Console guide¶
The console is where you watch detections, manage the fleet, and respond.
Signing in¶
Access is gated by Zero-Trust — sign in with your organization's SSO or a one-time PIN sent to your email. Unauthenticated requests never reach the app.
Fleet view¶
See every monitored host, its status (online/offline), and what it's reporting. Use it to confirm new hosts after onboarding.
Working with detections¶
- Review detections surfaced from your sources.
- Triage and record a disposition.
- Configure how and where you're notified.
Responding¶
Response actions are carried out by sending signed jobs to agents. Agents only execute a fixed allow-list of actions — the console can't ask a host to run arbitrary commands. See Security.
More detailed walkthroughs and screenshots are coming as the console UI settles.