Use the console
Open Getting started for a guided path. You can return to any step. On a phone, Menu opens navigation to agent connections, policies, people and monitoring.
Try a safe example
Choose a workstation, protected domain controller or production target and select Run safe example. The result explains allow, deny or approval using fixed synthetic facts and a synthetic policy. Nothing is executed, your workspace policy is unchanged, and the example does not verify a real connection.
Connect your agent
- Open Agent connections, select Add agent, and give it a recognizable name.
- In Connect this agent, choose an expiry, up to 90 days or Never, and Issue API key. The agent sends the key as
Authorization: Bearer <API key>. Save it when shown; it is not available again after closing the dialog. API keys in the sidebar lists every agent's keys and issues or revokes them; Get an API key covers the header, replacing a key and the CLI. - Choose your host and copy its configuration. Replace the placeholder in the client's private secret configuration. Keep upstream provider credentials outside the agent's access.
- Submit an intended request for a test resource you control, then select Check connection. For positively identified sample fixtures, the page identifies a mock target and incident. This connected test may execute an action; the safe example above never does.
- Open the agent's activity and inspect the decision, execution outcome and evidence. Listing tools or issuing a key does not prove the action is governed.
Enforcing applies to participating requests and their configured mappings. Some mappings can remain observe-only or use an external executor. Calls that bypass the gateway or executor are outside that protection. Open the mode label for this explanation at any time.
Understand a request
Open Activity and select a request. The summary separates what policy decided, what execution evidence establishes, and the next safe step. Decision evidence retains the recorded codes and evidence. An approval authorizes a specific plan; it does not itself prove execution. An unknown provider outcome needs investigation before another attempt.
An older record may not distinguish an explicit deny from a missing permit. The console states that limitation rather than guessing the cause.
Set up a reviewer
- Under Team & access, open People and Add person.
- Enter a name and sign-in email. Creating the account does not send an invitation email automatically.
- Open the person's account and complete password setup or use the configured directory provider. If issuing a password setup code, share it privately using your organization's normal process.
- Assign the actions and targets that person may review under Review permissions. Administrators also need explicit review assignments.
Reviewers use their normal sign-in account. Historical bearer credentials remain available for inspection and revocation in Advanced controls; the normal setup path does not issue reviewer credentials.
Change a policy
Open Policies in the Space you administer and choose a named start. If that Space has available action mappings but no active policy, the security response baseline can create its first draft. Otherwise, copy current protections or add review requirements to them. Accounts and shared policies must be available to that Space.
Edit common rules and impact limits, validate, and preview against recorded history. Inspect the proposed changes, then explicitly activate the draft. The safe example does not preview your policy; the policy page does. A preview with no relevant history cannot establish coverage for untested actions.
Custom Cedar and advanced budget structures may require the complete configuration editor. The console refuses conversions that would discard protections. A deployment without supported mappings needs its operator to configure the connector path before a useful policy can be created.
Connect a monitoring source
Open Monitoring → Connect a source, choose Tines or Entra, and follow the permissions and collector commands. An operator runs the collector on the trusted host and stores its provider credentials privately. Collection and scheduling are not performed by the browser.
Select Check connection to inspect retained collection evidence. A saved connection can still be waiting for its first sync, stale, revoked or failing. Monitoring records visibility and coverage gaps; it does not confer execution authority.
Account and workspace settings
My account contains your sign-in and personal settings. Workspace settings contains tenant-level controls. Keep the selected Space in view when configuring agents and sources; its data and permissions can differ from another Space.
Community access and optional samples
A new hosted claim starts persistent Community. Invitation and API key expiry remain separate from workspace access. The optional safe example does not dispatch a provider or change live approvals, limits or execution state. Advanced CLI demo downloads are available only in a workspace containing exclusively identified synthetic fixtures. Mixed workspaces keep their data and use ordinary guided setup. See Editions for hosted capacity and Community transition for release status.