Updated
Platform guides
Day-to-day guides for each part of the product, how to find your way around with the organisation and project switcher, and what to check if something is missing.
These guides cover day-to-day work in each part of the product, from scanning to reporting.
Choose your organisation and project
The switcher at the top of the sidebar sets your organisation, and the Projects list in the sidebar sets your project. Check the organisation and project before you act.
| Place | Belongs to |
|---|---|
| Preferences | The project |
| Settings | The organisation |
| Account Settings, in the menu on your name at the bottom of the sidebar | You |
Create, rename or delete a project
Each needs Admin on the main project; see roles and permissions.
| To | Do this |
|---|---|
| Create a project | Select + beside Projects, enter a Project Name and select Create Project. The number of projects depends on your plan; see pricing. |
| Rename or delete a project | Open the project's ⋯ menu and choose Rename Project or Delete Project. |
If something is missing
If a page, button or item is not there, check these in turn.
| Check | Why it matters |
|---|---|
| Your role | Some items depend on your role. |
| Your plan | Some items depend on your plan; see pricing. |
| The organisation or project in the switcher | You may have the wrong one selected. See Choose your organisation and project. |
Find and triage
- AssetsAssets is your inventory of networks, identities, apps, devices and data: browse, filter, add, tag, edit, export and delete assets, and jump from an asset to its findings.
- ExposureBrowse, filter, triage, bulk-edit and export findings and vulnerabilities, with identity exposures and configuration checks alongside.
- Add or import findingsRecord a finding by hand, report one from the vulnerability library, or import a Nessus, Burp Suite, Nuclei, SARIF or JSON report from your own tools.
- Identity exposuresReview leaked credentials and account addresses found in breaches and on the dark web, resolve them once the account is secured, and reveal a leaked password.
- Configuration checksReview pass and fail results for your cloud and identity configuration, and request a fix or an exception.
Track and report
- RiskRecord a risk in the Risk register, score it by likelihood and impact, choose how to treat it, link the controls that reduce it, and track it to closure.
- ActionsTrack remediation work in the Actions list, and decide pending proposals in the Proposals inbox.
- GovernanceGovernance is where you write and approve security policies, start from built-in starter policies, and keep the reusable Sections that policies and reports are built from.
- ReportsGenerate an executive overview, vulnerability, compliance, configuration or assessment report from your current data, then review, approve and export it.
- EngagementsRun a penetration test as an engagement: set its scope, attach findings, then generate a client-ready report.