Help center

Help topics

01/

Getting started

The first workflow from an empty workspace to usable inventory.

01/ Read the dashboard overview

The dashboard is the daily starting point for assets, active findings, risk score, coverage and recent scanner activity.

  1. Open Dashboard from the sidebar and check the four metric cards at the top.
  2. Use the onboarding strip to jump to the next unfinished setup step.
  3. Review Risk snapshot and Coverage intelligence before opening detailed pages.
  4. Use Priority actions and Recent scan history for the most urgent follow-up work.

If the dashboard is empty, create an agent token and run the first scan.

02/ Deploy a scanner agent

Agents run authorized discovery from a network position you control.

  1. Open Agents and create an enrollment token.
  2. Download the Windows or Linux installer and run it on a host that can reach the intended internal networks.
  3. Confirm heartbeat, version and command status in the agent list.
  4. Add more agents only when sites, VLANs or security zones cannot be reached from the first scanner.

The normal rollout starts with one collector, not an agent on every endpoint.

03/ Plan coverage

Coverage shows which sites and network segments are visible and which still need attention.

  1. Open Coverage and add the sites or segments that belong to the workspace.
  2. Record owner notes so later reports explain who is responsible.
  3. Compare covered segments, blind spots and AD-only or network-only assets after scans.
  4. Place another scanner or adjust routing/firewall rules for unreachable areas.

Coverage is an operational map, not just a percentage.

04/ Run a discovery scan

Scans collect evidence from authorized internal ranges or configured cloud collectors.

  1. Open New scan and choose the scan type that matches the target.
  2. Enter a limited IP range or select an automatic cloud/everything mode when available.
  3. Choose the language used for generated findings and reports.
  4. Start the scan and inspect the scan detail page for discovered assets, evidence and reports.

Large scopes should be explicit and planned with the network owner.

02/

Inventory

How to inspect assets, software and hardware lifecycle information.

01/ Use the asset inventory

Assets consolidate scan evidence into one view for endpoints, servers, network devices and services.

  1. Open Assets to filter by search text, role, source or risk context.
  2. Select an asset to review hostname, IP address, role, evidence and lifecycle fields.
  3. Use bulk actions when multiple assets need the same owner or context update.
  4. Keep hostname, role and business importance clean so risk scoring is easier to understand.

Unknown assets should be triaged instead of ignored.

02/ Review software inventory

Software inventory helps find installed products and recurring package exposure.

  1. Open the software view from Assets.
  2. Search for product names, versions or publishers.
  3. Use asset links to see where a package was observed.
  4. Prioritize unsupported or unexpected software before low-risk cleanup.

Software quality depends on authenticated endpoint evidence.

03/ Check hardware and warranty data

Hardware fields and warranty lookup support lifecycle planning.

  1. Open an asset detail page and review model, serial number and procurement fields.
  2. Use warranty lookup when the asset has enough vendor-identifying data.
  3. Record purchase or owner information when automatic evidence is incomplete.
  4. Use lifecycle gaps in reports when planning replacement work.

Lifecycle data is best treated as planning evidence, not a blocking control.

03/

Findings and risk

How to move from raw findings to accepted decisions and action work.

01/ Work with findings

Findings translate evidence into active risks with severity, asset context and a recommendation.

  1. Open Findings from the sidebar or a dashboard metric.
  2. Filter by scan, language and workflow status.
  3. Read severity, asset, business context, description and recommendation together.
  4. Export CSV when another team needs the current finding list.

A finding is active until it is fixed, accepted or marked as a false positive.

02/ Accept or reopen risk

Accepted-risk decisions document why a finding is not being fixed immediately.

  1. Open the Accept control on an active finding.
  2. Choose the decision: accepted risk, business required or false positive.
  3. Choose the scope: this asset, the same site or the whole workspace.
  4. Add a reason and optional expiry date, then save the decision.
  5. Use Reopen when the exception is no longer valid.

Accepted risk should always include a business reason.

03/ Use the action queue

Actions turn recurring or important findings into a work queue.

  1. Open Actions from the sidebar or dashboard.
  2. Sort by priority and focus on open or in-progress items first.
  3. Use the linked asset or finding to understand the evidence.
  4. Update status as remediation work moves forward.

The dashboard shows the highest-priority actions so they are not buried in tables.

04/

Reports and compliance

Create stakeholder-ready output from scans, findings and workspace context.

01/ Create reports

Reports package scan results into management, technical, action-plan or compliance-oriented output.

