How to move from approved scope to reviewable evidence.

Choose the task in front of you. Each guide names the Workbench screen, the safety boundary, and the evidence to inspect before moving on.

  • How to use Guard

    Log in to Workbench, pick the project that owns the target, run an authorized assessment, and review findings next to HTTP Records and OAST.

    Open the guide
  • Configure Workbench

    Set workspace components, identities, and support paths before the first production-adjacent run.

    Open the guide
  • Optimize a bug bounty hunt

    Keep in-scope hosts in the authorization gate, prefer staging, and submit only replayable evidence.

    Open the guide
  • Run SAST across languages

    Class hunters and language-aware research agents share one worker cap. They read the clone; they do not get a shell.

    Open the guide
  • Run an authorized assessment

    Choose the project, confirm target ownership, set exclusions, launch the run, and keep the operator stop path visible.

    Open the guide
  • Configure authenticated testing

    Attach dedicated test identities, preserve role boundaries, and keep production user sessions out of the assessment.

    Open the guide
  • Review a finding before export

    Open the finding, inspect its request and response, check reachability, then decide whether engineering has enough evidence.

    Open the guide
  • Trace an OAST callback

    Relate the out-of-band interaction to its project, request, and finding instead of treating a callback as a conclusion.

    Open the guide
  • Operate users, SSO, and compliance

    Assign workspace roles, configure OIDC, review SLA settings, and keep compliance output tied to the source evidence.

    Open the guide