Menu
Feedback
Start here
Tutorials


Tutorials
Explore in-depth tutorials for operating your VTEX store.
Tutorials
Security
VTEX Shield
Security Monitor

This feature is part of VTEX Shield. If you are already a VTEX customer and want to adopt VTEX Shield for your business, please contact Commercial Support. Additional fees may apply. If you are not yet a customer but are interested in this solution, please complete our contact form.

Security Monitor is a dashboard that helps merchants identify and manage potential risks in their environment in real time. The tool identifies configuration risks and the behavior of admin users, then notifies merchants via email, enabling them to take preventive action against security vulnerabilities.

To access the dashboard, follow the steps below:

  1. In the VTEX Admin, go to Dashboards, or type Dashboards in the search bar.
  2. Under Security Monitor, click Security Monitor Dashboard.

{"base64":"  ","img":{"width":1398,"height":643,"type":"png","mime":"image/png","wUnits":"px","hUnits":"px","length":73703,"url":"https://raw.githubusercontent.com/vtexdocs/help-center-content/refs/heads/main/docs/en/tutorials/Security/VTEX%20Shield/security-monitor_1.png"}}

Security Monitor displays the findings in three tabs based on their status:

In all tabs, you can:

Below, you will find specific details about the information available in each tab and their related actions.

Open

The Open tab displays the threats detected by the Security Monitor that have not yet been managed or snoozed.

The top bar displays the total number of findings and the number of threats by severity level (high, medium, or low).

{"base64":"  ","img":{"width":1148,"height":103,"type":"png","mime":"image/png","wUnits":"px","hUnits":"px","length":7087,"url":"https://raw.githubusercontent.com/vtexdocs/help-center-content/refs/heads/main/docs/en/tutorials/Security/VTEX%20Shield/security-monitor_2.png"}}

The tab displays the full list of open findings in a table, from the most recent to the oldest:

Column fieldsDescription
FindingUser email or application key related to the finding.
TypeType of finding detected:
  • Old app keys: Application keys that were created more than 6 months ago.
  • Excessive Super Admins: Users or application keys with the Owner (Admin Super) role.
  • Leaked App Keys: Application keys that have been leaked on the web and identified by the VTEX Security team.
  • Inactive Users: Users who have not accessed the Admin in the last 30 days.
  • Excessive Permissions: Users or application keys with access to resources they did not use in the last 30 days.
DetectedDate the finding was detected.
SensorSensor that detected the threat:
  • VTEX Identity
SeverityLevel of threat severity, determined by the impact or potential risk associated with the threat:
  • High
  • Medium
  • Low
Action menu ⋮Menu of possible actions for the finding:

Managing findings

To manage a finding, follow the instructions below:

  1. In the finding row, click the ⋮ menu.

  2. Select Manage.

    You will be redirected to the Users screen in Account Management to edit the roles associated with the specific user or application key.

Snoozing findings

To move a finding to the Snoozed tab, removing it temporarily from the Open tab, follow the instructions below:

  1. In the finding row, click the ⋮ menu.
  2. Select Snooze.
  3. Choose the number of days you want the finding to remain in the Snoozed tab. The options available are: 7, 90, or 120 days.
  4. Click Snooze.

{"base64":"  ","img":{"width":519,"height":369,"type":"png","mime":"image/png","wUnits":"px","hUnits":"px","length":17885,"url":"https://raw.githubusercontent.com/vtexdocs/help-center-content/refs/heads/main/docs/en/tutorials/Security/VTEX%20Shield/security-monitor_3.png"}}

Snoozed

The Snoozed tab lists the findings that have been snoozed in a table, with the same information as described in the Open tab.

In the Snoozed tab, the actions menu in each finding's row only displays the Unsooze option, which allows you to undo the snooze action and send the finding back to the Open tab.

Closed

The Closed tab displays a list of findings that have been managed and are therefore closed. It displays the following information in a table:

Column fieldsDescription
FindingUser email or application key related to the finding.
TypeType of finding detected:
  • Old app keys: Application keys that were created more than 6 months ago.
  • Excessive Super Admins: Users or application keys with the Owner (Admin Super) role.
  • Leaked App Keys: Application keys that have been leaked on the web and identified by the VTEX Security team.
  • Inactive Users: Users who have not accessed the Admin in the last 30 days.
DetectedDate the finding was detected.
ClosedDate the finding was closed.
Closed ByIndicates that the finding was automatically closed after being managed by an admin user.
SeverityLevel of threat severity, determined by the impact or potential risk associated with the threat:
  • High
  • Medium
  • Low

Searching for findings

In the search bar, enter the user's email address or the name of the application key to find related findings.

Filtering findings by type

By clicking Type , you can choose one of the finding types to filter the results displayed in the list. Click Apply to confirm the chosen filter, and the list will be updated.

{"base64":"  ","img":{"width":362,"height":398,"type":"png","mime":"image/png","wUnits":"px","hUnits":"px","length":19655,"url":"https://raw.githubusercontent.com/vtexdocs/help-center-content/refs/heads/main/docs/en/tutorials/Security/VTEX%20Shield/security-monitor_4.png"}}

Editing notification settings

To edit the admin users who will be notified about the findings, follow the steps below:

  1. Click the gear button in the top right corner of the screen.

  2. Enter the email address of the user that will receive notifications and press Enter. Repeat this step for as many users as you want.

    To remove a user, click the X next to their email.

  3. Click Save.

{"base64":"  ","img":{"width":739,"height":530,"type":"png","mime":"image/png","wUnits":"px","hUnits":"px","length":51588,"url":"https://raw.githubusercontent.com/vtexdocs/help-center-content/refs/heads/main/docs/en/tutorials/Security/VTEX%20Shield/security-monitor_5.png"}}

Learn more

Contributors
2
Photo of the contributor
Photo of the contributor
+ 2 contributors
Was this helpful?
Yes
No
Suggest Edits (GitHub)
VTEX Shield
« Previous
Penetration tests and vulnerability notifications
Next »
Contributors
2
Photo of the contributor
Photo of the contributor
+ 2 contributors
On this page
Still got questions?
Ask the community
Find solutions and share ideas in the VTEX community.
Join our community
Request support from VTEX
For personalized assistance, contact our experts.
Open a support ticket
GithubDeveloper portalCommunityFeedback