Keyboard navigation
Use the skip link to reach content, Tab and Shift+Tab to move, Enter or Space to activate controls, arrow keys in tabs and menus, and Escape to close dialogs.
Find direct answers and practical guides for first discovery, approved sources, endpoint agents, coverage, inventory operations, reports, limits and troubleshooting.
The first workflow from an empty workspace to usable inventory.
The dashboard is the daily starting point for assets, active findings, risk score, coverage and recent scanner activity.
If the dashboard is empty, create an agent token and run the first scan.
Agents run authorized discovery from a network position you control.
Linux and macOS install from a source package that needs Python 3.9 or newer; Windows uses the compiled installer when your deployment publishes one and the same source package otherwise. The installer registers a systemd user timer, a LaunchAgent or a scheduled task, and never asks for the token on a command line it did not receive it on.
Coverage shows which sites and network segments are visible and which still need attention.
Coverage is an operational map, not just a percentage.
Scans collect evidence from authorized internal ranges or configured cloud collectors.
Large scopes should be explicit and planned with the network owner.
How to inspect assets, software and hardware lifecycle information.
Assets consolidate scan evidence into one view for endpoints, servers, network devices and services.
Unknown assets should be triaged instead of ignored.
Software inventory helps find installed products and recurring package exposure.
Software quality depends on authenticated endpoint evidence.
Hardware fields and warranty lookup support lifecycle planning.
Lifecycle data is best treated as planning evidence, not a blocking control.
How to move from raw findings to accepted decisions and action work.
Findings translate evidence into active risks with severity, asset context and a recommendation.
A finding is active until it is fixed, accepted or marked as a false positive.
Accepted-risk decisions document why a finding is not being fixed immediately.
Accepted risk should always include a business reason.
Actions turn recurring or important findings into a work queue.
The dashboard shows the highest-priority actions so they are not buried in tables.
Create stakeholder-ready output from scans, findings and workspace context.
Reports package scan results into management, technical, action-plan or compliance-oriented output.
Report quality improves when asset owners, coverage and risk decisions are maintained.
NIS2-oriented views collect declarations and evidence for security management conversations.
Compliance reports support preparation; they do not replace legal advice.
Workspace settings, credentials, billing, support and partner operation.
Credential profiles help authenticated collection while keeping the boundary explicit.
Do not store broad admin access when a narrower read-only account is enough.
Workspace settings control team members, security context and operational metadata.
Role changes should follow the least-privilege principle.
Billing shows plan status; support creates a ticket with the operational details needed for help.
Public visitors can use Contact; signed-in users should use Support.
Partners can separate customer workspaces while keeping oversight from one console.
Customer separation is part of the operating model.
Choose the right authorized source and keep its boundary understandable.
Use the smallest approved source that can answer the inventory question.
Do not connect a source just because credentials exist. The owner, purpose and scope should be clear first.
Endpoint mode reports local inventory, heartbeats and queued batches from an approved device.
Agent requests are HMAC-signed. Production installer code signing is a separate release and distribution control.
These sources are designed to document approved state without changing the source system.
Keep credentials in the customer-controlled scanner host or vault. Do not place passwords in tickets, reports or source code.
AssetObserve preserves observations and resolves them with stable identity signals where possible.
A clean inventory is more valuable than an aggressive automatic merge.
Keep discovery observable, recoverable and usable as the inventory grows.
Use jobs, task outcomes and coverage to understand what happened after a discovery request.
Durable leases and checkpoints let eligible work be retried without silently duplicating evidence.
Use the inventory controls to narrow results before opening or exporting a large result set.
The commercial Enterprise asset limit remains 50,000 even though local technical tests include a synthetic 60K scenario.
Keep discovery scope and concurrency within the tested guardrails.
Do not raise these limits for a real environment without approved capacity, backup, monitoring and recovery evidence.
Start with placement and authorization, then use coverage and task evidence to narrow the failure.
An unreachable segment is not the same as an empty segment. Keep those outcomes separate in the investigation.
Use AssetObserve with a keyboard or assistive technology and find non-visual alternatives for complex content.
Use the skip link to reach content, Tab and Shift+Tab to move, Enter or Space to activate controls, arrow keys in tabs and menus, and Escape to close dialogs.
The interface uses semantic HTML and targets current screen readers and browsers. Formal NVDA, VoiceOver and TalkBack evaluation is still pending, so compatibility is not yet claimed as verified.
