Surface
Workspace-level settings modal, currently showing the Security subpage (which is paywalled).
Layout
Centered modal overlay with left nav + right content.
Top header
⚙ Settingstitle.×close button (top-right).
Left nav
Workspace selector — sid179's Workspace ▼ at top.
Section: Workspace - Workspace overview - Workspace collaborators - Workspace usage - Integrations - Security (active)
Section: Account - Billing - Account seats - Account usage - Advanced
Section: User - Profile - Personalization
The IA separates Workspace (team/project-scoped), Account (billing/seats — company scope), and User (individual scope). This is classic enterprise-ready settings nesting. Anything.com's per-project settings (see Anything.com - Project Settings) have no equivalent workspace/account/user hierarchy — they are single-user / single-workspace by IA.
This alone is a meaningful enterprise-readiness moat: multi-tenant-friendly settings structure + named admin roles + workspace-level usage tracking.
Right pane — Security Scanning (paywalled)
Shield icon + title
"Security Scanning"
Subtitle
"Identify and remediate vulnerabilities in your workspace dependencies"
Feature list (each with a green check)
- ✓ Scan workspace Apps for security vulnerabilities
- ✓ View detailed CVE information and severity levels
- ✓ Track security scan history across your workspace
- ✓ Download Software Bill of Materials (SBOM) reports
Upsell
- "Upgrade to Core to access security scanning."
+ Upgrade to unlock— blue primary pill button.
Strategic observations
SBOM (Software Bill of Materials) reports are a B2B-procurement-grade feature. Security-conscious buyers (finance, healthcare, government) require SBOM for vendor assessments. That Replit sells SBOM as part of Core means Core is a B2B-ready SKU, not just a power-user upgrade. This materially strengthens Replit - ICP ring 3 (enterprise) and Enterprise Developers segment.
Anything.com - Tech still shows no security messaging at all. This gap is growing, not shrinking.
- CVE severity information — shows Replit is consuming a real vulnerability database (NVD likely), not surface-level dependency list.
- Scan history — audit log mentality.
Components observed
| Component | Purpose |
|---|---|
| Modal overlay (not full-page) | Keep user in context |
| 3-section nav (Workspace / Account / User) | IA nesting |
| Bullet list with checkmarks | Feature itemization |
| Full-feature gate (no free-tier equivalent) | Core-only capability |
| Upsell pill under feature list | Dismissible-looking but only path |
Sources
- !Settings.png