How to move from approved scope to reviewable evidence.
Choose the task in front of you. Each guide names the Workbench screen, the safety boundary, and the evidence to inspect before moving on.

How to use Guard
Log in to Workbench, pick the project that owns the target, run an authorized assessment, and review findings next to HTTP Records and OAST.
Open the guide
Configure Workbench
Set workspace components, identities, and support paths before the first production-adjacent run.
Open the guide
Optimize a bug bounty hunt
Keep in-scope hosts in the authorization gate, prefer staging, and submit only replayable evidence.
Open the guide
Run SAST across languages
Class hunters and language-aware research agents share one worker cap. They read the clone; they do not get a shell.
Open the guide
Run an authorized assessment
Choose the project, confirm target ownership, set exclusions, launch the run, and keep the operator stop path visible.
Open the guide
Configure authenticated testing
Attach dedicated test identities, preserve role boundaries, and keep production user sessions out of the assessment.
Open the guide
Review a finding before export
Open the finding, inspect its request and response, check reachability, then decide whether engineering has enough evidence.
Open the guide
Trace an OAST callback
Relate the out-of-band interaction to its project, request, and finding instead of treating a callback as a conclusion.
Open the guide
Operate users, SSO, and compliance
Assign workspace roles, configure OIDC, review SLA settings, and keep compliance output tied to the source evidence.
Open the guide