  1. Open Reports and choose the scan to report on.
  2. Select report type, output format and language.
  3. Generate the report and download or open the finished artifact.
  4. Use management reports for stakeholders and technical reports for remediation teams.

Report quality improves when asset owners, coverage and risk decisions are maintained.

02/ Use NIS2 report areas

NIS2-oriented views collect declarations and evidence for security management conversations.

  1. Open Security & Compliance settings to maintain declarations.
  2. Generate a NIS2 report from the report builder when evidence is ready.
  3. Review gaps and use them as governance tasks rather than automatic legal conclusions.
  4. Keep declarations current when controls or responsible people change.

Compliance reports support preparation; they do not replace legal advice.

05/

Administration

Workspace settings, credentials, billing, support and partner operation.

01/ Configure credentials safely

Credential profiles help authenticated collection while keeping the boundary explicit.

  1. Open Settings, then Credentials.
  2. Create profiles only for systems you are authorized to inventory.
  3. Match credentials to collectors and target types intentionally.
  4. Rotate or remove credentials that are no longer needed.

Do not store broad admin access when a narrower read-only account is enough.

02/ Manage workspace and team settings

Workspace settings control team members, security context and operational metadata.

  1. Open Settings to review workspace and team details.
  2. Invite users with the role they need for their work.
  3. Maintain risk context so findings reflect business impact.
  4. Use Security & Compliance for policy declarations and security posture metadata.

Role changes should follow the least-privilege principle.

03/ Use billing and support

Billing shows plan status; support creates a ticket with the operational details needed for help.

  1. Open Billing to review plan status, limits and checkout or invoice state.
  2. Use Download PDF on an invoice row when accounting needs the invoice file.
  3. Open Support to create a workspace ticket.
  4. Choose the best category and include affected area, operating system, browser or agent details.
  5. Reply on the ticket thread when the support team needs more information.

Public visitors can use Contact; signed-in users should use Support.

04/ Operate the partner center

Partners can separate customer workspaces while keeping oversight from one console.

  1. Open Partner Center when your organization has partner access.
  2. Review customer workspaces and open the customer detail page when needed.
  3. Keep reports, tickets and billing separated per customer workspace.
  4. Use admin-level access only for operational tasks that require it.

Customer separation is part of the operating model.

06/

Discovery sources

Choose the right authorized source and keep its boundary understandable.

01/ Choose a discovery source

Use the smallest approved source that can answer the inventory question.

  1. Start with a limited network range or one owned lab segment.
  2. Use optional endpoint mode for devices that roam or are not reliably reachable from a scanner.
  3. Add AD LDAPS, SNMPv3 or DHCP/DNS snapshots only after confirming the required read-only access.
  4. Review source provenance on assets before using the result in a report or operational decision.

Do not connect a source just because credentials exist. The owner, purpose and scope should be clear first.

02/ Use persistent endpoint inventory

Endpoint mode reports local inventory, heartbeats and queued batches from an approved device.

  1. Create one enrollment token for the intended endpoint or rollout group.
  2. Install the agent on a device you own or are authorized to administer.
  3. Confirm the first heartbeat and inventory result in the agent list.
  4. Check update target, offline queue and last result before treating a device as current.

Agent requests are HMAC-signed. Production installer code signing is a separate release and distribution control.

03/ Connect AD, SNMPv3, DHCP and DNS safely

These sources are designed to document approved state without changing the source system.

  1. Use a least-privilege read-only account for AD LDAPS and confirm its directory scope.
  2. Use SNMPv3 credentials approved for inventory-only device reads.
  3. Provide DHCP/DNS state through the authorized HTTPS snapshot endpoint.
  4. Run one small validation collection and compare the observed records with the source owner.

Keep credentials in the customer-controlled scanner host or vault. Do not place passwords in tickets, reports or source code.

04/ Review asset identity

AssetObserve preserves observations and resolves them with stable identity signals where possible.

  1. Open an asset and inspect its source observations and evidence.
  2. Prefer serial number, SMBIOS UUID, managed-device ID, directory GUID and MAC address over display names.
  3. Review ambiguous candidates instead of assuming two similar names are the same device.
  4. Keep an identity decision reversible when new evidence appears.

A clean inventory is more valuable than an aggressive automatic merge.

07/

Operations and scale

Keep discovery observable, recoverable and usable as the inventory grows.

01/ Follow discovery operations

Use jobs, task outcomes and coverage to understand what happened after a discovery request.

