Maintaining Your Approov Account
There isn't one single Approov metric that determines whether an account is healthy. The most useful approach is to establish what "normal" looks like for your app, and then monitor it for meaningful changes.
This overview covers the areas worth watching, the signals that justify a closer look, and a practical monitoring routine you can adopt.
What to monitor
Passing vs. failing attestations
This is your overall view of how much legitimate app activity is successfully passing Approov checks, versus how much traffic is being rejected.
A rise in failures does not automatically mean something is wrong. In many cases, Approov may simply be doing its job and rejecting modified apps, rooted or jailbroken devices, emulators, instrumentation frameworks, or other environments that fall outside your security policy.
What matters more is a sudden or unexplained change in the normal failure rate.
See App & Device Metrics for the attestation result metrics that give you this view.
Why devices are failing
Look at the rejection reasons rather than just the total number of failures.
This helps distinguish expected security detections from configuration issues. For example, a sudden increase in app-not-registered shortly after releasing a new app version may indicate that the new build or signing certificate has not been registered correctly. See Managing Registrations if you need to check this.
Increases in detections associated with rooting, jailbreaking, emulators, hooking frameworks, or other suspicious environments may represent genuine hostile or automated activity. Establish the baseline for your app so that you can understand how this changes over time.
If failures are coming from your own test infrastructure rather than real users, see Using Approov with emulators.
App versions in use
Keep an eye on which versions of your app are actively communicating with Approov. You will already be familiar with which versions are live and which your customers are using.
This is useful both operationally and from a security perspective. It can help you:
- see how quickly users are migrating to a new release;
- identify unexpected legacy versions that remain active;
- spot unusual or unregistered app builds.
We recommend checking this after every production release.
Changes around releases and configuration updates
Some of the most useful monitoring happens immediately before and after a change.
After releasing a new app version, changing an Approov security policy, updating an app signing certificate, or modifying API configuration, watch the metrics closely for unexpected changes in passing or failing traffic.
A sudden spike immediately after one of these events is much more actionable than an isolated failure.
Usage and traffic volume
Track overall usage over time and understand what your normal daily and monthly volumes look like.
Unexpected increases or decreases can be worth investigating. They may simply reflect normal business activity, but they can also identify unusual automation, a rollout problem, an integration issue, or a change in user behavior.
Your monthly Approov summary email also provides a useful longer-term view of account usage.
API and certificate monitoring
For APIs protected with Approov, we recommend enabling API monitoring. This can alert you if an endpoint becomes inaccessible, or if its certificate configuration no longer matches the pins held in your Approov account.
approov monitoring -addAPI your.domain
This is particularly useful around certificate renewals and infrastructure changes, where an unexpected certificate change could otherwise cause connectivity problems.
Security policy
It is worth periodically confirming which Approov security policies are active, and ensuring that they still reflect what you intend to allow or reject.
Metrics should be interpreted in the context of this policy. For example, a device characteristic may appear frequently, but only becomes significant if your current policy is configured to reject it.
See Security Policies for how policies are defined and customized.
Admin and user maintenance
It is important that account Admins keep the current account users up to date. This means removing users and revoking the roles of individuals who leave your organization:
approov users -list
approov users -revoke dev-1234
See User Management and Account Access Roles for the available roles and what each one can do. When removing users from your account, please be sure to edit the recipients receiving monitoring emails too.
If the configuration of personnel on your Approov account has changed, we would be more than happy to facilitate a technical onboarding for your new team. Please get in touch to let us know.
When to reach out for an investigation
The Approov team is always available to help you with your configuration. If we notice something exceptional happening with your account, we will reach out to you proactively, or you will receive a monitioring email to alert you. However, you may want to contact us to investigate further if you notice any of the following:
- a sudden increase in overall attestation failures;
- a significant change in the percentage of devices failing;
- a new or increasing rejection reason appearing;
- a spike in
app-not-registeredafter an app release; - unexpected app versions or SDK versions appearing;
- an unusual increase in traffic volume;
- API monitoring or certificate-pin alerts;
- a sharp change that coincides with a release, signing-certificate update, or security-policy change.
Failures themselves are not necessarily bad. A healthy Approov account may reject plenty of requests, because those requests genuinely should not be trusted. The question is whether the pattern is expected for your app and security policy.
A practical monitoring routine
For most customers, we suggest the following:
| When | What to do |
|---|---|
| After a new release or configuration change | Check the live metrics closely. |
| During normal operation | Review trends periodically, rather than watching individual failures. |
| Monthly | Review the Approov usage summary, passing and failing device trends, and your current security policy. |
| Continuously | Configure elevated-failure and API monitoring alerts, so the team does not need to constantly watch the dashboards. |
Open the Approov metrics dashboards with:
approov metrics
Monitoring recipients and thresholds are configured through the Approov CLI:
approov monitoring -setFailureCountThreshold 1000 -setFailurePercentageThreshold 20
approov monitoring -addAlert ops-alert@your.domain
approov monitoring -get
See Service Monitoring for the full set of options.
If you establish a normal baseline for the account first, the dashboards become much more useful: rather than asking "are there failures?", you can ask "what has changed, and why?"