Getting started
Concepts
| Term |
Meaning |
| Console |
The central control plane you log into to see detections and manage the fleet. |
| Agent |
A lightweight, outbound-only process on each monitored host. |
| Source |
A place detections come from (an endpoint, a cloud provider, a SaaS audit log). |
| Detection |
A signal surfaced from a source into the console for review. |
| Job |
A signed, allow-listed instruction the console sends to an agent. |
How it fits together
Your hosts / cloud sources
│ (agent connects OUTBOUND — no inbound ports)
▼
SheerSight console ──► detections, fleet view, response
▲
│ Zero-Trust login (SSO / one-time PIN)
You
First steps
- Get access to the SheerSight console (your team admin invites you; login is
gated by Zero-Trust SSO or a one-time PIN).
- Onboard your first host — see Onboarding a VM.
- Connect your sources — paste read-only credentials for GitHub, AWS,
Google Workspace, and more; see Connecting sources.
- Confirm data is flowing and set your notification preferences in the
console.
Next