> For the complete documentation index, see [llms.txt](https://docs.emseapea.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.emseapea.ai/admin-guide/dashboard-and-risk.md).

# Dashboard and risk flags

The dashboard is the inventory of every employee-built app in your org: stat tiles (apps, pending requests, failed scans, stale apps, over-broad access) above a filterable table.

Three risk flags, computed from the event log — never hand-maintained:

* **Failed scan** — the app's last deploy attempt was blocked by secret scanning or Semgrep. The findings are stored on the app's Scans tab.

  **The absence of this flag is not a clean bill of health.** Both scanners look for patterns they already know about. A pass means nothing matched those patterns — not that the code is safe, and not that it was reviewed by anyone. Treat a green scan as one check that ran, and read the app's Scans tab for exactly which rules that was.
* **Stale** — no commits, deploys, or gateway traffic in N days (default 30, configurable per org). Stale apps with live credentials are decommission candidates.
* **Over-broad** — the app's credential grants systems the app has never actually called through the gateway. Observed usage comes from real egress events, so this flag tells you where to narrow access.

Click any app for its detail page: the lineage graph (owner → intent → repo → credential → systems → deployments), events, scans, and deployments.
