Overview
High-level operational view of findings, tasks, run requests, and recent SecOpsAI activity.
Recent dashboard events
Recent agent runs
Work
Own remediation, approvals, investigations, and execution runs in one operational queue.
Findings
One triage queue for canonical SecOpsAI Core findings and dashboard operational records, with task and run correlation.
Findings queue
Finding detail
Assets
Understand what is connected, what changed, and whether each sensor and service is healthy.
Sensors
Scans & schedules
Inventory
Related findings
Changes since last sync
System
Review platform health, runtime integrations, access boundaries, and action history.
SecOpsAI Intelligence
Use approved read-only actions through a local ChatGPT subscription bridge or the hosted SecOpsAI ChatGPT app.
Local Codex bridge
Uses the ChatGPT sign-in already owned by Codex on this computer.
Required for service controls. Existing pilot installations may use the same credential configured for Triage Ops.
ChatGPT app
Read authorized SecOpsAI findings, assets, and research from inside ChatGPT.
Request analysis
Actions use normalized SecOpsAI context. They cannot publish, close findings, run scans, or execute package code.
Analysis jobs
Every request and result is durable, bounded, and reviewable.
Native action queue
Pending and recently applied local SecOpsAI triage actions.
Investigation sessions
Recent SecOpsAI investigation sessions, progress, artifacts, and approval state.
Selected session
Live session plan, approvals, event feed, and artifacts for the investigation you are reviewing now.
Recent orchestrator runs
Research
Turn credible leads into durable, evidence-led investigations with explicit disclosure and publication gates.
Create research case
Promote from package watchlist
Preview selected npm leads first. Creating draft cases is a separate protected action and never fetches or executes package code.
Research discovery
Monitor approved registry sources and review explainable candidates before creating a case. Coverage is shown per ecosystem; a scoped monitor is not a global clean result.
Case queue
Select a case to review its evidence and workflow.
Publications
Review source-backed news and original research, then approve, stage, and deploy public security content.
Admin action token
Read-only status can load without this token. Write actions require the dashboard secret value from `BLOG_OPS_ADMIN_TOKEN`; it is stored only in this browser session.
Actions
Buttons dispatch the protected GitHub Actions runner. External news still requires explicit approval before publishing.
Draft review queue
Select a draft to preview source-backed content and approve or reject it.
Draft preview
Recent Blog Ops workflow runs
Supply Chain Triage
Operational control plane for incoming supply-chain alerts: evidence checks, local impact, mitigation, response, and handoff into Research Cases or Blog Ops.
Admin action token
Read actions can run without this token. Closing, escalation, and blog draft creation require the helper-side `TRIAGE_OPS_ADMIN_TOKEN` or `BLOG_OPS_ADMIN_TOKEN`.
Supply Chain Alerts
Open SCM findings loaded from the native SecOpsAI helper or hosted helper proxy.
Filters
Alert Review
Campaign Research & Autonomous Discovery Advanced campaign intake, route explanations, research-case handoff, correlation, watchlists, and review-only blog draft handoff.
Global Registry Coverage
Continuous package-registry surveillance: collector health, cursor lag, coverage gaps, dead letters, and the candidate inbox produced by the detection pipeline.
Pipeline actions
Protected actions use the research admin token. A degraded or paused collector means surveillance is incomplete, not clean.
Registry collectors
Latest feed events
Newest registry events across all collectors. Candidate events link into Research.
Coverage windows
Gaps first. A gap means the cursor stopped before the window ended and replay is pending.
Operator Guide
Step-by-step dashboard playbook for research, daily triage, blog review, and protected actions.
Automated guide steps
These shortcuts automate repetitive read-only steps from the guide. They never close findings, persist campaign findings, create blog drafts, approve drafts, or publish posts.
Passwords, tokens, and recovery
SecOpsAI has separate credentials for the dashboard, research actions, and Edge sensor operations. None of these should be shared or pasted into another field.
TRIAGE_OPS_ADMIN_TOKEN protects Research Cases and Supply Chain Triage writes. BLOG_OPS_ADMIN_TOKEN is the documented fallback when configured.SECOPSAI_ADMIN_TOKEN is an API administrator secret for sensor enrollment and recovery. Sensor tokens are separate, scoped credentials.For a dashboard account, ask an existing workspace owner to invite your email from Settings, then choose your own password from the one-time link. To recover access, use Send password reset on the sign-in screen.
For research actions, an administrator generates a long random token, configures it server-side in the local helper and/or Cloudflare Worker, and gives it to authorized operators through a secure channel. The dashboard stores it only for the browser session.
For Edge onboarding, use the hosted API administrator secret only with the Edge onboarding flow. Prefer one-time sensor enrollment tokens for normal setup; never use an Edge API token as a dashboard password.
