Skip to main content

Security Center

Where: Company โ†’ Security (Company Admins only).

The bouncer at the door. Zaptix Sentinel watches every AI prompt and request flowing through your ERP, spots suspicious behaviour, blocks bad IPs, and raises incidents so a human can take a look.

๐Ÿ“ท Screenshot spot โ€” capture this screen and save it as static/img/screenshots/admin-security.png, then replace this whole box with the single line:
![Security Center](/img/screenshots/admin-security.png)

What Sentinel doesโ€‹

  1. Prompt firewall โ€” screens every AI prompt in real time for injection, jailbreak and data-extraction attempts.
  2. Autonomous sweep โ€” correlates sign-in and AI activity into plain-English incidents (credential probing, credit-burn spikes, access anomalies).
  3. Proposed actions โ€” when something needs doing (block an IP, revoke sessions, require MFA), Sentinel proposes it and a human confirms โ€” the same propose-and-confirm pattern as every other agent.

The tabsโ€‹

TabWhat's there
OverviewCurrent security posture and recent activity.
EventsEvery detection with category, severity (Info โ†’ Critical) and status โ€” confirm or clear each.
IncidentsCorrelated clusters โ€” acknowledge, resolve or dismiss.
BlocklistIPs blocked by Sentinel or by you; unblock from here.
AuditThe full security audit trail โ€” sign-ins, failed attempts, password changes, permission events.
PolicyThe knobs (below).

Policy settingsโ€‹

  • Firewall mode โ€” Monitor (log and alert, never block) or Enforce (block high-confidence attacks inline โ€” the shipped default).
  • AI review โ€” a second, smarter AI look at rule-flagged prompts.
  • Detection thresholds โ€” how suspicious something must be to flag or block.
  • Access controls โ€” require MFA company-wide, password length & complexity rules.
  • Auto-response (advanced) โ€” let Sentinel act on very-high-confidence attacks without asking. Off by default; keep it off until you've watched it run false-positive-free for a couple of weeks โ€” it can lock real users out.

Practical guidanceโ€‹

  • Start in Monitor, read a week of events, then move to Enforce.
  • Rising AI abuse incidents usually mean a runaway script or someone hammering the rate limits โ€” not necessarily an attacker.
  • The blocklist is your fastest response to a scripted abuser; incidents are for patterns.
  • Remind the team about the basics in Personal Settings & Security: MFA on, sign-in alerts read, no shared logins.