Module - Security Auditor

Installation & Setup

Prerequisites

Before installation:

  1. Confirm that the target Gateway meets the declared Ignition compatibility requirement.

  2. Obtain a trusted, signed module package through your organization's approved release process.

  3. Ensure the installing account has the required Gateway module-administration permission.

  4. Confirm that the Gateway environment has persistent storage and the required outbound access for any planned report/notification destinations.

Installing the module

  1. Sign in to the Ignition Gateway with an authorized administrator account.

  2. Open the standard Gateway module-management interface.

  3. Upload the approved module package.

  4. Review the module identity, version, signature, and dependency information presented by the Gateway.

  5. Complete the Gateway installation workflow.

  6. Confirm that the module reaches its normal running state.

  7. Review Gateway logs for installation, dependency, storage, or initialization errors.

  8. Open Security Auditor > Configuration and verify that its health/status information indicates normal operation.

Gateway menu labels and restart behavior can vary with the Ignition version and deployment policy. Follow the standard installation procedure for the target Gateway.

Initial configuration

Privacy and health

Open Security Auditor > Configuration > General.

Screenshot 2026-08-17 1.10.18 PM.png
  • Review the visible health and connection status before enabling operational features.

  • Enable Anonymize Personally Identifiable Information when displayed/exported usernames and IP addresses should be reduced according to your policy.

  • Use the password-management action only under an approved Gateway secret-management procedure.

Privilege detection

Open Security Auditor > Configuration > Privilege Detection.

Screenshot 2026-08-17 1.13.39 PM.png
  1. Enter approved usernames in Excluded Users.

  2. Enter the exact monitored names in Privileged Roles.

  3. Select Notify only under Automated response for initial testing.

  4. Add a controlled Notification Method.

  5. Save the configuration and validate with a non-production account.

Do not enable role removal or session termination until account-recovery procedures and user-source behavior have been tested.

Retention and archive protection

Open Security Auditor > Configuration > Pruning.

Screenshot 2026-08-17 1.10.09 PM.png
  1. Select Enable Pruning only after agreeing the retention policy.

  2. Enter Pruning Age and select Pruning Unit.

  3. Select Export Before Pruning when an archive is required before removal.

  4. Provide Export ZIP Password through the organization's approved secret-handling process.

  5. Save and verify a controlled retention run before production use.

Protect archive passwords and exported content as sensitive operational data.

Report delivery

Open Security Auditor > Reports > Report Builder.

Screenshot 2026-08-17 1.19.26 PM.png
  1. Add a report delivery entry.

  2. Select an approved delivery type and destination.

    Screenshot 2026-08-17 1.19.37 PM.png
  3. Choose the report content and schedule that match the operational requirement.

    Screenshot 2026-08-17 1.20.30 PM.png
  4. Test delivery manually.

  5. Verify both Gateway logs and receipt at the destination.

  6. Enable the schedule after the test succeeds.

Configuration roles

Role

Typical responsibility

Gateway administrator

Installs the module, assigns permissions, manages Gateway backup/security, and approves external connectivity.

Security/operations administrator

Configures privilege policy, notification destinations, report schedules, and retention policy.

System integrator

Validates user-source names, email profiles, external destinations, and Gateway integration in a controlled environment.

Security recommendations

  • Apply least-privilege access to Security Auditor pages and administration actions.

  • Prefer HTTPS/WSS for external delivery.

  • Restrict Gateway outbound access to approved destinations.

  • Do not place reusable credentials in user-visible configuration values or shared documentation.

  • Protect Gateway backups, report exports, and retention archives.

  • Validate destructive policy actions with test users before production enablement.

Verification

After setup:

  1. Confirm module health/status is normal.

  2. Generate controlled session and project activity.

  3. Confirm that activity appears in Reports.

  4. Test privilege detection in Notify only mode.

  5. Test each report/notification destination.

  6. Verify retention/archive behavior with non-production or approved test data.

Updating the module

Before updating:

  1. Record the installed module and Ignition versions.

  2. Back up the Gateway and module-related operational data according to your organization's procedures.

  3. Export or record required configuration without exposing secrets.

  4. Install the approved updated module through the standard Gateway workflow.

  5. Verify health, reporting, privilege detection, and delivery after the update.

A certified upgrade, downgrade, or rollback matrix is not documented.

Uninstallation considerations

Before uninstalling, disable scheduled operational actions, export required evidence, and take an approved backup. Confirm data-retention and deletion requirements with your Gateway administration policy.


Last updated: