First authorized assessment
The first Eresus Guard assessment belongs in Workbench, not in the CLI.
Open https://workbench.eresussec.com, choose a Project, and start a Scan against an authorized staging target.

Do not run eresus-guard scan. That command is not the customer product.
Before you start
- The organization has Professional, Business, Enterprise, or MSSP access
- You can log in or use SSO
- The target, identities, and exclusions are written and authorized
- The Web Analysis Engine is healthy under Settings → Components if the assessment needs a browser-backed path
In Workbench
- Open Projects and create or select the staging project.
- Start New Scan (web/API) or SAST Scan (source). Enter only authorized hosts or an authorized source snapshot.
- Attach approved modules, extensions, and test identities. Production user sessions stay out.
- Confirm the authorization gate, metadata IP blocking, and exclusions.
- Launch from Workbench. Watch Dashboard or Active Scan. Pause or stop from Workbench if the target becomes unstable.
- Triage in Findings. Open the finding, then HTTP Records or OAST before you export.

A pause is a safety action, not a failed run.
After the first run
Refine exclusions, identities, and module selection in the same project. Re-run from Scan History only while authorization still holds.
Then read:
Need a workflow that is not documented here? Email contact@eresussec.com.