Security Center
Where: Company โ Security (Company Admins only).
The bouncer at the door. Zaptix Sentinel watches every AI prompt and request flowing through your ERP, spots suspicious behaviour, blocks bad IPs, and raises incidents so a human can take a look.
๐ท Screenshot spot โ capture this screen and save it as static/img/screenshots/admin-security.png, then replace this whole box with the single line:

What Sentinel doesโ
- Prompt firewall โ screens every AI prompt in real time for injection, jailbreak and data-extraction attempts.
- Autonomous sweep โ correlates sign-in and AI activity into plain-English incidents (credential probing, credit-burn spikes, access anomalies).
- Proposed actions โ when something needs doing (block an IP, revoke sessions, require MFA), Sentinel proposes it and a human confirms โ the same propose-and-confirm pattern as every other agent.
The tabsโ
| Tab | What's there |
|---|---|
| Overview | Current security posture and recent activity. |
| Events | Every detection with category, severity (Info โ Critical) and status โ confirm or clear each. |
| Incidents | Correlated clusters โ acknowledge, resolve or dismiss. |
| Blocklist | IPs blocked by Sentinel or by you; unblock from here. |
| Audit | The full security audit trail โ sign-ins, failed attempts, password changes, permission events. |
| Policy | The knobs (below). |
Policy settingsโ
- Firewall mode โ Monitor (log and alert, never block) or Enforce (block high-confidence attacks inline โ the shipped default).
- AI review โ a second, smarter AI look at rule-flagged prompts.
- Detection thresholds โ how suspicious something must be to flag or block.
- Access controls โ require MFA company-wide, password length & complexity rules.
- Auto-response (advanced) โ let Sentinel act on very-high-confidence attacks without asking. Off by default; keep it off until you've watched it run false-positive-free for a couple of weeks โ it can lock real users out.
Practical guidanceโ
- Start in Monitor, read a week of events, then move to Enforce.
- Rising AI abuse incidents usually mean a runaway script or someone hammering the rate limits โ not necessarily an attacker.
- The blocklist is your fastest response to a scripted abuser; incidents are for patterns.
- Remind the team about the basics in Personal Settings & Security: MFA on, sign-in alerts read, no shared logins.