Skip to main content

Security Activity Timeline

The Security Activity Timeline is one place to see what security-relevant things happened across your workspace, in time order. It merges activity that already lives in other Dralvia surfaces (link and contract scans, browser protection, sign-ins, response actions, endpoint agent events, repository scans, AI agent policy decisions, and email remediation) into a single feed so you do not have to open each console separately.

It reads existing activity only. It does not create new events, and it never shows sample or placeholder data.

Overview​

Every entry in the feed carries:

  • A surface chip (Scans, Browser, Identity, Response, Endpoints, Repositories, AI agents, or Email).
  • A severity (Critical, High, Medium, Low, or Info).
  • The time it happened.
  • A short title and one-line summary.
  • A What this means explanation you can expand, so the signal is never shown without context.
  • A View link back to the source surface for the full detail.

The newest activity is shown first, grouped by day.

What each surface shows​

SurfaceWhat it records
ScansURL, domain and smart-contract scan verdicts
BrowserNavigations, downloads and extension state from browser protection
IdentitySign-ins and sign-in risk signals
ResponseActions taken on a security surface, and whether they completed
EndpointsSecurity events reported by the endpoint agent on your devices
RepositoriesRepository scan verdicts, including exposed secrets and dependency risk
AI agentsAI agent requests checked against your workspace policy
EmailRemediation actions on messages, with the status the mail provider returned

A repository scan that did not finish is shown at info severity rather than as a clean result: it has no verdict, and an unfinished scan is not a pass. A queued email remediation is likewise shown as info until the provider confirms it, because a requested action is not a completed one.

What it is for​

Use it to answer "what has been going on in my workspace" without hopping between consoles:

  • Spot a risky scan verdict, a blocked page, an unfamiliar sign-in, and a session revocation in one scroll.
  • Filter to a single surface (for example only Identity) or a single severity (for example only High) to focus.
  • Follow the View link to open the originating console when you need the full evidence.

How to use it​

  1. Sign in to Dralvia and open the dashboard.
  2. In Protection Modules, choose the Operations area and open Security Activity Signals.
  3. The timeline loads the most recent activity for your workspace (up to the last 30 days).
  4. Use the surface, severity, asset, time-window, and workflow-state filters to focus the feed.
  5. Select What this means on any entry to read a plain-language explanation.
  6. Select View to open the source surface for the full record.

Saved investigation views​

Use Saved investigation views to keep the current module, severity, asset, time-window, and workflow-state filters.

  1. Set the activity filters you need.
  2. Enter a view name.
  3. Optionally choose Use as my default.
  4. Select Save current.

Selecting a saved view restores its filters. Owners can change its name or filters with Update, or remove it with Delete. Deleting a view removes only the saved preference; it never deletes activity or findings.

Private views are visible only to their owner. Workspace owners and allowed administrators can choose Shared with workspace. Other workspace users can use shared views but cannot publish a private view as shared. Views from another workspace are never listed.

If saving fails, current filters and activity remain visible. Duplicate owner names, unsupported filters, and denied sharing requests show an error without replacing the active view.

Saved views contain filters only. They do not duplicate activity records or create a second findings store.

API​

The same data is available from the public API:

GET /api/security/activity

Query parameters:

ParameterMeaningDefaultMaximum
limitNumber of entries to return50200
since_hoursHow far back to look, in hours168 (7 days)720 (30 days)
surfaceRestrict to a surface (scan, browser, identity, response, edr, repo, agent, email). Repeatable.all
severityRestrict to one severity (critical, high, medium, low, info)all

Each item is returned in a single normalized shape:

{
"surface": "scan",
"event_type": "url_scan_verdict",
"severity": "critical",
"occurred_at": "2026-07-10T14:00:00+00:00",
"title": "malicious.example",
"summary": "URL scan verdict: malicious (score 90)",
"explanation": "A link or website was scanned and scored. ...",
"reference": { "kind": "scan", "id": "scan-1", "href": "#/scan?target=malicious.example" }
}

The response also includes counts.by_surface and counts.by_severity for the current window.

When part of the timeline is unavailable​

The timeline is assembled from one source per surface. If a source cannot be read, the response still returns the surfaces that worked, and says so:

{
"degraded": true,
"unavailable_surfaces": ["identity"]
}

degraded is false and unavailable_surfaces is empty on a healthy response. When degraded is true, treat the timeline as incomplete for the named surfaces: events may exist there that are not in this response. Do not read the absence of events on a listed surface as "nothing happened".

Open the timeline from the hamburger menu under Workspace Security Operations → Security Activity. For URL scan entries, View opens the URL & Phishing Scanner with that website filled in. It does not point to a separate scan-detail page. The compatibility route accepts existing #/scan links, so older stored activity does not produce a missing-page screen.

Saved-view persistence uses GET and POST /api/security/saved-views, plus PATCH and DELETE /api/security/saved-views/{id}. Saved filters include module, severity, asset, since_hours, and workflow_state.

API error quick reference​

StatusMeaningWhat to do
401Not signed in, or no workspace context on the requestSign in, or include your API key and workspace context.
403Your plan does not include this moduleAvailable on Pro and Enterprise. Compare plans in the dashboard.
429Too many requests in a short timeSlow down and retry after a short pause.
500Temporary service errorRetry shortly. The dashboard shows a "Try again" action.

Plan availability​

The Security Activity Timeline is available on Pro and Enterprise. On lower plans the module shows a locked state with a link to compare plans.

Limits​

  • It is an aggregation view. It surfaces activity that other Dralvia surfaces already recorded for your workspace, so a surface you have not enabled contributes nothing to the feed.
  • The current feed includes URL and contract scans, browser protection, identity events, response actions, endpoint agent events, repository scans, AI agent policy decisions, and email remediation. Report, case, EvidencePack, cloud posture, and deception activity are not included yet.
  • The window is capped at the last 30 days.
  • Activity is scoped to your own workspace only.
  • Asset matching applies to the normalized activity currently loaded for the selected time window. Workflow state applies to response actions that expose a normalized state.

Where it appears​

Dashboard, Protection Modules, Operations area, Security Activity Signals.