Important security events should become visible alerts—not disappear into a log.
This release turns privileged staff-security evidence into durable triage alerts, detects repeated denied privileged actions, and requires exact permission plus recent strong authentication before an alert can be acknowledged or resolved.
Automated monitoring checks
Confirms schema v24, threshold detection, idempotent sweeps, strong-auth alert closure and immutable evidence.
Trigger → detect → triage
Use an isolated QA Security Admin to generate three denied privileged actions, detect the resulting high-severity alert, prove that triage is blocked before step-up, then acknowledge/resolve it after strong authentication.
Security alert triage
Before step-up: click Acknowledge and expect a red BLOCKED result. After enrolling and stepping up, Acknowledge and Resolve should turn green.
No QA Security Admin dashboard loaded yet.
Production monitoring evidence
These remain open until ClaraWide is genuinely operating them in production.
Recent monitoring QA runs
Evidence tools
Clearing browser QA evidence does not rewrite server-owned alert history or staff-security evidence.
