Client guide
Clients work in their own organization. A provider can deliver assessments into this workspace, but your account does not gain access to the provider's other clients.
First access
Accept your invitation, set your password, and configure MFA if required. Open My Account for profile, password, token, and notification preferences.
See Quick start and Authentication.
Team and permissions
Your organization manager handles authorized team operations. Viewers read assigned results, while assessment contributors need the corresponding project permissions.
Review assessment results
Open Projects, choose the engagement, and inspect its narrative, assets, findings, and report. Provider-managed projects keep their configuration under provider control. Client-managed internal projects allow your authorized team to maintain its own assessment data.
Use the findings' evidence, remediation guidance, status, and history to coordinate fixes and retests. Public AI candidates can require review before becoming confirmed findings.
See Issue lifecycle and AI review.
Attack surface
Open Attack Surface to inspect assets, services, and issues. Review the included scope with your provider. The Out of scope section remains available for exclusions, with editing determined by permissions. An empty included scope means monitoring is not running against targets.
See Scope and Issue status changes.
Cloud access and findings
Connect your own AWS, Azure, or GCP account using the documented read-only credentials. Review account connection state separately from assessment results. Open a misconfiguration to inspect the affected resource and remediation, then use the status selector to track Open, Resolved, or Suppressed.
See Connect a cloud account and Manage cloud findings.
Automation
Your API and Galileo connection uses https://api.hashiro.ai/api/ with your own token. One profile is enough. Only operations permitted for your organization and project are available.
See API, Galileo configuration, and Automatic Assessments.