Public Guide

Onboard Your Workspace

Create your workspace, first administrator, and integration keys so your team can start ingesting findings safely. Audience: Workspace owners and first tenant administrators. Typical setup time: 15-20 minutes.

Start herejourney

Use this if

Create your workspace, first administrator, and integration keys so your team can start ingesting findings safely.

Audience: Workspace owners and first tenant administratorsTypical time: 15-20 minutes

Start here

Step 1 of 7

Recommended
1
2
3
4
5
6
7

Before You Begin

  • Authorized Identity: Administrator access to your company's identity provider (IdP) or authority to register a new organization profile.
  • Scanner Access: Access to run the Docker container or install scanner clients in your CI/CD pipelines.
  • API Key Permissions: Authority to generate and store secure integration API keys (requires admin privilege).
  • Network/Firewall Permissions: Network permissions allowing outbound HTTPS connections to api.blackshield.chaplau.com.
  • Prepare organization name, workspace slug, and first admin work email.
  • Decide who will own triage and API key rotation after onboarding.
  • Have one scanner target ready for first-ingestion validation.

Do this now

1

Step 1

Create workspace and first admin

Use guided onboarding to register your organization and establish the first trusted admin account.

  • Complete organization profile and workspace slug.
  • Verify admin email and enforce your password policy requirements.
  • Sign in and confirm dashboard access for the primary admin.

What success looks like

Sign in and confirm dashboard access for the primary admin.

2

Step 2

Create integration API keys

Issue separate keys per integration so you can rotate or revoke without disrupting all pipelines.

  • Create one API key per CI pipeline, scanner, or cloud integration.
  • Set expiration windows that align with your secret rotation policy.
  • Store raw keys in your secret manager, never in source control.

What success looks like

Store raw keys in your secret manager, never in source control.

3

Step 3

Set ownership and operating defaults

Define who reviews findings and how escalation decisions are made before data starts arriving.

  • Assign at least one admin and one analyst owner.
  • Set target response times for critical and high severity findings.
  • Share a first-week rollout checklist with engineering and security leads.

What success looks like

Share a first-week rollout checklist with engineering and security leads.

What success looks like

  • First admin can sign in and open the dashboard.
  • At least one ingestion API key is created and stored in your secret manager.

Continue

Keep your rollout moving with the next recommended step.

After Login: First-Day Next Steps
Onboard Your Workspace | BlackShield Docs