# Secure

<Callout type="info">{BADGE_DEFINITIONS.Beta}</Callout>

The Secure section of the dashboard detects and controls risk in agent sessions. Policies scan session interactions for secrets, sensitive data, prompt injection, destructive tool use, and unsanctioned MCP servers — then flag or block what they find. Findings feed risk analytics, per-session review, and an inventory of shadow MCP servers discovered in agent traffic.

Secure pages require the organization admin role.

## Sections

### [Risk Overview](/docs/ai-control-plane/secure/risk-overview)

The security analytics dashboard: events scanned, findings, flagged sessions, and active policies at a glance, with ranked breakdowns by category, rule, and user, and a risk-events-over-time chart.

### [Risk Policies](/docs/ai-control-plane/secure/risk-policies)

Create and manage the policies that scan agent sessions. A stepped editor configures what to detect, which sessions are in scope, whether to flag or block, severity, sensitivity, and audience — including natural-language guardrail policies.

### [Risk Events](/docs/ai-control-plane/secure/risk-events)

The finding-level log: every policy finding with its category, severity, rule, session, and user. Matched content is redacted by default, and any finding opens the full session transcript for investigation.

### [Shadow MCP](/docs/ai-control-plane/secure/shadow-mcp)

An inventory of unsanctioned MCP servers discovered in agent traffic, with per-server usage detail and allow-rule decisions to sanction or block them.

### [Detection Rules](/docs/ai-control-plane/secure/detection-rules)

The catalog of built-in detectors behind risk policies — secrets, financial data, PII, healthcare, prompt injection, and more — plus custom rule authoring with CEL expressions, live testing, and AI-suggested rules.

## Related organization settings

Additional security controls live in the organization settings rather than the project Secure group: audit logs, roles and permissions (RBAC), SSO and directory sync, remote identity providers for MCP authentication, API keys, and active MCP connection management.
