No active engagements
Operations Dashboard
Monitor authorized engagements, execution, evidence, and worker health.
Start an engagement
Follow these steps in order. Each test runs from a worker that matches the engagement location.
- 1Create the engagementClick New Engagement, select test type, external or internal execution, and the authorization dates.
- 2Add scope and authorizeIn the engagement table, click the shield button. Add each exact host, scheme, and port, then click Authorize.
- 3Connect the matching workerExternal engagement: use an external worker. Internal engagement: install a worker inside that network.
- 4Run the testOpen AI Execution, choose a provider and authorized engagement, enter the objective, then review the proposed actions.
No active execution
No validated findings
No critical exposure
Engagement Workspace
Top Threat Exposures
Recent Activity
Worker Status
A worker is required for every target-facing test. Use an external worker on an internet-connected node for public assets, or an internal worker inside the customer network for private assets. The control plane never scans a target directly.
Plan a test with an LLM
Choose an authorized engagement, provider, approval method, and objective. Planning uses the engagement attack graph, tenant semantic memory, and—when enabled—current public web research with retained clickable sources.
Agent Team
Configure the coordinator and specialist roles used for evidence-aware planning. Each run snapshots this configuration. Autonomous runs require fresh administrator verification and remain bounded by the selected engagement scope, approved adapter classes, action cap, and replan cap.
Disposable Workspaces
Attack Graph
CPE, CVE, CWE, CAPEC, and ATT&CK correlation will appear as evidence-backed paths.
Advanced path analytics
Run one of the fixed, read-only path analyses for the selected engagement. Results are derived from the current graph projection.
Derived, read-only view · run an analysis to check projection freshness.
Tool Catalog
Immutable Automation Adapters
These schema-specific adapters produce domain-separated worker signatures, normalized evidence, and graph projector receipts. The broader catalog remains available through audited, no-shell argument-vector workspaces.
Integrations & API Keys
Configure every external API dependency here. Credentials are sealed by the root-owned xRiskS vault, are never returned to the control plane or browser, and require a fresh authenticator code to create, verify, or disable.
Knowledge Library
Search the integrity-verified built-in library and your tenant-isolated articles. Organization articles are hashed and every change is audited.
Proposals awaiting review
Workers can propose reusable knowledge only from evidence they produced. Reviewers must approve a proposal before it becomes an organization article.
