Overview
Every protected endpoint, what was found on it, and the things worth a decision today.
What matters now
Devices
Sensitive data found
Counted by what a file contains, not by its name or folder. A file called notes.txt with 400 phone numbers in it is customer data.
Stories
Each story is one sequence of related events on one device, with a cause, a decision and a result.
Rules
Rules run top to bottom and the first one that matches decides what happens. Drag a row to change the order. Select one to edit it.
| Order | Rule | Applies to | Where | Looks for | What happens | Status |
|---|
New rule
Five steps, one at a time. You can go back to any step you have finished.
Tenants and detectors
Two lists that rules draw from. Change a list here and every rule using it follows, without editing a single rule.
Tenant lists
A list is a set of tenants you approve, one entry per app, each with a description so the next person knows why it is there. A list allows nothing on its own. A rule has to point at it.
Seen on your devices, not on the list
Detectors
| Detector | What it matches | Where it came from | Used by |
|---|
Configuration
Where people come from, and how you group them. Rules point at what you set up here.
Identity sources
People
| Account | Comes from | Department | Device |
|---|
Where this is stored
Groups you made in Arca
A group can hold directory accounts, directory groups and roaming devices at the same time. Rules pick a group by name.
Logs
Everything the agent recorded on all three endpoints, not only the events that became stories. When something looks unusual Arca stops it first and records why, so every block shows up here beside the ordinary traffic.
Events
Anything that became a story links to it. Everything else is here because it happened, not because it was a problem.
AI and accounts
Which AI tools and work apps are signed in on each endpoint, and whose tenant each account belongs to. Three Google accounts on one laptop is normal. Not knowing whose they are is not.
What Arca can say about an account
Apps and the accounts signed into them
This screen only reports what is signed in. Blocking, allowing and masking are decided in Rules. Pick one device, or select any account, to read it in plain English.
Agents running on these endpoints
Domains seen across the fleet
| Domain | Status | Where that comes from | Accounts | Devices | Apps |
|---|