  1. Check the discovery job status before starting the same work again.
  2. Read task outcome, lease and retry information for incomplete work.
  3. Use coverage to distinguish an unreachable segment from stale evidence or failed authentication.
  4. Escalate repeated failures with the affected source, scope and timestamp instead of only a screenshot.

Durable leases and checkpoints let eligible work be retried without silently duplicating evidence.

02/ Work with a large inventory

Use the inventory controls to narrow results before opening or exporting a large result set.

  1. Use server-side search and filters to define the operational question.
  2. Save a useful view for recurring ownership, freshness or source checks.
  3. Move through results with cursor pagination rather than opening every asset at once.
  4. Request a CSV export and monitor its background-job status for large result sets.

The commercial Enterprise asset limit remains 50,000 even though local technical tests include a synthetic 60K scenario.

03/ Understand current limits

Keep discovery scope and concurrency within the tested guardrails.

  1. Plan network discovery in authorized ranges up to 65,536 candidate hosts.
  2. Keep host concurrency at 24 and port concurrency at 12.
  3. Keep the Enterprise commercial asset limit at 50,000.
  4. Use an owned staging environment before claiming production-scale readiness.

Do not raise these limits for a real environment without approved capacity, backup, monitoring and recovery evidence.

04/ Troubleshoot missing or stale data

Start with placement and authorization, then use coverage and task evidence to narrow the failure.

  1. Confirm scanner or agent placement, routing and firewall policy for the intended scope.
  2. Check that the source credential has the expected read-only permission.
  3. Inspect the latest task outcome, retry state and last observation timestamp.
  4. Collect the affected scope, source, timestamp and error context before opening a support ticket.

An unreachable segment is not the same as an empty segment. Keep those outcomes separate in the investigation.

Field reference

Screen and field reference

What every field on the main screens means, the values it accepts and an example.

New scan

Every field on the authorized scan launcher. Only the fields that apply to the chosen scan type stay active.

Field What it does Accepted values Example
Scan name Required A label for this run so you can find it later in scan history and reports. Any short text. HQ discovery - March
What do you want to scan? (scan type) Required Selects which collectors run and which fields below stay active. Network discovery, Network authenticated, Cloud provider, Active Directory, or Everything. Network - discovery
IP range Conditional The authorized internal address range to scan. Network scan types only. One CIDR block or address. Plan large ranges with the network owner. 192.168.1.0/24
Execution point Required Where the scan runs from: an installed agent inside the customer network, or this web/demo host. Installed agent, or This web server. Installed agent
Scanner agent Conditional Which enrolled agent performs the scan. Needed when the execution point is an installed agent. One of your enrolled agents. HQ-Scanner-01
Scan scope Required An upper bound on how many addresses this scan may cover, as a safety guardrail. Quick, Site inventory, or Enterprise inventory. Quick
Authorization confirmation Conditional Confirms you are authorized to inventory every reachable asset in the selected scope. Checked or unchecked. Checked
Domain controller Conditional Hostname or internal IP of the DC for an Active Directory scan. Uses certificate-validated LDAPS on port 636. Hostname or IP - no URL and no port. dc01.corp.example
Credential profile Optional Which stored credentials to use. Auto-match picks by scope, or choose a specific profile. Auto-match, or a specific credential profile. Auto-match by scope
Notes Optional Free context stored with the scan, e.g. a change ticket or approval reference. Any text. Approved under CHG-2043

Create a scanner agent token

Enroll one scanner per network position. One token belongs to one agent and is reused for scheduled scans until you rotate it.

Field What it does Accepted values Example
Agent name Required A label for this scanner so you can recognize it in the agent list. Any short text. acme-scanner-01
Platform Required The kind of host the agent runs on; selects the right installer. Windows, Linux, or Collector appliance. Windows
Notes Optional Where the scanner sits and who owns it, for later operators. Any text. Munich HQ, mgmt VLAN, tech: Ada
Health (list column) Optional Check-in state shown in the registered-agents table. online, stale, offline, or not connected. online
Token (list column) Optional The reusable enrollment token. Rotate only if it was lost, exposed, or the agent is re-enrolled. Shown in full once at creation, masked afterwards. aoa_xxx

Add a site and network segment

Define authorized locations and subnets, then assign a scanner so the system knows what should be visible.

