Skip to content

Getting started

Concepts

Term Meaning
Console The central control plane you log into to see detections and manage the fleet.
Agent A lightweight, outbound-only process on each monitored host.
Source A place detections come from (an endpoint, a cloud provider, a SaaS audit log).
Detection A signal surfaced from a source into the console for review.
Job A signed, allow-listed instruction the console sends to an agent.

How it fits together

  Your hosts / cloud sources
        │ (agent connects OUTBOUND — no inbound ports)
        ▼
     SheerSight console  ──►  detections, fleet view, response
        ▲
        │  Zero-Trust login (SSO / one-time PIN)
      You

First steps

  1. Get access to the SheerSight console (your team admin invites you; login is gated by Zero-Trust SSO or a one-time PIN).
  2. Onboard your first host — see Onboarding a VM.
  3. Connect your sources — paste read-only credentials for GitHub, AWS, Google Workspace, and more; see Connecting sources.
  4. Confirm data is flowing and set your notification preferences in the console.

Next