The 17 Notion security checks Black Cat runs
Black Cat SSPM evaluates 17 security policies against your Notion configuration on every scan, classifies each finding by risk, and provides remediation steps. Browse them by topic below.
How to connect Notion — what access Black Cat needs, and why.
Access control & privilege
6 checks · highest severity: medium
Data sharing & exposure
7 checks · highest severity: high
Configuration hardening
3 checks · highest severity: medium
Access control & privilege (6)
- Guest User Sprawl severity: medium
- Member Without Email severity: medium
- Bot Without Description severity: low
- Excessive Workspace Members severity: low
- Excessive Guest Ratio severity: medium
- Bot User Without Name severity: low
Data sharing & exposure (7)
- Stale Public Page severity: high
- Root Level Public Page severity: high
- Root Level Public Database severity: high
- Inline Public Database severity: medium
Configuration hardening (3)
- Stale Page severity: medium
- Orphaned Page Without Parent severity: low
- Stale Database severity: medium
Other checks (1)
severity: medium Audit Log Anonymous Actor fix difficulty: medium #
Investigate audit log events with unidentifiable actors
- Review the flagged audit log event details in the Notion audit log
- Determine if the event was triggered by a system process, API integration, or unknown user
- If caused by an integration, verify the integration is authorized and document its expected behavior
- If the actor cannot be identified, investigate potential unauthorized access
- Enable SAML SSO to ensure all user actions are attributed to identified accounts
- Review workspace security settings and integration permissions
Satisfies: NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-10.1