Identity watchdog
Once you’ve connected Google Workspace or Microsoft Entra ID, Sencai’s identity watchdog polls your directory provider’s own security and audit signals and surfaces them alongside the rest of your platform security surface - no separate agent or configuration is needed beyond the directory connection itself.
What it collects
Section titled “What it collects”The watchdog polls each connected provider’s admin activity/audit APIs and maps what it finds into a shared taxonomy so events from different providers show up in one place: login anomalies, MFA/2-step verification being disabled, admin privileges granted, account suspensions, password resets, new admin accounts, OAuth app authorizations, and bulk deletes, among others. Not every event type is produced by every provider - only the kinds of activity that provider’s own API actually reports appear.
Event feed
Section titled “Event feed”Settings → Watchdog (/gravity/workspace/watchdog) lists events for
your currently selected organization, each with a source badge (Google
Workspace or Microsoft Entra), severity (Critical / High / Medium / Low /
Info), and status.
Filter by severity, status, or a specific chip (Login Anomaly, MFA Disabled), and - when your organization has events from more than one source - filter by source too. Expand a row for the underlying event detail, including actor/target email, IP address, and the raw event payload where available.
For each event you can:
- Mark as resolved - you’ve reviewed it and addressed it (or confirmed no action was needed).
- Mark as false positive - the event doesn’t represent a real issue.
Both actions are logged with a timestamp; neither is reversible from this screen once applied, though you can act on the same event again through your identity provider directly if needed.
Known limitation: Microsoft Entra sign-in logs
Section titled “Known limitation: Microsoft Entra sign-in logs”Reading Entra sign-in activity requires a paid Microsoft Entra ID P1 or P2 license on your tenant - this is a licensing restriction on Microsoft’s side, not something Sencai’s consent request can unlock. On a tenant without that license, sign-in-based events (like login anomalies) won’t appear for your Entra-connected directory, while directory audit events (admin actions, privilege changes) still work normally regardless of license tier.
Security posture (Google Workspace)
Section titled “Security posture (Google Workspace)”Settings → Security Posture (/gravity/workspace/security-posture)
is Google-Workspace-specific: it reports 2-step verification (2SV)
enforcement status, suspicious login counts, and a computed security score
out of 100, weighted most heavily toward admin accounts that don’t have 2SV
enabled.
Select Assess Now to run a fresh assessment on demand, or wait for the next scheduled one. A score only appears once an assessment has run for your organization - an organization that’s never been assessed shows “Not Yet Assessed”.
The page also lists concrete next steps when your score has room to improve - enforcing 2SV domain-wide, requiring it specifically for admin accounts, and reviewing suspicious logins in Google Admin’s own audit reports.
What’s next
Section titled “What’s next”- Single sign-on - connect a directory provider
- Workspace directory - the underlying synced directory data
- Security overview - how this fits into your platform-wide security posture
- Audit log - Sencai’s own action history, separate from these provider-sourced events