Skip to main content
Security Center helps authorized administrators review security activity in Sofie. It is an operational review surface, not a replacement for your organization’s required security program.
Security Center access depends on permissions. Some users may view logs, while only settings administrators can generate or export access review material.

Security Center tabs

TabUse it for
EventsSearch authentication, access, policy, recovery, and admin activity.
AlertsReview elevated-risk or anomaly activity surfaced by Sofie.
Access ReviewsGenerate and inspect snapshots for privileged access and policy gaps.
RecoveryReview passkey recovery, removal, restore, and deletion-related activity.

Review events

Use Events when you need to search activity. Filters may include:
  • Search text.
  • Actor.
  • Subject.
  • Date range.
  • Category.
  • Risk level.
Common event categories include:
  • Auth.
  • Access.
  • Policy.
  • Recovery.
  • Data recovery.
  • Admin.
Start with a date range and actor when investigating a specific user-reported issue. Start with category and risk when reviewing broader activity.

Review alerts

Use Alerts for activity that deserves focused inspection. When reviewing an alert:
  • Check when it happened.
  • Check actor and subject.
  • Check risk level.
  • Open any available action link.
  • Dismiss only after you understand why it appeared.
  • Escalate according to your organization’s process when needed.

Generate access review snapshots

Access review snapshots can help capture a point-in-time view of privileged access, overrides, pending invites, and passkey policy gaps.
1

Open Security Center

Go to Security Center.
2

Choose Access Reviews

Open Access Reviews.
3

Generate snapshot

Click Generate Snapshot if your account can manage Security Center.
4

Inspect findings

Open the generated snapshot and review the findings.
5

Export if needed

Export only when your organization process calls for it.

Review recovery activity

Use Recovery when you need to inspect:
  • Passkey recovery.
  • Passkey removal.
  • Account recovery steps.
  • Restores.
  • Workspace deletion-related activity.
Recovery activity often needs follow-up when it involves privileged users, unexpected timing, or repeated failures.

Security review checklist

Use this checklist during regular review:
  • Privileged users still need elevated access.
  • Privileged users meet passkey policy.
  • Stale accounts are addressed.
  • Pending invitations are still valid.
  • Recent high-risk alerts are explained.
  • Recovery events match expected support activity.
  • Integration administration changes were expected.
  • Access review snapshots are stored according to your process.
Do not treat Sofie Security Center as a compliance claim. Use it as one review input alongside your organization’s required procedures, systems, and records.