Console Overview
The Telovix Console is the security operations workspace for fleet health, runtime evidence, detection, response, API Security, Kubernetes security, compliance, and telecom monitoring. The available pages and actions depend on the signed-in user's role and the active platform vertical.
Where to start
| If you are... | Start here |
|---|---|
| Installing the Console for the first time | Console Installation then return to complete the setup wizard |
| Enrolling your first sensor | Quick Start for an end-to-end walkthrough |
| Investigating an active alert | Alert Inbox and Triage |
| Tracing a suspicious process or binary | Process Tree and Investigate |
| Scoping a policy or enforcement rule | Fleet Management to target the right sensors, then Security Policies |
| Monitoring compliance posture | Compliance |
| Setting up 5G Core or O-RAN monitoring | Ensure the telecom vertical is active in Settings, then see Telecom and O-RAN Overview |
| Integrating with a SIEM or webhook | SIEM Integration or Webhook Notifications |
| Managing users and roles | RBAC and User Management |
| Configuring the AI assistant | AI Assistant |
Navigation sections
The Console navigation follows the operational workflow from monitoring through detection and response. The Telco section is visible only when the telecom vertical is active.
Dashboard
The Dashboard summarizes fleet health, recent activity, alerts, resource use, and data-delivery status. Select a metric or chart segment to open the corresponding filtered view.
Sensors
| Page | What you do there |
|---|---|
| Fleet | Find enrolled Sensors, review health and identity, open Sensor details, manage groups, and monitor upgrades. |
| Deploy | Generate deployment commands and enrollment tokens for supported environments. |
| Health Center | Review fleet connectivity, event delivery, resource use, and Sensor health evidence. |
Monitor
| Page | What you do there |
|---|---|
| Live Feed | Follow incoming runtime events and open an event for process, network, workload, and security context. |
| Shell Sessions | Review observed interactive shell sessions and the activity associated with each session. |
| Runtime Explorer | Inspect processes, system activity, connections, listening services, and containers for selected Sensors. |
| Investigate | Search historical evidence with server-side filters and build an investigation from matching events. |
| Process Tree | Reconstruct observed process ancestry and inspect live or historical execution evidence. |
| Threat Graph | Explore relationships between runtime entities and correlated security activity. |
Detect
| Page | What you do there |
|---|---|
| Attack Chains | Review correlated runtime sequences and their evidence timelines. |
| Behavioral Analytics | Investigate deviations from learned behavior, review baseline maturity, and manage Anomaly Exceptions. |
| Runtime Detection | Review analytics, manage Custom Rules and Built-in Rules, and inspect Recent Matches. |
| API Security | Review API posture, inventory, threats, contracts, request evidence, and visibility health. |
| SBOM Scanner | Inspect image inventories, software components, vulnerabilities, and scan status. |
Respond
| Page | What you do there |
|---|---|
| Runtime Blocks | Review enforcement analytics, active policies, security-policy templates, and custom blocking policies. |
| Application Restrictions (inside Runtime Blocks) | Define allowed application behavior and review it in Observe, Audit, or Enforce mode. |
Alerts
| Page | What you do there |
|---|---|
| Inbox | Triage fired alerts, record verdicts, add notes, and pivot into investigations. |
| Alert Rules | Configure alert conditions, scope, routing, and notification destinations. |
| Notifications | Review and manage notification delivery. |
Reports
| Page | What you do there |
|---|---|
| Compliance Reports | Review framework posture and supporting runtime evidence. |
| Analytics | Analyze event trends and activity over the selected time range. |
| Audit Log | Review operator actions that changed identity, policy, or fleet state. |
| SIEM Integrations | Configure and monitor external security-event forwarding. |
Kubernetes
| Page | What you do there |
|---|---|
| Kubernetes Fleet | Open fleet or cluster views for workloads, resources, connectivity, security posture, and cluster-scoped API Security. |
| Admission | Review admission decisions and configure admission policy behavior. |
Telecom (telecom vertical only)
| Page | What you do there |
|---|---|
| Network | Open the network workspace, Overview topology, Network Functions, RAN, and O-RAN views. |
| Sessions | Inspect session evidence, User Plane, 5G Core, and supported Protocols. |
| Threats | Review telecom findings and detection details. |
| Assurance | Review service levels and start or download packet captures. |
See Telecom Overview for the views within each workspace.
