The 27 Sentry security checks Black Cat runs
Black Cat SSPM evaluates 27 security policies against your Sentry configuration on every scan, classifies each finding by risk, and provides remediation steps. Browse them by topic below.
How to connect Sentry — what access Black Cat needs, and why.
Access control & privilege
18 checks · highest severity: critical
Data sharing & exposure
7 checks · highest severity: medium
Access control & privilege (18)
- SSO Disabled severity: high
- Default Role Not Member severity: medium
- Excessive Admins severity: medium
- Dormant User severity: medium
- Old Pending Invite severity: medium
- Inactive Admin severity: medium
- Expired Invitation Not Removed severity: low
- Events Member Admin Disabled severity: medium
- Alerts Member Write Enabled severity: medium
- Long-Term Inactive Member severity: medium
- Deactivated Member Not Removed severity: medium
- Owner Role Review severity: high
- Pending Admin Invite severity: high
- Inactive Member 90 Days severity: medium
- Default Role Elevated to Admin or Owner severity: critical
- Expired Admin Invite Not Cleaned Up severity: medium
- Admin Redundancy Missing severity: high
- Very Stale Pending Invite severity: high
Data sharing & exposure (7)
- Enhanced Privacy Disabled severity: medium
- Open Membership severity: medium
- Event Attachments Access severity: medium
- Data Scrubber Disabled severity: medium
- Data Scrubber Defaults Disabled severity: medium
- Debug Files Access severity: low
Other checks (2)
severity: high Member Without 2FA fix difficulty: easy #
Require all active members to enroll in two-factor authentication
- Sign in to Sentry as an organization owner or admin
- Navigate to Settings > Security (https://sentry.io/organizations/<org>/settings/security/)
- Enable "Require Two-Factor Authentication" to enforce 2FA for all members
- Notify affected members to set up an authenticator app or hardware key before the deadline
- Members without 2FA will be locked out until they complete enrollment
- Verify enrollment status in Settings > Members after the enforcement deadline
Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: critical Admin Without 2FA fix difficulty: easy #
Immediately enforce two-factor authentication on all admin-level accounts
- Sign in to Sentry as an organization owner
- Navigate to Settings > Members (https://sentry.io/organizations/<org>/settings/members/)
- Identify all admin, manager, and owner accounts lacking 2FA
- Contact each affected admin directly and require 2FA enrollment before next login
- Enable "Require Two-Factor Authentication" in Settings > Security to prevent future gaps
- Consider temporarily downgrading admins who cannot enroll promptly until 2FA is active
Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4