# Overview (/en/docs/platform/security)



This section covers the controls that protect a CentralCSP workspace and the records of what happened in it.

## What you can do [#what-you-can-do]

Four pages cover the workspace controls and their records:

* **Require two-factor authentication** for every member. [Two-factor enforcement](/en/docs/platform/security/mfa)
* **Review the audit trail** of administrative actions. [Audit logs](/en/docs/platform/security/audit-log)
* **Understand what is kept and for how long:** [Data retention](/en/docs/platform/security/data-retention)
* **See the full set of controls** and how to review them. [Platform security](/en/docs/platform/security/platform-security)

## Start here [#start-here]

If you are setting up a workspace for a team, do these in order:

1. Enrol your own two-factor, then require it workspace-wide.
2. Decide whether AI integrations are allowed, and set the kill switch accordingly.
3. Make everyone a Member except the few who must administer the account.
4. Grant website access through groups rather than per person.

## Next steps [#next-steps]

* [Platform security](/en/docs/platform/security/platform-security)
* [Roles and permissions](/en/docs/platform/team/roles-and-permissions)