Field What it does Accepted values Example
Site name Required Name of a physical or logical location. Any short text. Munich HQ
Site type Optional What kind of location this is. office, branch, datacenter, warehouse, homeoffice/VPN, or cloud. office
Segment name Required Name of one internal network range. Any short text. HQ Client VLAN
CIDR Required The subnet in CIDR notation. Drives IPAM and scan planning. A valid CIDR block. 10.10.20.0/24
Zone Optional Network zone of the segment, used for risk weighting. client, server, management, dmz, guest, vpn, or OT/IoT. client
Environment Optional Environment class of the segment. production, office, dmz, lab, or branch. production
Criticality Optional Business criticality of the site or segment. normal, high, or critical. high
Scanner agent Optional Which agent covers this segment. Unassigned means it is a blind spot. One of your agents, or Unassigned. acme-scanner-01

Segment IPAM

One row per usable address in a segment, cross-referenced with discovered assets and manual reservations (capped at the IPAM address limit).

Field What it does Accepted values Example
IP address (reservation) Required Reserve an address so IPAM shows it as taken even if no asset was discovered there. An address inside this segment's CIDR. 10.10.20.5
Label (reservation) Optional What the reserved address is for. Any text. Gateway
Status (address map) Optional Each address is classified automatically. used (matched asset), reserved (manual), or free. used

Inventory search, filters and columns

Server-side search and filtering for large inventories. Filters are optional and combine with the search box.

Field What it does Accepted values Example
Search inventory Optional Free-text search across IP, hostname, owner and serial number. Any text. 192.168 or acme-pc
Type Optional Filter by asset type. All types, or a specific type. server
Criticality / Environment / Status Optional Narrow by business criticality, environment or observed status. Any of the listed options, or all. high / production / seen
Source Optional Filter by where the asset came from. network, or a cloud provider. network
Sort / Direction / Rows Optional Order the result set and page size. Sort by last seen, hostname, criticality, source/identity confidence...; 25-200 rows. Last seen / Descending / 50
Confidence (column) Optional Per-asset source vs identity confidence. 0-100% each. src 82% / id 90%

Filters and the accept-risk form

Filter the finding list, then document each risk as fixed, accepted or a false positive.

Field What it does Accepted values Example
Scan (filter) Optional Limit findings to one scan or show all. A scan, or All scans. All scans
Language (filter) Optional Language used to render finding text. en, de, fr, nl, pl, tr. tr
Status (filter) Optional Workflow filter for the list. Active, Accepted/ignored, or All. Active
Decision (accept) Conditional Why you are not fixing this finding now. accepted risk, business required, or false positive. accepted risk
Scope (accept) Conditional How far the decision applies. this asset, same site, or whole workspace. this asset
Expires (accept) Optional Optional date the exception auto-expires. A date, or blank for no expiry. 2026-12-31
Reason (accept) Conditional Business justification stored with the decision. Required when accepting. Any text. Vendor patch due Q3

Action queue fields

Turn findings into tracked work with an owner, a due date and completion evidence.

Field What it does Accepted values Example
Status Optional Workflow state of the action. open, in progress, blocked, accepted, or done. in progress
Owner Optional Who is responsible for the work. A workspace member, or Unassigned. Ada Byte
Due date Optional Target completion date; drives the overdue and due-soon flags. A date. 2026-08-15
Campaign Optional Group the action into a remediation campaign. A campaign, or Not in a campaign. Q3 patch push
Blocked reason Conditional Why the action cannot proceed. Use when status is blocked. Any text. Waiting on vendor
Completion evidence Optional A reference proving the work is done. Scan, change or evidence reference. CHG-2043
Work note Optional A free note added to the work timeline. Any text. Patched 3 of 5 hosts

Generate a report

Package one scan's results into a stakeholder-ready report.

Field What it does Accepted values Example
Scan Required Which scan the report is built from. One of your scans. HQ discovery - March
Report type Optional The report template to render. management, technical, action-plan, nis2 and other published types. management
Language Optional Output language of the report. en, de, tr and other enabled languages. de
Format Optional Output file format. PDF, HTML and other published formats. PDF
Notify Optional Security-contact groups that get the finished report by email. Any configured contact labels. IT leadership

Team access and invitations

Invite colleagues with the least role they need. Owner and admin can manage the workspace; the danger zone is owner-only.

Field What it does Accepted values Example
Work email Required Email of the person you are inviting into this workspace. A valid email. tech@acme.de
Workspace role Optional Access level for the invited user (least privilege). auditor, viewer, operator, or admin (owner is fixed). operator
Expires after Optional How long the invitation link stays valid. Never, 7, 14, or 30 days. 7 days
Confirm slug (danger zone) Conditional Type the workspace slug to confirm permanent, irreversible deletion. Owner only. The exact workspace slug. acme

Scan credential profiles

Create read-only credential profiles for authenticated collection. Secrets are never stored in the database - they stay in the agent's or the server's local vault.

