Monitoring Hub
The single place every scan reports to: live activity, your security report, monitor keys, alert rules, and the open items that need attention.
The Monitoring Hub is where the platform's continuous monitoring and your Scan Now runs come together. It has five views, available in the navigation above the page content and in the workspace sidebar. Account settings, integrations, and organization management share the same sidebar.
Overview
The default landing view shows devices reporting in the last seven days, devices needing attention, connected integrations, and alert rules. Below those summaries are open items that need your attention, in two groups. Getting started lists setup steps you have not finished yet, such as adding a Seat License, connecting your email, setting up a device monitor, enabling the daily MFA scan, or creating your first alert; on the Free Tier the items that require a seat are badged. Findings are posture problems from your monitors: devices scored Critical or At Risk, users without MFA, failing mail posture checks, and unmonitored mailboxes. Each task links to the view or page where you fix it. Device findings open the specific report, with remediation steps first; device details, passing checks, and inventory remain available in expandable sections.
Security Report
Your security posture and threat activity at a glance: Monitored Devices, Identity Posture, Mailbox enrollment, Email Health, and Web Traffic. Charts link to their supporting activity, posture report, or member list. Mailbox enrollment describes member configuration, not connection health. No scored email or URL activity is shown as unavailable rather than zero threats. This view also holds the Download attestation report button, which generates the printable Security Attestation Report (account admins only).
Scan Activity
A searchable, filterable table of every run on the account, with the full report a click away.
- Monitor type: URL, Email, File, Device, Identity, Mail Posture, or AI Exposure.
- Status: completed, queued, or filtered (an email that an integration's spam rules moved to Spam or Junk automatically; the report still exists).
- Time range: last 24 hours, 3 days, 7 days, or all time.
- Verdict: Malicious, Suspicious, or Clean for analysis runs; Critical, At Risk, or Healthy for posture runs.
- Check results: only runs with at least one failed check, only fully passing runs, or a minimum number of failed checks.
- Search matches the run's target and description, so you can find a hostname, a subject line, a URL, or a submitter.
Status, submitter, and check-count controls are available under Advanced filters. Enable Latest per device to see each device’s latest run in the chosen date range; verdict and check filters apply after grouping. This view considers up to the most recent 1,000 device scans and shows a notice when that limit is reached. Uncheck it to return to the complete scan history.
Results are paged (25, 50, or 100 per page), and Download CSV downloads the current filtered set, up to 1,000 rows. CSV follows the selected view, including latest-per-device grouping. Each row shows the monitor type, the target, who submitted it, the verdict, and the failed-check count. Clicking a row opens the matching report: email, malware, URL, device, identity, mail posture, or AI exposure.
Monitors
Monitors are scoped keys that let an extension or agent submit scans without any access to the rest of your account: Web Extension (URL runs from the Chrome Monitor), Mail Extension (email runs from the Outlook and Gmail plugins), and Device Monitor (posture scans from the macOS and Windows agents). Each monitor has a display name and, separately, a seat assignment, the seated member its runs bill to and report as the submitter. Last activity is shown when a scan can be matched to the monitor’s ID. Missing activity attribution is labeled unknown and does not mean the monitor is offline. Keys are shown once when created; you can rename or reassign a monitor later without regenerating its key, and revoke it here at any time. Org integrations and the personal Outlook mailbox do not need a monitor key; their connection wizard handles credentials.
Alerts
Start from a critical-device, malicious-content, or daily-flagged-check preset, or create a custom rule. Review the recipient and conditions before saving; selecting a preset alone does not enable an alert. Rules watch completed runs and deliver matches by email or to an HTTP endpoint, immediately or as an hourly or daily digest. See Alerts.
Where runs come from
| Source | Monitor type | Cadence |
|---|---|---|
| Scan Now (web app or API) | URL, Email, File | On demand; 30 free runs a day, 500 per seat |
| Chrome Monitor, mail plugins | URL, Email | As you browse and read mail |
| Google Workspace / Microsoft 365 integrations | Real time, as mail arrives | |
| Personal Outlook mailbox | Real time | |
| Device agents | Device | About hourly |
| CrowdStrike Falcon / Microsoft Defender | Device | Daily |
| Identity posture scan (MFA, dormant accounts) | Identity | Daily |
| Mail posture scan (forwarding, inbox rules, mail auth) | Mail Posture | Daily |
| AI exposure scan | AI Exposure | Daily |
Personal accounts see a pointer to the Organizations page in the hub header: team monitoring, members, seats, and org-wide integrations live on a shared organization account.