Never commit secrets, put them in browser build variables, or paste them into chat. Rotate a credential if it was exposed, then verify the replacement before revoking the old one.
dev-admin-token and change-me-before-pilot belong only to development templates. They are not administrator passwords and must not be used for a hosted or customer pilot.Overview daily workflow
Use Overview as the morning command scan. It answers: what changed, what is blocked, what needs review, and which runs or findings deserve attention first.
Click Overview, then click Refresh data if the timestamp looks stale.
Read the top metrics first: active runs, blockers, in-review work, and security-review count.
Use recent events and recent runs to spot failed automation, stuck reviews, or unexpected spikes.
If a metric is concerning, jump to Tasks, Findings, or Supply Chain Triage instead of acting from memory.
Tasks daily workflow
Tasks is the work queue for ownership, deadlines, blockers, and run visibility. Use it to turn findings into tracked work.
Click Tasks and scan each column: Inbox, Planned, In Progress, Review, Blocked, and Done.
Open a task card to edit owner, reviewer, priority, due date, security-review flag, and description.
Use Open work brief when you need a copyable implementation or investigation brief.
Use Save and queue only when the task is ready to become a run request. Otherwise use Save task.
Findings daily workflow
Findings is the detection backlog. It is best for reading detection details, linking work, and deciding whether a finding needs deeper triage.
Click Findings, then filter or select a finding from the backlog.
Read the evidence, source, severity, status, and any linked task or run context.
Click Create task when the finding needs remediation, research, or review ownership.
For supply-chain SCM-* findings, switch to Supply Chain Triage for advisory checks, evidence verdicts, mitigation, closure, and research/blog handoff.
Independent research: lead to publication
Research Cases are the durable investigation record. Use them for original package, malware, typosquatting, infrastructure, or vulnerability research that may become a public report.
SCM-* alert handling, evidence verdicts, local impact, mitigation, and response.Choose a lead: an alert from Supply Chain Triage, a reviewed package watchlist entry, or a public source you are authorized to investigate.
Open Research. Click New case for a manual investigation, or use Promote from package watchlist, then click Preview selected before Create draft cases.
Set a precise title, type, severity, confidence, owner, and summary. Add every affected package, publisher, repository, brand, or infrastructure item under Subjects.
Collect evidence safely: public source URLs, registry metadata, local artifact hashes, static-analysis notes, screenshots, and controlled sandbox results. Record provenance and timestamps. Never execute untrusted packages on this Mac.
Add IOCs only when supported by evidence. Link each IOC to its source evidence, add detection rules when useful, and write analyst notes explaining uncertainty and limitations.
Validate the claim and complete disclosure handling. Set confidence and move the case through Investigating, Validation, and Disclosure pending as appropriate.
When the readiness blockers are resolved, set status to Ready to publish, click Download case report, review the deterministic Markdown/JSON export, then click Create review draft.
Open Blog Ops, review the draft line by line, correct claims and references, then use Approve. Publish and deploy only after human editorial approval and responsible-disclosure review.
After publication, set the case to Published, preserve the export manifest, and use the IOCs and detection rules to improve SecOpsAI defensive coverage.
AI Dependency Guard workflow
Use AI Dependency Guard before merging AI-built code, generated manifests, or agent-suggested install commands. It detects missing, newly registered, lookalike, advisory-matched, and private/allowlisted dependency candidates without installing or executing packages.
--fail-on high or --fail-on critical.--include-agent-logs to compare manifests against OpenClaw, Hermes, and session telemetry for packages suggested before they appear in code.Run secopsai supply-chain ai-dependency-guard --path . --json from the repo you want to review.
Add --include-agent-logs --agent-source auto when OpenClaw, Hermes, or local session logs might contain AI-suggested dependencies.
Review missing_or_hallucinated, newly_registered, name_similarity_risk, source_mismatch, and advisory_matched classifications. Treat local_only_or_private as expected only when it matches your policy allowlist.
Use --persist-findings only for high-confidence risks that should enter the SOC queue. Those findings remain reviewable in Findings; the dashboard does not run package installs or dependency code.
For CI, use the GitHub Action mode ai-dependency-guard. Keep it warning-only for early rollout, then opt into fail-on: high once private package allowlists are tuned.
Native Triage daily workflow
Native Triage shows helper health, pending triage actions, orchestrator history, and local SecOpsAI state freshness.
Click Native Triage and check helper readiness before relying on dashboard actions.
Review pending actions. Apply or close only when the evidence and analyst note are ready.
Use recent orchestrator summaries to see what was queued, completed, failed, or needs human review.
If helper health is degraded, use the copyable CLI fallback from the relevant section and restart/update the helper before retrying buttons.
Supply Chain Triage daily workflow
Supply Chain Triage is the operational alert review and response plane. Start here when SecOpsAI has already detected a suspicious package release.
Click Supply Chain Triage, then click Refresh evidence.