Field What it does Accepted values Example
Name Required A label for this credential profile. Any short text. HQ read-only AD
Credential type Optional Which system the credential targets; selects the fields shown. AD/LDAPS, Windows WinRM, Linux/macOS SSH, SNMPv3, VMware, Kubernetes, cloud providers, or warranty APIs. Windows WinRM/WMI
Username hint Optional Non-secret hint shown in the list; the real secret stays local. Any text. DOMAIN\svc-read
Privilege level Optional Documents how much access the account has. read-only, privileged read, or domain admin approved. read-only
Target scope Optional CIDR ranges this credential applies to. Blank means a global fallback. Comma-separated CIDR ranges. 10.20.0.0/16
Owning agent Optional Assign to an agent (secret stays in that agent's vault), or leave blank for server-mode (secret encrypted in this server's local vault). An agent, or unassigned. acme-scanner-01
Secret fields Conditional Username, password, key or token - these vary by credential type and are never written to the database. Depends on the profile type. kept in local vault

Billing details

Keep invoice data complete for hosted checkout and German invoice PDFs. Payments and plan changes happen in hosted checkout, not here.

Field What it does Accepted values Example
Billing email Optional Where invoices are sent. A valid email. billing@acme.de
Company / recipient Optional Legal recipient name printed on the invoice. Any text. Acme IT GmbH
Address block Optional Postal address for the invoice. Street, postal code, city, region, country. Musterstr. 1, 80331 Munich
VAT ID / USt-IdNr. Optional Tax identifier printed on the invoice. A valid VAT ID. DE123456789
Plan / status (read-only) Optional Your active plan and its billing state. e.g. active or trialing. active

New support request

Create a ticket with only the technical details that matter. The issue type controls which detail fields appear.

Field What it does Accepted values Example
Issue type Optional Category of the request; controls which detail fields show. One of the listed categories. Agent problem
Subject Required Short summary of the problem. Any short text. Agent stopped checking in
Operating system Conditional OS of the affected machine, for technical issues. e.g. Windows 11, Ubuntu 24.04. Windows 11
Browser Conditional Browser where the problem appears. Chrome, Edge, Firefox, or Safari. Edge
Agent / platform Conditional Which agent or installer is affected. Windows agent, Linux agent, installer, scanner host. Windows agent
Affected area or reference Optional Agent name, invoice number or page involved. Any text. acme-scanner-01
What happened? Required What you tried, what you expected, and what happened instead. Any text. Heartbeat stopped after reboot

Dashboard sections

The daily starting point. Every tile here is read-only and links into a detailed page.

Field What it does Accepted values Example
Metric cards Optional The four top cards summarizing the workspace. assets, active findings, risk score, coverage. 142 assets
Onboarding strip Optional Shortcut to the next unfinished setup step. Disappears once setup is complete. Appears only while setup is incomplete. Run first scan
Risk snapshot Optional Current risk posture from the latest scan. Read-only summary. Risk score 61
Coverage intelligence Optional What is visible versus blind spots. Read-only summary. 3 blind spots
Priority actions Optional The most urgent follow-up work, surfaced from the action queue. Read-only list. 5 open
Recent scan history Optional The latest scan runs and their status. Read-only list. HQ discovery - finished

Create a customer workspace

For MSP/partner accounts: create separated customer workspaces and watch them from one risk board.

Field What it does Accepted values Example
Customer name Required Name of the managed customer workspace. Any short text. Example IT GmbH
Industry profile Optional Sector profile; weights risk scoring for that customer. small business, MSP, SaaS, school, hospital, bank, manufacturing, energy/KRITIS, retail, or craft. hospital
Country Optional The customer's country. Any country. Germany
Service tier Optional The service you provide this customer. managed risk, monthly reporting, one-time assessment, or co-managed. monthly reporting
Authorization confirmation Conditional Confirms the customer authorized partner access. Required to create the workspace. Checked. Checked
Customer risk board (columns) Optional Per-customer overview row on the board. risk, coverage, assets, collectors, critical/high. Risk 58 / 92% coverage
Need a human?

Contact support

Send the team your question, affected area and any scanner or browser details. Signed-in users can create a workspace ticket; public visitors can use the contact form.

Contact support