Skip to content

Getting started full revamp - #3088

Open
alexane-bougeardbebin-sekoia wants to merge 68 commits into
mainfrom
revamp/gettin_started
Open

Getting started full revamp#3088
alexane-bougeardbebin-sekoia wants to merge 68 commits into
mainfrom
revamp/gettin_started

Conversation

@alexane-bougeardbebin-sekoia

Copy link
Copy Markdown
Contributor

No description provided.

Updated the documentation to reflect the new name and features of the Roy AI assistant, including its capabilities and usage instructions.
Corrected the link for event drop notifications in best practices.
Added workspace mode scope details and updated triggers.
Added webhook payload reference and example to documentation.
Added information on finding incoming webhook URLs for Slack, Microsoft Teams, and Mattermost.
Added instructions for generating a HAR file and troubleshooting steps for WebSocket connectivity issues.
Added a note about legacy role names and their descriptions for users maintaining older scripts or using the Sekoia API directly.
Added access information for different user roles regarding subscriptions.
Removed duplicate 'FAQ and troubleshooting' entry.
Updated the notification creation instructions to reflect changes in terminology and structure.
Updated markdown links and improved clarity in instructions for triaging alerts.
Updated links in glossary to include '.md' extension for consistency.
Updated links in the getting started documentation to include the .md extension for consistency.
Updated user invitation steps and related links for clarity.
Updated links in the login guide to include file extensions.
Updated links to use .md extension for consistency.
@github-actions

github-actions Bot commented Jul 3, 2026

Copy link
Copy Markdown

Newest code from alexane-bougeardbebin-sekoia has been published to preview environment

🚀 Latest deployment was built on 2026-07-03 15:47:36 (f442e6e489d058cc179418927f9f0e685cd4c9f2).

@TomLecSek TomLecSek left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The theme is really black&white 😅 . Intended i suppose but i think changing the color for titles and subtitles will improve the readibility of pages by identifying sections visually.

Review to continued...

Comment thread docs/getting_started/index.md Outdated
Comment thread docs/getting_started/index.md Outdated
Comment thread docs/getting_started/index.md Outdated

### Sekoia Defend

Sekoia Defend is the extended detection and response (XDR) product. It collects logs from your entire environment, applies a continuously updated catalog of over 1,000 detection rules mapped to the MITRE ATT&CK framework, and gives you the tools to investigate alerts and automate responses.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

XDR should have an entry in Glossary imo.


# What is Sekoia

Sekoia is an AI-powered Security Operations Center (SOC) platform that brings together detection, threat intelligence, and automated response in a single, integrated solution. It is designed to help security teams of all sizes detect threats faster, investigate with more context, and respond with less manual effort.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Enhancement suggestion:

I would be nice to have an automated link between words and their anchor in the Glossary.
I'm sure mkdocs does that somehow (with a plugin maybe ?)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Comment thread docs/getting_started/what_is_sekoia.md
Comment thread docs/getting_started/troubleshooting_common_issues.md Outdated
Comment thread docs/getting_started/troubleshooting_common_issues.md
Comment thread docs/getting_started/troubleshooting_common_issues.md Outdated
Comment thread docs/getting_started/troubleshooting_common_issues.md Outdated
Comment thread docs/getting_started/troubleshooting_common_issues.md
Comment thread docs/getting_started/troubleshooting_common_issues.md
@Corentincoutable

Copy link
Copy Markdown
Contributor
Capture d’écran 2026-07-06 à 16 09 32

I would suggest to re-word it as follow :
"In multi-tenant workspaces, a "Communities" button appears in the breadcrumb at the top of the page. Use it to filter the platform based on a specific community or select multiple communities to view aggregated data for all of them."


Capture d’écran 2026-07-06 à 16 27 19

I would suggest to re-word it as follow :
"If you are not sure whether a setting belongs to the workspace or the community, check the Settings menu. Workspace-level settings appear at the top of the listing (Workspace label), and community-level settings appear just bellow it (Communities you manage label)."

And here is the specified screenshot :
Capture d’écran 2026-07-06 à 16 26 57


Capture d’écran 2026-07-06 à 16 43 01

I would suggest to re-word it as follow :
"To filter on a specific community in a multi-tenant workspace, click the Communities button in the breadcrumb at the top of one page and select the community (or communities) you want to access."

@ka0ula

ka0ula commented Jul 8, 2026

Copy link
Copy Markdown
Contributor

IMHO for the Intelligence part, the stepper doesn't reflect the real use case priority. Right now it opens with "explore the database," then buries feed/dissemination inside a reports step. But dissemination into existing security tooling is one of the strongest reasons an MSSP, CISO, or SOC lead buys Intelligence in the first place. If we lead with database exploration, we're asking a skeptical buyer to tour a UI before we show them the thing that actually convinces them (their tools getting fed with our intel).

Before we rewrite this, I'd rather make sure we're anchoring the guide on the right use cases instead of guessing. @alexane-bougeardbebin-sekoia can you sync with Julien De Pins on this? He talks to prospects and customers directly and will know which use case actually closes deals or drives adoption (search/investigation vs. dissemination vs. reporting vs. notifications). That should decide the order and weight of these steps, not our assumptions from the inside

@AndersOlsson-Sekoia AndersOlsson-Sekoia left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Great work Alexane, missing a few critical points however. Suggested as per the review comments.

Comment thread docs/getting_started/quick_start_reveal.md Outdated
Comment thread docs/getting_started/quick_start_reveal.md Outdated
Comment thread docs/getting_started/quick_start_reveal.md Outdated
Comment thread docs/getting_started/navigate_the_platform.md Outdated
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants