Getting started full revamp - #3088
Conversation
Updated the documentation to reflect the new name and features of the Roy AI assistant, including its capabilities and usage instructions.
Corrected the link for event drop notifications in best practices.
Added workspace mode scope details and updated triggers.
Added webhook payload reference and example to documentation.
Added information on finding incoming webhook URLs for Slack, Microsoft Teams, and Mattermost.
Added instructions for generating a HAR file and troubleshooting steps for WebSocket connectivity issues.
Added a note about legacy role names and their descriptions for users maintaining older scripts or using the Sekoia API directly.
Added access information for different user roles regarding subscriptions.
Removed duplicate 'FAQ and troubleshooting' entry.
Updated the notification creation instructions to reflect changes in terminology and structure.
Updated markdown links and improved clarity in instructions for triaging alerts.
Updated links in glossary to include '.md' extension for consistency.
Updated links in the getting started documentation to include the .md extension for consistency.
Updated user invitation steps and related links for clarity.
Updated links in the login guide to include file extensions.
Updated links to use .md extension for consistency.
Updated links in the secure your account documentation to include the .md extension.
Removed markdown link from note about 2FA deployment.
|
Newest code from alexane-bougeardbebin-sekoia has been published to preview environment 🚀 Latest deployment was built on 2026-07-03 15:47:36 (f442e6e489d058cc179418927f9f0e685cd4c9f2). |
TomLecSek
left a comment
There was a problem hiding this comment.
The theme is really black&white 😅 . Intended i suppose but i think changing the color for titles and subtitles will improve the readibility of pages by identifying sections visually.
Review to continued...
|
|
||
| ### Sekoia Defend | ||
|
|
||
| Sekoia Defend is the extended detection and response (XDR) product. It collects logs from your entire environment, applies a continuously updated catalog of over 1,000 detection rules mapped to the MITRE ATT&CK framework, and gives you the tools to investigate alerts and automate responses. |
There was a problem hiding this comment.
XDR should have an entry in Glossary imo.
|
|
||
| # What is Sekoia | ||
|
|
||
| Sekoia is an AI-powered Security Operations Center (SOC) platform that brings together detection, threat intelligence, and automated response in a single, integrated solution. It is designed to help security teams of all sizes detect threats faster, investigate with more context, and respond with less manual effort. |
There was a problem hiding this comment.
Enhancement suggestion:
I would be nice to have an automated link between words and their anchor in the Glossary.
I'm sure mkdocs does that somehow (with a plugin maybe ?)
There was a problem hiding this comment.
|
IMHO for the Intelligence part, the stepper doesn't reflect the real use case priority. Right now it opens with "explore the database," then buries feed/dissemination inside a reports step. But dissemination into existing security tooling is one of the strongest reasons an MSSP, CISO, or SOC lead buys Intelligence in the first place. If we lead with database exploration, we're asking a skeptical buyer to tour a UI before we show them the thing that actually convinces them (their tools getting fed with our intel). Before we rewrite this, I'd rather make sure we're anchoring the guide on the right use cases instead of guessing. @alexane-bougeardbebin-sekoia can you sync with Julien De Pins on this? He talks to prospects and customers directly and will know which use case actually closes deals or drives adoption (search/investigation vs. dissemination vs. reporting vs. notifications). That should decide the order and weight of these steps, not our assumptions from the inside |
AndersOlsson-Sekoia
left a comment
There was a problem hiding this comment.
Great work Alexane, missing a few critical points however. Suggested as per the review comments.
Updated instructions for customizing the interface, including clearer steps for dragging columns and setting preferred authentication methods.




No description provided.