Admin · Security Center
Security Posture: Active — Google SSO enforced · Entitlements allowlist enabled · MFA via Google Workspace · Break-glass audit logging active
Verified

Loading security status...

MFA Status

Multi-factor authentication enforcement

Enforced
ProviderGoogle Workspace
MethodPasskey / Google Authenticator
ScopeAll admin users
Users with MFA Live count — pending backend

SSO Configuration

Single sign-on identity provider

Active
Identity ProviderGoogle OAuth 2.0
Domainprospectrdigital.com
Session TokenJWT (24h expiry)
Active Sessions Live count — pending backend

Approved Users

Entitlements allowlist — only these users can access the portal

Loading...
Loading user list...
Access is controlled by the server-side entitlements allowlist. Adding a Google account does not grant access without an explicit entitlement entry.

Recent Denied Logins

Unauthorized access attempts in the last 7 days

Loading...
Loading...

Secret Scan Status

Pre-commit hook + git history scan for leaked credentials

Active
Pre-commit Hook Active on sovereign-portal-sandbox
Hook Path/root/.config/git-hooks/pre-commit
BlocksPATs, API keys, connection strings, OAuth tokens
PolicyNever --no-verify — fix the secret, do not skip
Last Scan Scan history — pending backend

Defense in Depth

Access control layers — L1 through L5

L1
Prompt — SOUL.md rules embedded in every agent Can be bypassed by injection
L2
Application — Skills manifest allowedRoles / blockedRoles Code-level · Bug risk
L3
IAM Role — Runtime execution role scoped to target resource only Infrastructure · Cannot be bypassed
L4
Network — VPC isolation between runtimes Infrastructure · Cannot be bypassed
L5
Bedrock Guardrail — Content policy: topic denial, PII filtering on every I/O AWS-managed · Semantically aware · Cannot be bypassed