Topology maps have searchable device and connection tables, charts have value tables, and HTML is the primary accessible report format. Request another accessible format when needed.
Independent auditing and disabled-user evaluation are not complete. PDF tagging has not been verified; use the linked HTML report alternative.
The written form needs no account, phone call or speech. We aim to acknowledge accessibility feedback within five working days and can provide an alternative format.
What every field on the main screens means, the values it accepts and an example.
Every field on the authorized scan launcher. Only the fields that apply to the chosen scan type stay active.
| Field | What it does | Accepted values | Example |
|---|---|---|---|
| Scan name Required | A label for this run so you can find it later in scan history and reports. | Any short text. | HQ discovery - March |
| What do you want to scan? (scan type) Required | Selects which collectors run and which fields below stay active. | Network discovery, Network authenticated, Cloud provider, Active Directory, or Everything. | Network - discovery |
| IP range Conditional | The authorized internal address range to scan. Network scan types only. | One CIDR block or address. Plan large ranges with the network owner. | 192.168.1.0/24 |
| Execution point Required | Where the scan runs from: an installed agent inside the customer network, or this web/demo host. | Installed agent, or This web server. | Installed agent |
| Scanner agent Conditional | Which enrolled agent performs the scan. Needed when the execution point is an installed agent. | One of your enrolled agents. | HQ-Scanner-01 |
| Scan scope Required | An upper bound on how many addresses this scan may cover, as a safety guardrail. | Quick, Site inventory, or Enterprise inventory. | Quick |
| Authorization confirmation Conditional | Confirms you are authorized to inventory every reachable asset in the selected scope. | Checked or unchecked. | Checked |
| Domain controller Conditional | Hostname or internal IP of the DC for an Active Directory scan. Uses certificate-validated LDAPS on port 636. | Hostname or IP - no URL and no port. | dc01.corp.example |
| Credential profile Optional | Which stored credentials to use. Auto-match picks by scope, or choose a specific profile. | Auto-match, or a specific credential profile. | Auto-match by scope |
| Notes Optional | Free context stored with the scan, e.g. a change ticket or approval reference. | Any text. | Approved under CHG-2043 |
Enroll one scanner per network position. One token belongs to one agent and is reused for scheduled scans until you rotate it.
| Field | What it does | Accepted values | Example |
|---|---|---|---|
| Agent name Required | A label for this scanner so you can recognize it in the agent list. | Any short text. | acme-scanner-01 |
| Platform Required | The kind of host the agent runs on; selects the right installer. | Windows, Linux, or Collector appliance. | Windows |
| Notes Optional | Where the scanner sits and who owns it, for later operators. | Any text. | Munich HQ, mgmt VLAN, tech: Ada |
| Health (list column) Optional | Check-in state shown in the registered-agents table. | online, stale, offline, or not connected. | online |
| Token (list column) Optional | The reusable enrollment token. Rotate only if it was lost, exposed, or the agent is re-enrolled. | Shown in full once at creation, masked afterwards. | aoa_xxx |
Define authorized locations and subnets, then assign a scanner so the system knows what should be visible.
| Field | What it does | Accepted values | Example |
|---|---|---|---|
| Site name Required | Name of a physical or logical location. | Any short text. | Munich HQ |
| Site type Optional | What kind of location this is. | office, branch, datacenter, warehouse, homeoffice/VPN, or cloud. | office |
| Segment name Required | Name of one internal network range. | Any short text. | HQ Client VLAN |
| CIDR Required | The subnet in CIDR notation. Drives IPAM and scan planning. | A valid CIDR block. | 10.10.20.0/24 |
| Zone Optional | Network zone of the segment, used for risk weighting. | client, server, management, dmz, guest, vpn, or OT/IoT. | client |
| Environment Optional | Environment class of the segment. | production, office, dmz, lab, or branch. | production |
| Criticality Optional | Business criticality of the site or segment. | normal, high, or critical. | high |
| Scanner agent Optional | Which agent covers this segment. Unassigned means it is a blind spot. | One of your agents, or Unassigned. | acme-scanner-01 |
One row per usable address in a segment, cross-referenced with discovered assets and manual reservations (capped at the IPAM address limit).
| Field | What it does | Accepted values | Example |
|---|---|---|---|
| IP address (reservation) Required | Reserve an address so IPAM shows it as taken even if no asset was discovered there. | An address inside this segment's CIDR. | 10.10.20.5 |
| Label (reservation) Optional | What the reserved address is for. | Any text. | Gateway |
| Status (address map) Optional | Each address is classified automatically. | used (matched asset), reserved (manual), or free. | used |
Server-side search and filtering for large inventories. Filters are optional and combine with the search box.