Settings and administration
Administrators open Settings from the user menu. Settings are grouped by function and include infrastructure, authentication, users, integrations, API access, updates, license, and vertical configuration. Pages that require operator or admin access are hidden or read-only for lower roles.
| Page | What you do there |
|---|---|
| Infrastructure | Configure platform services, scanners, email, AI providers, and deployment-wide settings. |
| Authentication and Users | Manage local accounts, roles, MFA, sessions, and SSO. |
| Integrations and API Access | Configure webhooks, SIEM destinations, and API keys. |
| Updates and License | Review software-update settings, entitlement status, and licensed capacity. |
| Appearance | Choose your theme, font, text size, sidebar position, and detail-panel widths. |
| Data Lake | Configure S3-compatible or Azure Blob destinations for received sensor data. |
Roles and permissions
The Console has five roles. Permissions apply consistently to Console pages and API operations.
| Role | Tier | Capabilities |
|---|---|---|
viewer | 1 | Read-only access to fleet view, events, alerts, and compliance pages. Cannot create, modify, or delete anything. |
analyst | 2 | Everything in viewer, plus: create and manage investigations, add notes, run AI triage. |
sensor_owner | 3 | Scoped operator access. Can manage sensors explicitly assigned to this user but cannot access unscoped fleet data. Same API permissions as operator within the assigned scope. |
operator | 3 | Full sensor management, policy assignment, enforcement rule creation, investigation management, alert triage, custom rules. Cannot create users or modify Console infrastructure settings. |
admin | 4 | All operator capabilities, plus: user management, Console settings, sensor revocation and deletion, billing/license management. |
sensor_owner and operator share the same permission tier (3). The difference is scope: sensor_owner users have their accessible sensors restricted to an explicitly assigned list; operator users can access all sensors (unless cluster-level scope is configured).
Authentication
Session TTL: 12 hours by default. Sessions expire after 28 minutes of inactivity with a warning, and auto-logout occurs at 30 minutes.
Remember me: 30-day session when selected at login.
Passwords: Minimum length is 12 characters.
Two-factor authentication: Password-enabled accounts can configure an authenticator in account settings. When enabled, local login requires the code after the password. For SSO-only accounts, configure MFA at the identity provider. See SSO.
SSO: OpenID Connect (OIDC) is supported for Okta, Microsoft Entra ID, Google Workspace, and generic OIDC providers. Administrators configure it from Settings > SSO.
Vertical and platform context
The vertical setting controls which navigation sections and features are active:
standard: All sections except the Telco navigation group are visible. Telecom-specific compliance frameworks, AI tools, and dashboards are hidden.telecom: All sections including the full Telco navigation group are active. 3GPP TS 33.117, O-RAN WG11, CIS Telecom, and NIS2 Telecom compliance frameworks are selectable.
Set the vertical during the setup wizard. You can change it at any time from Settings, but the service requires a restart for the change to take effect across all active sessions. No database migration is needed.
AI assistant
The Console includes an AI assistant accessible from a panel on supported pages. Its structured tools query fleet data, events, baselines, and compliance state. The assistant can correlate events, reconstruct process ancestry, query NGAP KPIs, and help write detection rules.
The LLM provider is configurable from Settings: Anthropic, OpenAI, Gemini, a custom OpenAI-compatible endpoint, or a Telovix-managed endpoint for Telovix Cloud deployments. The assistant is disabled by default; enable it by configuring a provider and API key in Settings.
See AI Assistant for the full tool list and configuration.