1Security
Screens

Today

The first screen after sign-in - what deserves your attention on this tenant today, ranked by risk and urgency, with a five-minute band you can clear before your first coffee.

Today

The Today screen is the front door of 1Security. It answers one question the moment you sign in: what should I do on this tenant today, in what order, and how long will it take? Everything on it is something you can act on - a decision to make, an action to retry, an anomaly to triage, a consent to grant. There are no vanity counters. Act on an item and it disappears, because the state behind it changed; skip an item and it stays away until the next day.

Three bands

The page is cut into three bands, top to bottom:

  • If you only have 5 minutes. A short list of items that each resolve with one in-app decision - approve or reject a batch of actions, retry the failed ones, decide the owner reviews addressed to you, triage a handful of critical anomalies, confirm an attestation. 1Security estimates how long each takes and fills the band to about five minutes, cheapest-per-point first. The band only appears when there is something for it; an empty band is the product working, not a bug.
  • The rest of today. Everything else worth your attention, ranked: open anomalies, findings assigned to you, attestations coming due, Microsoft Secure Score recommendations (one at a time, rotating so an irrelevant one never becomes the only thing you see), setup gaps such as a missing consent or a tenant with a single admin.
  • In progress. Long-running work you are waiting on rather than doing: the initial scan, actions that are applying or being confirmed in Microsoft 365.

How items are ranked

Every item carries a severity, a clock if it has one (a grace period ending, a review date), and whether it is addressed to you personally. Items with a clock in the next 24 hours rank first, then items new since your last visit, then everything else by severity. Items addressed to you rank above tenant-wide ones. Counts feed the rank only mildly - twelve failed actions are not twelve times more urgent than one.

The optional preset above the list (security admin, compliance owner, AI governance, MSP operator) reorders the page for the kind of admin you are. It never hides anything.

Skipping and snoozing

Every card has a hide control. Skip for today hides the item until tomorrow. Setup-style items that are not time-critical - pick your compliance frameworks, set up alerting, invite a second person, grant a consent - can also be snoozed for 7, 30 or 90 days, or hidden forever. Skips are yours alone: two admins of the same tenant keep separate lists. "Show hidden items" in the header brings everything back.

What feeds it

Band itemComes from
Actions about to apply themselves, awaiting approval, failed, unconfirmedThe Action Center registry
Decisions addressed to youOwner reviews on resources you own
Critical and open anomaliesAnomalies, open episodes above the alert line
Security tasks assigned to youFindings routed to your user
Attestations due, frameworks to confirmCompliance
Secure Score recommendationsSecurity score, once Secure Score access is granted
Set up alertingAlerting, while no rule delivers anywhere
Connect X, invite a second personTenant consents and accounts

Consent reminders are capped at two per day so they never drown real work. If a feed cannot be loaded, the page says which one and shows the rest.

What an administrator on custom permissions sees is set by the Today row of the permission matrix. View own shows only what is addressed to them - owner decisions and assigned security tasks. View all adds the tenant-wide items, each one only when the same person can also view that section tenant-wide. With neither, the screen is not available.

Count-based cards carry a 30-day line with two deltas, since yesterday and since last week. Cards about apps, licences, sites and files draw it from a hidden trend policy that 1Security scans daily, so the line is the same one Trends would show; the small trend button on such a card copies it onto your Trends board as a visible trend you can rename, tune or delete. Anomaly and action cards draw their line from the registries themselves, as judged today, so an anomaly dismissed yesterday disappears from every past day too. Yes/no cards, such as a consent to grant, have no history.

The Daily brief rule in Alerting mails the same page every morning: the 5-minute band, today's cards with their deltas, savings and what is in progress. Recipients, the hour and the digest toggle are managed there like any other rule; quiet hours apply.

Where the graph went

The organisation graph that used to be the home screen now lives under Organisation graph in the navigation, and behind the link in the Today header.

On this page