| Field | What it does | Accepted values | Example |
|---|---|---|---|
| Search inventory Optional | Free-text search across IP, hostname, owner and serial number. | Any text. | 192.168 or acme-pc |
| Type Optional | Filter by asset type. | All types, or a specific type. | server |
| Criticality / Environment / Status Optional | Narrow by business criticality, environment or observed status. | Any of the listed options, or all. | high / production / seen |
| Source Optional | Filter by where the asset came from. | network, or a cloud provider. | network |
| Sort / Direction / Rows Optional | Order the result set and page size. | Sort by last seen, hostname, criticality, source/identity confidence...; 25-200 rows. | Last seen / Descending / 50 |
| Confidence (column) Optional | Per-asset source vs identity confidence. | 0-100% each. | src 82% / id 90% |
Filter the finding list, then document each risk as fixed, accepted or a false positive.
| Field | What it does | Accepted values | Example |
|---|---|---|---|
| Scan (filter) Optional | Limit findings to one scan or show all. | A scan, or All scans. | All scans |
| Language (filter) Optional | Language used to render finding text. | en, de, fr, nl, pl, tr. | tr |
| Status (filter) Optional | Workflow filter for the list. | Active, Accepted/ignored, or All. | Active |
| Decision (accept) Conditional | Why you are not fixing this finding now. | accepted risk, business required, or false positive. | accepted risk |
| Scope (accept) Conditional | How far the decision applies. | this asset, same site, or whole workspace. | this asset |
| Expires (accept) Optional | Optional date the exception auto-expires. | A date, or blank for no expiry. | 2026-12-31 |
| Reason (accept) Conditional | Business justification stored with the decision. Required when accepting. | Any text. | Vendor patch due Q3 |
Turn findings into tracked work with an owner, a due date and completion evidence.
| Field | What it does | Accepted values | Example |
|---|---|---|---|
| Status Optional | Workflow state of the action. | open, in progress, blocked, accepted, or done. | in progress |
| Owner Optional | Who is responsible for the work. | A workspace member, or Unassigned. | Ada Byte |
| Due date Optional | Target completion date; drives the overdue and due-soon flags. | A date. | 2026-08-15 |
| Campaign Optional | Group the action into a remediation campaign. | A campaign, or Not in a campaign. | Q3 patch push |
| Blocked reason Conditional | Why the action cannot proceed. Use when status is blocked. | Any text. | Waiting on vendor |
| Completion evidence Optional | A reference proving the work is done. | Scan, change or evidence reference. | CHG-2043 |
| Work note Optional | A free note added to the work timeline. | Any text. | Patched 3 of 5 hosts |
Package one scan's results into a stakeholder-ready report.
| Field | What it does | Accepted values | Example |
|---|---|---|---|
| Scan Required | Which scan the report is built from. | One of your scans. | HQ discovery - March |
| Report type Optional | The report template to render. | management, technical, action-plan, nis2 and other published types. | management |
| Language Optional | Output language of the report. | en, de, tr and other enabled languages. | de |
| Format Optional | Output file format. | PDF, HTML and other published formats. | PDF |
| Notify Optional | Security-contact groups that get the finished report by email. | Any configured contact labels. | IT leadership |
Invite colleagues with the least role they need. Owner and admin can manage the workspace; the danger zone is owner-only.
| Field | What it does | Accepted values | Example |
|---|---|---|---|
| Work email Required | Email of the person you are inviting into this workspace. | A valid email. | tech@acme.de |
| Workspace role Optional | Access level for the invited user (least privilege). | auditor, viewer, operator, or admin (owner is fixed). | operator |
| Expires after Optional | How long the invitation link stays valid. | Never, 7, 14, or 30 days. | 7 days |
| Confirm slug (danger zone) Conditional | Type the workspace slug to confirm permanent, irreversible deletion. Owner only. | The exact workspace slug. | acme |
Create read-only credential profiles for authenticated collection. Secrets are never stored in the database - they stay in the agent's or the server's local vault.
