> ## Documentation Index
> Fetch the complete documentation index at: https://docs.sreagent.app/llms.txt
> Use this file to discover all available pages before exploring further.

# Review security findings

> Work through misplaced credentials, expiring certificates, unusual API activity, access denials and IAM findings on the Security page.

export const Plan = ({tier}) => <Badge color="blue">{tier} plan</Badge>;

The **Security** page collects what SRE Agent finds about your estate in one place, split into tabs. You read a finding, decide what it means, and mark it so the next person on call knows it was seen.

<Plan tier="Business" />

Security is part of the infrastructure suite, together with Efficiency, Teams and the Network Map. Every role can read the page. Acknowledging findings, running scans and adding monitors needs the member role. Deleting a monitor and managing suppression rules needs org admin.

## Open the page and pick a tab

<Steps>
  <Step title="Open Security">
    Click **Security** in the **Infrastructure** section of the sidebar. The page opens on
    **Secrets**. Times on the page are shown in your organization's time zone, and the page says
    which one.
  </Step>

  <Step title="Choose a tab">
    The tabs are **Secrets**, **Certificates**, **API Anomalies**, **Retention**, **AI Governance**,
    **K8s Security**, **CVE / Vulnerabilities**, **Config Drift**, **IAM** and **Access Denials**.
    Org admins also see **Compliance**, which is covered in [Compliance
    evidence](/guides/security-cost/compliance).
  </Step>

  <Step title="Open a finding">
    Click **Details** on a row, or click the row on **API Anomalies**. The panel shows the
    description, severity, status and the evidence behind it. Each panel has its own link, so you
    can paste it into a ticket or chat.
  </Step>

  <Step title="Triage it">
    Click **Acknowledge** to record that somebody read it. The finding stays in the table with its
    badge changed. On **Secrets** you can also click **False Positive**. **Reopen** puts an
    acknowledged finding back to open.
  </Step>
</Steps>

## What each tab shows

| Tab | What it covers |
| - | - |
| **Secrets** | Credentials in the wrong place: Kubernetes ConfigMaps, inline environment variables, alert and investigation text. Credentials inside Kubernetes Secrets are expected and are not flagged. |
| **Certificates** | TLS certificates found from your Kubernetes Ingresses and your AWS certificate inventory, plus any host you add with **Watch this host**. Set the warning and critical days per host. |
| **API Anomalies** | Unusual activity, with a **Triage summary** card on top. With a CloudTrail data source connected it includes calls in your AWS account, such as stopping a trail or opening a security group to the internet. |
| **Retention** | The retention policies for your records. Org admins edit them here or under **Settings**, **Preferences**. |
| **AI Governance** | Calls made to AI providers over the last 30 days: tokens, estimated cost, and whether each call was anonymized. |
| **K8s Security** | Cluster scans per cluster. **Run Scan** starts one. A finding count marked `(partial)` is a floor, because some checks could not run. |
| **CVE / Vulnerabilities** | Container images from your clusters and ECS task definitions, scanned for known vulnerabilities. **Discover Images**, **Scan All** and **Scan this image** keep the list current. |
| **Config Drift** | Workloads compared with a captured baseline. **Discover & Scan** adds workloads, **Capture Baseline** records the accepted state, **Check Now** compares. |
| **IAM** | A daily inventory of your AWS account's IAM users and roles, with findings for broad grants, external trust, missing MFA and unused credentials. **Run scan now** starts one. |
| **Access Denials** | The AWS calls your account refused in a window. See below. |

## Triage summary and suppression rules

On **API Anomalies**, the **Triage summary** card reads the latest window and groups related findings with one sentence each. A group marked **worth paging** deserves attention soon. Click the finding count on a group to narrow the table to it, and **Show all findings** to widen it again.

To acknowledge many findings at once, tick the open rows, add an optional note and click **Acknowledge selected**.

When a pattern is expected, for example a CI role that always creates access keys, an org admin can stop it filing findings. Open the finding and click **Suppress similar...**, or fill in the form under **Suppression Rules**: an actor pattern, a rule or anomaly type, an expiry date and a reason. Creating a rule resolves the open findings it covers. Deleting the rule makes them file again.

<Warning>
  A suppression rule hides future findings, not only the one you opened. Give every rule a short
  expiry and a clear reason.
</Warning>

## Read access denials

<Steps>
  <Step title="Open Access Denials">
    The tab asks your AWS account when you open it, so it reflects the account as it is now. It
    needs an AWS data source connected, and says so when none is.
  </Step>

  <Step title="Choose the question">
    **Calls** is **Refused** by default. Pick **Every failed call** to include throttles and
    malformed requests as well. Narrow with **Identity ARN** (a role name or part of an ARN),
    **Username**, and the **From** and **To** window. Click **Run**.
  </Step>

  <Step title="Read the groups">
    Each row is a group: the principal, the action, the error, a count, the resources touched, first
    and last seen, source IPs and an example event.
  </Step>
</Steps>

**Events to read** limits how much of the window is searched, and **Groups to show** limits the table. A wider window with the same budget stops earlier and says so. Denials are counted fresh on each run, so unlike the other tabs they cannot be acknowledged.

## Open an identity page

Click a principal name in a finding panel to open its identity page. It gathers everything recorded about that AWS identity: **Open findings**, **Refused and failed, last 24 hours**, **First seen**, **Volume**, any **Resources walked**, and **IAM findings**. An identity with nothing recorded says so and links to the **Access Denials** tab so you can ask yourself.

## What happens next

Acknowledged findings stay visible with their badge changed, and findings that resolve on their own remain reachable by their own link. Paste a finding's link into a ticket or chat message and the reader lands on the same panel.

## Related

* [Read the Network Map](/guides/security-cost/network-map): see what sits next to a finding.
* [Control data privacy and retention](/guides/administer/data-privacy-and-retention): retention and AI anonymization settings.
* [Connect AWS with a read-only role](/guides/get-started/connect-aws): connect the AWS account the checks read.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.