Users & Access
Map each Cloudflare Access login (email) to a role + tenant scope. Who can log in is controlled in the Cloudflare Zero Trust dashboard; this page controls what they can do here. Roles: soc_admin (full + manage users), soc_analyst (respond, cases), read_only (view only).
Users & Access is soc_admin only. Your role: {{ myRole }}.
{{ userFormTitle }}
All tenants
{{ t.label }}
Agent Installer
Generate a ready-to-run monitoring agent for your endpoints. Each installer is pre-keyed to {{ instTenantName }} and connects out to the 365 Security gateway on port 443 — no inbound firewall changes and no VPN. Run it as Administrator (Windows) or root/sudo (Linux/macOS) on the machine you want monitored.
{{ instMsg }}
Installer ready — {{ instResName }}
Endpoint ID: {{ instResId }}
Agent group: {{ instResGroup }}
Gateway: {{ instResManager }}
Run as: {{ instResRunAs }}
{{ instResCmd }}
{{ instEdrNote }}
{{ tenantCount }} managed client orgs · isolated Grafana + Wazuh
Onboard New Client
← All tenants
{{ tv.healthLabel }}
Open org in Grafana ↗
{{ tv.name }}
Grafana org {{ tv.org }} · {{ tv.siteCount }} sites monitored
{{ tv.isoNote }}
Sites
← {{ sd.tenantName }}
{{ sd.statusLabel }}
{{ p.label }}
Per-site dashboard ↗
{{ sd.domain }}
{{ sd.tenantName }} · org {{ sd.org }}
{{ s.label }}
{{ s.value }}
{{ s.sub }}
Scope
Open in Explore ↗
IOC lookup
{{ iocResult.verdict }}{{ iocResult.q }}
{{ iocResult.detail }}
Investigate any IP / domain / hash — threat-intel verdict, attack activity on our estate (events · peak severity · auto-block · IRIS alert), and the suggested action. An IP that attacked us reads SEEN, not CLEAN.
Attacker activity · supporting context
Containment
blocked
released · 30m timeout
detected · not contained
LIVE
Origin by Country
{{ c.country }}{{ c.count }}
Top MITRE Techniques
{{ t.tactic }}
Network IDS · Suricata
{{ idsCard.total }}
{{ idsCard.sub }}
{{ s.count }}
Top external talkers
{{ t.ip }}{{ t.meta }}
{{ idsCard.emptyMsg }}
Detection queue · Wazuh alerts
Open in Explore ↗ (deep-dive in SIEM)
{{ alertShowing }}
File-integrity changes · last 24hnewest first · sensitive-path changes in amber
Portfolio concentration · tenant → endpoint · tile size = total CVEs, fill = critical density
critical
high
medium
low
{{ t.critStr }} critical
{{ t.total }}
{{ b.label }}
CVE exposure · wazuh-states-vulnerabilitiesCVE dashboard ↗
{{ k.label }}
{{ k.value }}
{{ k.sub }}
Compliance scorecard · framework pass-rate by tenant
click a tenant to scope endpoints + findings · red<50 · amber<80 · green≥80
GDPR = process/legal control, not config-scannable (N/A). {{ compMultiNote }}
CIS hardening by endpoint · SCA score vs 70% target
Showing: {{ compShowing }}show all
{{ e.host }} · {{ e.tenant }} · {{ e.os }}{{ e.failStr }}{{ e.scoreStr }}
Compliance findings · what's broken · where · how to fix
live Wazuh SCA failed checks
Live from Wazuh SCA (CIS benchmarks, fleet-wide). Framework scores are real pass-rates of checks tagged to each framework; NIST 800-53 uses direct tags where present plus the CIS→NIST crosswalk. GDPR is a process/legal control not covered by config scanning (N/A). Full raw data in the Grafana 365smg-compliance dashboard.
Per-tenant SLA · MTTA / MTTR vs contractual target
Client-facing PDF reports · white-labeled under 365SMG · availability gated by service plan. Open a report to preview, then print to PDF.
Period
June 2026
Client
▼
{{ reportSel.plan }}
{{ reportSel.availLabel }}
{{ rep.title }}
{{ rep.badge }}
{{ rep.cadence }}
Live data: for the 365smg estate, all six reports render live from Wazuh + IRIS — 30-day detections, CVE state, CIS/SCA scores, MITRE breadth, and real IRIS cases. Metrics with no live feed yet (MTTA/MTTR, edge uptime, IdP account/admin-action counts, change-approval records) are shown honestly as “—” rather than estimated — instrumenting those is the remaining roadmap item (see docs/CLIENT_REPORTS.md).
DFIR-IRIS · alerts pushed from the SOC portal → escalate to cases
{{ caseShowing }}
{{ respGateTitle }}
{{ respGateSub }}
Filter
AUTO → PROPOSE = would auto-contain when armed (near-certain + reversible) · PROPOSE = always needs a human (higher FP) · ♻ Reversible = analyst approve is the 2nd eye · ⚠ Irreversible = needs a named 2nd approver
{{ p.actionIcon }} {{ p.actionLabel }}
{{ p.confLabel }}
{{ p.revLabel }}
{{ p.id }} · {{ p.ago }} ago
{{ p.rule }}
{{ p.tenantName }} · agent {{ p.agent }} ({{ p.host }}){{ p.targetLine }}
{{ p.reason }}
{{ p.caseLinkLabel }}
{{ p.resultText }}
{{ p.gateNote }}
No pending proposals — you're clear. ✓
Currently contained — reverse when triage clears. Each reverse runs through respond() and is audited.
{{ c.kindLabel }}{{ c.host }}
{{ c.tenantName }} · {{ c.detail }}
No active containments. Isolated hosts and quarantined files appear here for one-click reversal.
Automated containment + control-plane actions — the record you can show a client with certainty. Auto-blocked attackers (Wazuh firewall-drop) never create a proposal; they land here as proof they were handled, with a link to the IRIS alert.
{{ h.label }}
{{ h.value }}
{{ h.sub }}
Per-client telemetry · {{ telCount }} tenants · click a row for detail
Perimeter firewall & IDS · last 24h
Open firewall dashboard ↗
{{ fwKpi.blocks }}
Blocks
{{ fwKpi.uniqueSrc }}
Unique blocked src IPs
{{ fwKpi.topPort }}
Top denied port
{{ fwKpi.idsAlerts }}
IDS/IPS alerts
Platform datasources · isolation-enforced
shared stack · per-tenant isolation at the datasource
{{ d.name }}
{{ d.healthLabel }}
{{ d.detail }}
{{ d.iso }}
Showing 365 SMG SOC-wide dashboards — pick a tenant in Scope above to see that client's.
Grafana dashboards · {{ launcherCount }}
deep-link · Cloudflare Access authenticates you · opens in Grafana ↗
{{ f.folder }}
Plan catalog · entitlements
Tenant subscriptions · usage vs. plan · synced from Zoho
Open Zoho Billing ↗
Zoho is the billing system of record & customer-facing surface (hosted invoices + client portal). This screen is internal control/visibility only — no card data is handled here. Enforcement: UI upsell → orchestrator gate → provisioning limits → auto-suspend on non-payment. See docs/BILLING_ENTITLEMENTS.md.