The Security & Access settings section summarizes workspace security tools.
It highlights access tokens and audit logs as available tools, lists the AI clients connected to the workspace, and shows Single Sign-On as planned.
Access Token Metrics
Section titled “Access Token Metrics”The section shows token metrics:
- Total tokens
- Active tokens
- Disabled tokens
- Tokens expiring soon
Use these metrics to review automation credentials and identify tokens that may need attention.
Access Tokens
Section titled “Access Tokens”Access tokens are available from this settings section.
Use Manage on the Access Tokens card to open the access-token page. There you can create, review, disable, and revoke tokens according to your permissions.
Learn more: Access Tokens Overview
Audit Logs
Section titled “Audit Logs”Audit logs are available from this settings section.
Use Manage on the Audit Logs card to review workspace activity for investigations, compliance checks, and change tracking.
Single Sign-On
Section titled “Single Sign-On”Single Sign-On is visible as a planned security capability.
The card explains that SSO is intended for centralized login, offboarding, and policy enforcement, but it is not currently available for setup from this settings section.
Best Practices
Section titled “Best Practices”- Prefer short-lived tokens when possible
- Use the narrowest token access that supports the task
- Review active and expiring tokens regularly
- Use audit logs to verify sensitive workspace changes
Next Steps
Section titled “Next Steps”- Review Access Tokens
- Learn about Roles
- Review Workspace Settings
Connected Apps
Section titled “Connected Apps”The section lists every member’s connected AI clients — applications authorized to read this workspace over MCP. See MCP security.
Each row shows the member who connected it, the application’s self-reported name, and when it was connected. All such access is read-only: a connected client cannot create, edit, or delete anything.
Use the disconnect action to revoke a connection. It takes effect on the client’s next call. Disconnecting here affects only this workspace — if the same member authorized the same application in another workspace, that connection is separate and is unaffected.
Members can also see and disconnect their own connections from their personal security settings, whatever their role in the workspace.