Select an alert in Supply Chain Alerts. The default Actionability filter shows only operator-actionable alerts; switch to All alerts when you need to audit no-local-impact or review-only scanner evidence.
Run Run Evidence Verdict first. It summarizes package verdict, confidence, advisory evidence, scanner rules, local impact, mitigation, and operator commands.
Click Explain verdict and Check advisory matches when you need source-backed evidence beyond the scanner rationale.
Click Check local repo usage. If local usage is none, record that as environment impact only. Do not downgrade a malicious package because this repo does not use it.
Click Read raw report when you need the exact diff/rule evidence before writing an analyst note.
Update the Close / escalation note with a source-backed summary before any protected response action.
Use Generate mitigation for block, audit, hunt, cache cleanup, and secret-rotation guidance. Use Create blog draft only for review-only external communication.
Campaign Research workflow
Use Campaign Research when multiple packages, IOCs, sources, publishers, or ecosystems appear related to one supply-chain attack.
Open the Campaign Research & Autonomous Discovery dock inside Supply Chain Triage.
Either quick-load a fixture, paste campaign JSON, or manually add campaign ID, title, source URLs, actors, publishers, IOCs, behavior indicators, and package rows.
Click Run Campaign Research. This single read-only action returns campaign verdict, package verdicts, correlations, local impact, mitigation, and references.
Click Correlate Campaign when the campaign includes shared publishers, C2s, source reports, or overlapping strings.
Click Check Local Usage before persistence so SOC findings distinguish malicious package evidence from local exposure.
Click Persist Findings only after reviewing the campaign JSON, confirming the Orchestrator Review has no route blockers, and removing false package extractions. This action is token-gated.
Click Create Campaign Blog Draft only when the campaign has references, affected package table, IOCs or an explicit none-found statement, mitigation, and SecOpsAI detection logic.
Autonomous Discovery workflow
Autonomous Discovery is a lead generator. It monitors trusted sources and watchlists, extracts possible supply-chain campaign candidates, then lets you promote a candidate into Campaign Research.
Set Since, Source, Limit, and Min score. Start with 24h, all, 10, and 35 for daily review.
Click Run Discovery to fetch candidates without writing SOC findings or blog drafts.
Review candidate titles, scores, behavior signals, the package-noise summary, and Orchestrator Review. Treat high score as "worth checking", not proof. The orchestrator classifies the report, validates real packages/extensions, separates source references from attacker IOCs, and shows rejected noise.
Click Use in Campaign Research only when the recommended route is Campaign Research and there are no route blockers. Malware/APT, CVE-only, GitHub-token breach, or general threat-intel leads should stay in the routed review lane unless package evidence exists.
After promotion, inspect highlighted package rows. Use Clean Obvious Package Noise before research. It removes common junk such as byline CSS classes, ordinary websites, image filenames, random numbers, repository issue paths, long encoded image slugs, placeholders, or generic article words misread as package IDs.
Use Run Autopilot Dry Run to preview the end-to-end campaign path without persistence. Discovery write actions are intentionally not shown here; persist findings or create a blog draft only from reviewed Campaign Research output.
Use generated watchlist suggestions only for validated packages, publishers, actors, malware names, extension IDs, GitHub repos, campaign IDs, or attacker IOCs. Source domains such as news sites are references, not attacker IOCs. Click a suggestion to fill the form, verify it is real, then click Add to Watchlist to save it with the admin token.
Blog Ops daily workflow
Blog Ops is the protected newsroom for source-backed drafts, approvals, feed rebuilds, and deployment. It never should be used as an autopublish shortcut.
Click Blog Ops, then click Refresh Blog Ops to load workflow status, sources, and draft queue.
Use Fetch news to ingest sources, Create drafts to generate review-only drafts, or Run fetch + draft for both.
Select a draft in the review queue. Check title, summary, severity, body, references, IOCs, affected artifacts, and recommended actions.
Use edit/save if the article needs cleanup. In local helper mode, use Images & source screenshots to attach an approved source image candidate or source image URL, then re-review because media resets the draft to Needs review. Approve only when claims and images are source-backed, licensed/safe, and no internal checklist, local path, secret, or copied external article text appears.
Click Publish approved to blog only after approval. This writes approved drafts into the blog posts directory and rebuilds feeds, but drafts remain under Approved. Use Rebuild feeds only as a repair/regeneration action. Click Deploy blog to Cloudflare when ready; after a successful deploy, those staged approved drafts move to Deployed.
Protected action rules
The dashboard is an operator console, not a shell. Browser actions call protected helper endpoints; write actions require an admin token and should leave an evidence trail.
http://127.0.0.1:45680 for helper-backed actions. Hosted production intentionally does not call the retired secopsai-helper.secopsai.dev tunnel unless a live SECOPSAI_HELPER_BASE_URL is explicitly configured.