened. Give every rule a short expiry and a clear reason.

Read access denials

1

Open Access Denials

The tab asks your AWS account when you open it, so it reflects the account as it is now. It needs an AWS data source connected, and says so when none is.
2

Choose the question

Calls is Refused by default. Pick Every failed call to include throttles and malformed requests as well. Narrow with Identity ARN (a role name or part of an ARN), Username, and the From and To window. Click Run.
3

Read the groups

Each row is a group: the principal, the action, the error, a count, the resources touched, first and last seen, source IPs and an example event.
Events to read limits how much of the window is searched, and Groups to show limits the table. A wider window with the same budget stops earlier and says so. Denials are counted fresh on each run, so unlike the other tabs they cannot be acknowledged.

Open an identity page

Click a principal name in a finding panel to open its identity page. It gathers everything recorded about that AWS identity: Open findings, Refused and failed, last 24 hours, First seen, Volume, any Resources walked, and IAM findings. An identity with nothing recorded says so and links to the Access Denials tab so you can ask yourself.

What happens next

Acknowledged findings stay visible with their badge changed, and findings that resolve on their own remain reachable by their own link. Paste a finding’s link into a ticket or chat message and the reader lands on the same panel.