New Security Center: role-based access and audit logs

Granular role-based access control, complete audit logs and clear controls, so you decide exactly who can see and do what, and can prove it later.

Product

Overview

Control, and proof of control

Security is not a feature you bolt on, it is who can do what, and being able to show it.

The new Security Center gives you granular role-based access control, so each person sees exactly what they should and nothing more. Every meaningful action is written to an audit log you can review later.

It is designed to be understandable, not just powerful: clear roles, sensible defaults, and a record you can point to when someone asks what happened and when.

Why it matters

Access you can prove, not just promise

Trust grows when control is visible.

Deciding who can see and do what is only half the job; the other half is being able to show it later. The Security Center pairs granular roles with a complete, tamper-evident audit trail.

That means an access review takes minutes, not a week of guesswork, and when a customer or auditor asks a hard question, the answer is already recorded.

Control and evidence together

Role-based access

Grant the exact permissions each person needs, nothing more, nothing less.

Complete audit logs

Every sensitive action is recorded with who, what and when.

Review-ready

Export a clear access report whenever compliance comes knocking.

What you get

In the box

  • Granular role-based access control
  • Complete, reviewable audit logs
  • Clear, sensible permission defaults
  • Controls that are easy to understand and manage

In practice

Security you can operate, not just admire

Central controls only help if someone actually uses them, so the Security Center is built around the questions admins ask weekly: who has access to what, what changed since last review, and which sessions look unusual right now.

Access reviews stop being a quarterly spreadsheet exercise. Because roles, devices and audit events live in one place, revoking a leaver's access or tightening a permission takes a minute, and the log proves it happened.

The same visibility calms audits. When a compliance question arrives, you export the trail for the period in question instead of reconstructing history from five tools, the difference between an afternoon and a week.

The strongest access control is the one your team actually understands, because a permission nobody reads is a permission nobody enforces.

Team for AppsProduct & Engineering

We build software for teams who want their tools to fit the way they actually work — web, mobile, AI and the systems that tie them together. We write here about what we learn shipping it.

Have a project in mind?

Tell us what you're building and we'll get back to you within one business day.