The dashboard
The dashboard is a set of cards. Which ones you get depends on your role, and owners see an extra one until their setup is finished.
Expiration timeline
Section titled “Expiration timeline”Everyone sees this card. It plots your leaf certificates by renewal deadline over 30, 90 or 180 days. A chip in the corner counts what falls due in the next 15 days; it turns red once something is due within 5. Above the plot, three tiles: nearest deadline, overdue count, total in range.
Select a marker to open what it covers. A marker holding a single certificate opens that certificate. One holding several opens the certificate list sorted by expiry, unfiltered, so you may need to scroll to the dates you were looking at. The Overdue marker is the exception: it opens the expired list directly. Markers cover a single day on the 30-day range and a wider span on the others.
The card counts leaf certificates only, never CA certificates.
Monitoring operations
Section titled “Monitoring operations”Operators and owners only. It answers “is NoCert working right now”.
Coverage evidence on the left gives four numbers: certificates, endpoints, Sentinels online out of total, and External queue, the public scans waiting to run. Below them sits the share of your observation records refreshed in the last 24 hours, then Domain enumeration, naming the next domain due and counting down to it.
Recent technical activity on the right lists the last four things that happened: scan batches, subdomain enumerations, and certificates entering the inventory. Live work sorts first.
Two things the card will not tell you:
- An empty feed means nothing was recorded, not that everything passed. The card says as much itself.
Sentinels onlineshows a dash rather than0/2when every Sentinel is offline, so no Sentinels and all Sentinels down look identical.
The Certificates number here counts your whole inventory, CA certificates included, so it will not match the leaf-only totals on the timeline.
Discovery feed
Section titled “Discovery feed”Viewers get this instead of Monitoring operations: the five most recent leaf certificates to enter the inventory, each with its issuer and where it was found.
Public TLS lifetime schedule
Section titled “Public TLS lifetime schedule”Everyone sees this card. It projects future renewal workload and reports nothing about your current state.
The CA/Browser Forum is cutting the maximum lifetime of public certificates in stages, from 398 days to 200, then 100, then 47. For each stage the card divides a year by that cap and multiplies by your leaf count, estimating how many issuance events a year you are heading for.
Existing certificates keep their current expiry; the caps apply by issue date. Private PKI is out of scope.
Finish setup
Section titled “Finish setup”Owners see this until it is done, then it disappears for good.
What it asks for depends on the account. An owner who signs in through an identity provider gets two items: verify a domain, and add a backup alert channel. A local owner also gets set a password and enable 2FA. A fifth appears once the organization has other local members. Deploying a Sentinel is listed as optional and does not block completion.
The backup channel item is stricter than it looks. It wants an enabled Slack, Teams or Discord channel alongside email on a target attached to your default rule. A channel left unattached, or attached to an escalation target instead, does not count. The card names the missing piece only when email is still enabled; turn email off and it asks for both, whatever else you have configured.
The Certificates badge
Section titled “The Certificates badge”The number beside Certificates in the sidebar counts what is expired plus what expires within 5 days, ignoring anything you have muted. Hover it for the split.
What refreshes, and when
Section titled “What refreshes, and when”The timeline refreshes every 60 seconds, and every 15 while a scan is running. Live scan rows refresh every 5 seconds and the recorded activity list every 60, whatever else is happening. Polling stops while the tab is hidden rather than while the window is unfocused, so a dashboard on a second screen keeps up.
Times on the activity rows are relative. Hover one for the exact instant, given in UTC with your local time beside it.
A brand-new organization
Section titled “A brand-new organization”Straight after signup the dashboard already has something in it, because NoCert scanned the domain from your email address without waiting for you. Expect a first certificate count, a first endpoint count, and activity rows.
What stays empty until you verify a domain is the recurring side: no enumeration schedule, and no new hosts appearing over time. Monitor your first domain covers the step that starts it.