Provider guide
Providers deliver security services to linked client organizations. Your role determines the available actions; being a provider does not grant global administration.
Set up your team
Open Organization to review your license, name, branding, language, and security policy. Use Team to invite managers and pentesters. Managers administer the provider organization; pentesters work within assigned projects.
See Organization and Roles.
Onboard a client
Use Customers > New Customer to provision the client and invite its initial management user. Review the provisional invitation status. Before the client claims the organization, eligible invitation-management controls are available; after claim, its credentials belong to the client.
See Customer management.
Deliver an assessment
Create the client engagement, select the authorized client, define scope and exclusions, assign team members, and document findings. Review AI candidates before publication. Maintain the narrative and generate the report when the work is ready.
Clients can review published results of provider-managed engagements without editing your project configuration.
See Projects, Findings, and Reports.
Surface monitoring
Providers manage in-scope targets by default when the controls are available. Review the configured targets with the client and keep exclusions current. An empty included scope means there are no targets being monitored.
See Scope configuration and Surface findings.
Cloud security
Guide clients through connecting their own cloud accounts with the required read permissions. Do not assume a provider relationship grants access to every client's cloud connection or credential. Navigate only the account context available to you.
See Cloud connections and Cloud findings.
API and Galileo
Use the same production API as clients: https://api.hashiro.ai/api/. Your token determines provider scope. Configure one Galileo profile and choose the project for each operation.