Docs

Getting started

The first hour, end to end. Sign up, work the setup wizard, get your first scan, invite your team, and the questions that come up once you're through it.

Most of this first hour is waiting on you, not the platform. From signing up to your first exposure snapshot is typically minutes, not days. This walks through the whole hour, in order.

1. Create your account

Sign up at app.ciso360.ai/auth/signup with a work email. Personal providers like Gmail aren't accepted. The Free plan needs no credit card.

Your first organisation is created for you, together with its main project. The organisation's main domain is the domain the platform treats as yours: the target for domain-scoped scans and the anchor for identity-exposure monitoring. Make sure it's a domain you're authorised to assess.

2. Validate your email, then use your identity provider

The first password you set is only for that initial validation. Once your email is confirmed, sign in with your identity provider going forward. There's no separate password to remember after that.

3. Work through the setup wizard

Two things happen here: you set your organisation profile, and you confirm which modules to switch on.

The profile is a handful of short questions — where you operate, your sector, your size, how sensitive your data is, your risk appetite, and what you're working towards right now. Between them they decide which standards get recommended, how ambitious a maturity target you start against, and how your first checklist is ordered.

One of those is worth knowing about before you answer it: a first security to-do list can be overwhelming, and a higher risk appetite deliberately gives you a shorter one aimed at the highest-priority work. You can raise the target later, once the first round is behind you.

Then the modules: governance and compliance, the policy starter set, and the two domain scans for identity exposure and attack surface. You'll also see a switch for cloud security posture management — see below. You can change these later under Preferences → Scan modules. Some need a step outside the platform first — confirming you own the domain, for instance, before an attack-surface scan can start.

Scanning needs your authorisation

The two scan modules run against your main domain, so turning them on needs proof you're authorised to have that domain assessed. Any one of three unlocks them: verify domain ownership with a DNS record, enter an invitation code, or move to a paid plan. This applies to the two scan modules only, so the Free plan is useful with no unlock at all.

You're also asked to confirm the authorisation itself. The scans are held until you do, and the acknowledgement is recorded in the audit log.

What the Free plan shows

Governance and compliance, the policy starter set, self-assessment, compliance reports and the audit log all work in full on the Free plan, as does connecting your own AI agent.

Two limits are worth knowing before you look for something and can't find it. Once scanning is unlocked, the asset, finding, vulnerability and identity-exposure lists show a limited window of the highest-risk rows — each list tells you the true total beside what it is showing, so you can see what a paid plan would reveal, and the exact figure is on the pricing page. And four surfaces need a paid plan: the Graph view, the raw scan-event history, the findings and configuration reports, and exporting a list. Compliance reports are not among them.

Cloud and SaaS posture is set up later

Turning that switch on registers your interest. Configuration posture is set up after the wizard, by connecting a cloud or SaaS tenant. See step 7.

4. Choose how you want to start

Two ways through the rest of the wizard, and both land in the same place: a guided assessment where the AI Sidekick walks you through your posture question by question, or browsing the roadmap yourself and picking things up as you go. Take whichever gets you oriented faster. Neither one is the "wrong" path.

5. Your first snapshot, in minutes

Once the wizard finishes and the scan modules are unlocked, scanning starts: a passive pass over your domain, and a check against known identity exposure. Land on the Dashboard's Overview for your first look at assets and findings, then check Identity Exposure for anything already out there: dark-web credential matches you can filter, reveal and triage.

This step is usually the fastest part of the whole hour: a first snapshot, not a multi-day wait. If you haven't unlocked the scan modules yet, start with Governance & compliance instead and come back to this once domain ownership is verified.

6. Invite your team and scope their access

Add the rest of your team from Settings → Organisation Management. If one group only needs a narrow slice (a web team that only cares about a single asset, say), share a dedicated project with them instead of adding them to the main project. The Admin role granted on the main project cascades across every project in the organisation; Reader and Contributor roles, and Admin granted on any other project, stay scoped to just that one.

7. What's next

A few natural next moves, each covered in full elsewhere:

  • Connect a cloud or SaaS tenant for configuration posture.
  • Connect your own AI agent over MCP. See Connect your AI agent.
  • Read How it works: the loop your organisation is now in, one page connecting every part of the platform. See How it works.

Frequently asked questions

The questions that tend to come up once you're through the first hour above. Not everything a customer might ever ask, just the doubts that come with what you've just done: your first triage, inviting your team, and what's next.

If a triage decision turns out to be wrong, can it be undone?

Yes. Every triage action (accept, suppress, resolve) can be reversed, and every change is attributed and shows up in the audit log, whether a person or an agent made it. A suppression can also be time-boxed: once the window elapses, the next scan that re-detects the finding reopens it.

If I invite someone to the main project, do they get access everywhere?

It depends on the role. The Admin role on the main project cascades across every other project in the organisation. Reader and Contributor roles, and Admin granted on a project other than main, stay scoped to the project they were granted on. To limit someone to a single project, share that specific project with them instead of the main one.

Does connecting a cloud or SaaS tenant change anything in it?

No. The connection is read-only. Posture recommendations surface as proposals for a human to review and approve. Nothing is applied automatically.

Does connecting my own AI agent use up the platform's AI credits?

No. Bringing your own MCP client (Claude, Copilot, or any other agent, including a self-hosted model) runs on your own model and your own token budget. AI Sidekick's own credits, used when you chat with a persona inside the app, are a separate, unrelated meter. See Connect your AI agent.

Next steps

On this page