Security
Account and platform security
Workspace security controls, the audit trail, and how long data is kept.
Last update:
This section covers the controls that protect a CentralCSP workspace and the records of what happened in it.
What you can do
Four pages cover the workspace controls and their records:
- Require two-factor authentication for every member. Two-factor enforcement
- Review the audit trail of administrative actions. Audit logs
- Understand what is kept and for how long: Data retention
- See the full set of controls and how to review them. Platform security
Start here
If you are setting up a workspace for a team, do these in order:
- Enrol your own two-factor, then require it workspace-wide.
- Decide whether AI integrations are allowed, and set the kill switch accordingly.
- Make everyone a Member except the few who must administer the account.
- Grant website access through groups rather than per person.
Next steps
Website access
Grant people and groups a role on one website. Where to do it, how the two paths combine, and why revoking often needs both.
Platform security
The workspace-level controls that protect your account. Two-factor enforcement, the AI integration kill switch, API key restrictions, and the audit trail.