Skip to content
Help Center

Security Monitoring Overview

View Markdown Contact support Contact support 3 min read
On this page

Overview

Persona offers enterprise-grade security monitoring through comprehensive audit logging and real-time event streaming. Our platform provides the visibility and control necessary to meet your organization’s security requirements while maintaining regulatory compliance.

While Persona provides tools to view and monitor logs within the Dashboard, we highly encourage you to import the logs into your organization’s SIEM to develop your own monitoring and alerting rules.

There are 3 categories of logs.

User Audit Logs

User Audit Logs track all human activity within your dashboard, including logins, configuration changes, data access, and role modifications. Logs are retained for 6 months.

  • Instructions on how to view User Audit Logs on your Dashboard are available here: Browsing User Audit Logs.
  • Details on getting User Audit Logs via our API are available in Persona’s API documentation: How to list all user audit logs.
  • Persona also supports BYOS (Bring Your Own Storage) delivery of User Audit Logs. Speak with us directly to learn more.

API Logs

API Logs record all programmatic API activity, including request/response details, authentication events, and call patterns. Logs are retained for 2 weeks.

  • Instructions on how to view API logs on your Dashboard are available in Persona’s API documentation: How to view API logs.
  • Details on retrieving API Logs via our API are available in Persona’s API documentation: API introduction.

Events

Webhooks Events are available for key events during the inquiry flow. Events are retained for 90 days.

Review your dashboard users in Posture

Use Posture when you need to review who on your team can access the Persona dashboard, how they use it, and activity that may need investigation. It covers your organization’s dashboard users, not the people you verify. Only organization Admins can access it.

  1. In the Persona dashboard, go to Governance > Posture. If you see No dashboards yet, select Generate Dashboards to load your organization’s users, sessions, and activity. Select it again when you need to refresh the view; the page does not load this data automatically.
  2. On Overview, review who is logged in, active sessions, and the seven-day activity charts. Select Users to search for a teammate and open their details, including roles, permissions, MFA status, sessions, and activity.
  3. In a user’s Permissions tab, review permissions marked unused before changing access. Posture infers use from matching successful audit-log activity in the last 30 days, so an unused label does not prove the permission is unnecessary. If you choose Create custom role, review the permissions it would keep: assigning it replaces that user’s existing roles.
  4. Open Anomalies to investigate concurrent sessions in different locations and unusual audit or download activity. Review the person’s activity before dismissing a finding; dismissal requires a note and appears in the dismissal history.

If data is missing or Posture is unavailable

  • If you cannot see Posture under Governance, check that you are signed in as an organization Admin. If you are an Admin and the page is still absent, contact Persona Support to check access for your organization.
  • If you see No dashboards yet or your data appears old, select Generate Dashboards and check the Last generated time. If loading fails, try again; if it continues to fail, contact Persona Support.
  • If a metric or permission-usage detail is unavailable, do not treat a blank or missing value as zero activity. Posture depends on session and audit-log data; use User Audit Logs for a closer review.
  • Location findings depend on location data observed for active sessions, so the absence of a finding does not rule out suspicious sign-ins. Review the user’s sessions and audit logs during an investigation.
Was this page helpful?If something is missing, let us know and we will take a look.
Thanks for the feedback. It helps us improve these docs.