Skip to content

Console guide

The console is where you watch detections, manage the fleet, and respond.

Signing in

Access is gated by Zero-Trust — sign in with your organization's SSO or a one-time PIN sent to your email. Unauthenticated requests never reach the app.

Fleet view

See every monitored host, its status (online/offline), and what it's reporting. Use it to confirm new hosts after onboarding.

Working with detections

  • Review detections surfaced from your sources.
  • Triage and record a disposition.
  • Configure how and where you're notified.

Responding

Response actions are carried out by sending signed jobs to agents. Agents only execute a fixed allow-list of actions — the console can't ask a host to run arbitrary commands. See Security.

More detailed walkthroughs and screenshots are coming as the console UI settles.