Web Analysis Engine
The Web Analysis Engine is a separately signed component. It is not Chromium baked into the Guard binary. Browser-driven analysis uses this component. You install and maintain it from Workbench.
Path: Settings → Components.

What it is for
Authorized assessments that need a real browser (rendering, navigation, some active checks) depend on a healthy engine. If the component is missing, stale, or broken, those assessments fail in Workbench with a component error. They do not silently fall back to an embedded browser.
What it is not
- Not an in-app Chromium you download with the CLI
- Not a local scanner for non-MSSP customers
- Not an offline or air-gapped license object
- Not something you point
eresus-guard scanat
Install, update, repair, rollback
From Settings → Components an operator with permission can:
- Install the current signed build when the workspace has none.
- Update to a newer signed build when Workbench offers one.
- Repair when the install is present but fails health checks.
- Rollback to the previous signed build if an update misbehaves.
Each action is a signed artifact change. Do not copy unsigned binaries into the workspace.
Who can change it
Admin-capable roles. Ordinary triage users should not install or roll back the engine. If the control is missing, you do not have the permission.
When something is wrong
- Open Settings → Components and read the status (installed, version, last health check).
- Run Repair if the build is installed but unhealthy.
- If the client on your machine is involved, run
eresus-guard doctoranderesus-guard version, then open Workbench again. See CLI operations. - If status stays failed, email contact@eresussec.com with workspace name, component version, and the error text. Do not attach HTTP corpora.
MSSP
MSSP self-host still uses online licensing. Component management stays in that Workbench. There is no air-gap SKU for the engine.
Related
Need a workflow that is not documented here? Email contact@eresussec.com.