Security, privacy, and billing · concept

Security and audit overview

Separate personal account security, administrative change history, and owner-only authentication audit evidence.

3 min readUpdated August 12, 2026
For
Owner, Admin
Availability
Your current plan and entitlements
Product evidence
WRKZY · reviewed August 12, 2026
Editorial review
WRKZY Editorial
Before you begin
  • Owner or Admin access to security, session, and audit views
  • Knowledge of the workspace's approved users and connected services
  • An incident owner and escalation path for unexpected activity
Establish least-privilege workspace and security controlsRead the transcript

Three layers of security evidence

WRKZY separates personal account security, administrative change history, and authentication audit:

Security evidence layers
LayerWhereWho and what
Personal securitySettings → Profile & securityEvery user manages their own password, authenticator MFA, personal connections, and active sessions
Settings change historySettings domain disclosures and overviewShows recent administrative changes with actor, action, target, and time when available
Authentication auditSettings → Security → Session logsOwner-only events and sessions with member filters, full IP visibility, pagination, and a 180-day review window

An Admin role does not grant access to another person's password, MFA seed, or session token. Full-IP authentication audit is intentionally Owner-only because it contains sensitive member and network history.

Security accountability

  1. 01
    AccountOrganization

    The customer account and ownership boundary.

  2. 02
    ScopeWorkspace

    The operating area where customer work and configuration live.

  3. 03
    GovernOwner

    Controls the organization, subscription, and highest-risk access.

  4. 04
    ConfigureAdministrator

    Configures members, channels, defaults, and operating controls.

  5. 05
    OperateMember

    Works customer queues, records outcomes, and escalates exceptions.

Each user secures their account; administrators govern workspace configuration; the Owner reviews the most sensitive authentication evidence.

Establish the baseline

  1. Every teammate opens Profile & security, uses a unique password, enables authenticator MFA, and reviews Active sessions.
  2. Owners and Admins review Members and remove unnecessary elevation.
  3. The Owner opens Settings → Security → Session logs.
  4. Switch between Events and Sessions.
  5. Use member, event type, date range, and page-size filters.
  6. Record the normal devices, locations, and login rhythm relevant to the organization.
  7. Review Settings Recent changes after high-risk channel, privacy, AI, role, or billing updates.
Authentication event types
Event familyExamplesQuestion
AccessLogin; heartbeat; session expiredDoes this session belong to the expected person and device?
Sign-outLocal; other sessions; global; individual sessionWas this an intentional response or routine cleanup?
RiskAuth error; security actionIs there a repeated pattern, unknown device, or access change requiring containment?

Investigate a concern

Start with the affected user and smallest time window. Compare event time, session state, browser/device, and IP. Ask the user to review their personal Active sessions. If the session is unknown, end sessions, change the password, verify MFA, and preserve audit evidence. Then review member role and recent administrative changes.

Do not treat a new IP as proof of compromise; mobile networks, VPNs, and travel change addresses. Correlate several signals.

Evidence and privacy

Full IP addresses and authentication history are personal security data. Share them only with authorized responders. Screenshots should exclude unrelated members and customer data. Never collect passwords, authenticator QR secrets, one-time codes, cookies, access tokens, or private keys.

WRKZY security and audit settings with session and change evidenceOpen full size
Security & audit separates the owner-only authentication log from the broader administrative change history. Open logs for session evidence; do not treat the page-level health label as a completed investigation.

Recovery and escalation

If role verification is unavailable, reload before interpreting an empty audit. For confirmed compromise, end sessions first, rotate credentials, then investigate. Preserve organization/workspace, user ID or work email, event/session ID, approximate time and timezone, event type, relevant IP only when authorized, and actions already taken.

Security review complete
  • Personal MFA and sessions reviewed
  • Elevated membership checked
  • Owner-only Events and Sessions filtered to the incident
  • Signals correlated before declaring compromise
  • Containment performed before deep analysis
  • Sensitive audit evidence shared only with authorized responders
Was this guide useful?

Choose an answer. No message text or personal information is collected.

Still need help?

Contact WRKZY support with the workspace name and a safe, redacted example.

Contact support about this guide