| Field | What it does | Accepted values | Example |
|---|---|---|---|
| Name Required | A label for this credential profile. | Any short text. | HQ read-only AD |
| Credential type Optional | Which system the credential targets; selects the fields shown. | AD/LDAPS, Windows WinRM, Linux/macOS SSH, SNMPv3, VMware, Kubernetes, cloud providers, or warranty APIs. | Windows WinRM/WMI |
| Username hint Optional | Non-secret hint shown in the list; the real secret stays local. | Any text. | DOMAIN\svc-read |
| Privilege level Optional | Documents how much access the account has. | read-only, privileged read, or domain admin approved. | read-only |
| Target scope Optional | CIDR ranges this credential applies to. Blank means a global fallback. | Comma-separated CIDR ranges. | 10.20.0.0/16 |
| Owning agent Optional | Assign to an agent (secret stays in that agent's vault), or leave blank for server-mode (secret encrypted in this server's local vault). | An agent, or unassigned. | acme-scanner-01 |
| Secret fields Conditional | Username, password, key or token - these vary by credential type and are never written to the database. | Depends on the profile type. | kept in local vault |
Keep invoice data complete for hosted checkout and German invoice PDFs. Payments and plan changes happen in hosted checkout, not here.
| Field | What it does | Accepted values | Example |
|---|---|---|---|
| Billing email Optional | Where invoices are sent. | A valid email. | billing@acme.de |
| Company / recipient Optional | Legal recipient name printed on the invoice. | Any text. | Acme IT GmbH |
| Address block Optional | Postal address for the invoice. | Street, postal code, city, region, country. | Musterstr. 1, 80331 Munich |
| VAT ID / USt-IdNr. Optional | Tax identifier printed on the invoice. | A valid VAT ID. | DE123456789 |
| Plan / status (read-only) Optional | Your active plan and its billing state. | e.g. active or trialing. | active |
Create a ticket with only the technical details that matter. The issue type controls which detail fields appear.
| Field | What it does | Accepted values | Example |
|---|---|---|---|
| Issue type Optional | Category of the request; controls which detail fields show. | One of the listed categories. | Agent problem |
| Subject Required | Short summary of the problem. | Any short text. | Agent stopped checking in |
| Operating system Conditional | OS of the affected machine, for technical issues. | e.g. Windows 11, Ubuntu 24.04. | Windows 11 |
| Browser Conditional | Browser where the problem appears. | Chrome, Edge, Firefox, or Safari. | Edge |
| Agent / platform Conditional | Which agent or installer is affected. | Windows agent, Linux agent, installer, scanner host. | Windows agent |
| Affected area or reference Optional | Agent name, invoice number or page involved. | Any text. | acme-scanner-01 |
| What happened? Required | What you tried, what you expected, and what happened instead. | Any text. | Heartbeat stopped after reboot |
The daily starting point. Every tile here is read-only and links into a detailed page.
| Field | What it does | Accepted values | Example |
|---|---|---|---|
| Metric cards Optional | The four top cards summarizing the workspace. | assets, active findings, risk score, coverage. | 142 assets |
| Onboarding strip Optional | Shortcut to the next unfinished setup step. Disappears once setup is complete. | Appears only while setup is incomplete. | Run first scan |
| Risk snapshot Optional | Current risk posture from the latest scan. | Read-only summary. | Risk score 61 |
| Coverage intelligence Optional | What is visible versus blind spots. | Read-only summary. | 3 blind spots |
| Priority actions Optional | The most urgent follow-up work, surfaced from the action queue. | Read-only list. | 5 open |
| Recent scan history Optional | The latest scan runs and their status. | Read-only list. | HQ discovery - finished |
For MSP/partner accounts: create separated customer workspaces and watch them from one risk board.
| Field | What it does | Accepted values | Example |
|---|---|---|---|
| Customer name Required | Name of the managed customer workspace. | Any short text. | Example IT GmbH |
| Industry profile Optional | Sector profile; weights risk scoring for that customer. | small business, MSP, SaaS, school, hospital, bank, manufacturing, energy/KRITIS, retail, or craft. | hospital |
| Country Optional | The customer's country. | Any country. | Germany |
| Service tier Optional | The service you provide this customer. | managed risk, monthly reporting, one-time assessment, or co-managed. | monthly reporting |
| Authorization confirmation Conditional | Confirms the customer authorized partner access. Required to create the workspace. | Checked. | Checked |
| Customer risk board (columns) Optional | Per-customer overview row on the board. | risk, coverage, assets, collectors, critical/high. | Risk 58 / 92% coverage |
Send the team your question, affected area and any scanner or browser details. Signed-in users can create a workspace ticket; public visitors can use the contact form.
Contact support