> ## Documentation Index
> Fetch the complete documentation index at: https://sofiedocs.usetransfer.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Security Center

> Use Sofie Security Center to review security events, alerts, access review snapshots, and recovery activity.

Security Center helps authorized administrators review security activity in Sofie. It is an operational review surface, not a replacement for your organization’s required security program.

<Note>
  Security Center access depends on permissions. Some users may view logs, while only settings administrators can generate or export access review material.
</Note>

## Security Center tabs

| Tab                | Use it for                                                                |
| ------------------ | ------------------------------------------------------------------------- |
| **Events**         | Search authentication, access, policy, recovery, and admin activity.      |
| **Alerts**         | Review elevated-risk or anomaly activity surfaced by Sofie.               |
| **Access Reviews** | Generate and inspect snapshots for privileged access and policy gaps.     |
| **Recovery**       | Review passkey recovery, removal, restore, and deletion-related activity. |

## Review events

Use **Events** when you need to search activity.

Filters may include:

* Search text.
* Actor.
* Subject.
* Date range.
* Category.
* Risk level.

Common event categories include:

* Auth.
* Access.
* Policy.
* Recovery.
* Data recovery.
* Admin.

<Tip>
  Start with a date range and actor when investigating a specific user-reported issue. Start with category and risk when reviewing broader activity.
</Tip>

## Review alerts

Use **Alerts** for activity that deserves focused inspection.

When reviewing an alert:

* Check when it happened.
* Check actor and subject.
* Check risk level.
* Open any available action link.
* Dismiss only after you understand why it appeared.
* Escalate according to your organization’s process when needed.

## Generate access review snapshots

Access review snapshots can help capture a point-in-time view of privileged access, overrides, pending invites, and passkey policy gaps.

<Steps>
  <Step title="Open Security Center">
    Go to **Security Center**.
  </Step>

  <Step title="Choose Access Reviews">
    Open **Access Reviews**.
  </Step>

  <Step title="Generate snapshot">
    Click **Generate Snapshot** if your account can manage Security Center.
  </Step>

  <Step title="Inspect findings">
    Open the generated snapshot and review the findings.
  </Step>

  <Step title="Export if needed">
    Export only when your organization process calls for it.
  </Step>
</Steps>

## Review recovery activity

Use **Recovery** when you need to inspect:

* Passkey recovery.
* Passkey removal.
* Account recovery steps.
* Restores.
* Workspace deletion-related activity.

Recovery activity often needs follow-up when it involves privileged users, unexpected timing, or repeated failures.

## Security review checklist

Use this checklist during regular review:

* Privileged users still need elevated access.
* Privileged users meet passkey policy.
* Stale accounts are addressed.
* Pending invitations are still valid.
* Recent high-risk alerts are explained.
* Recovery events match expected support activity.
* Integration administration changes were expected.
* Access review snapshots are stored according to your process.

<Warning>
  Do not treat Sofie Security Center as a compliance claim. Use it as one review input alongside your organization’s required procedures, systems, and records.
</Warning>
