# A tour of the console

URL: /get-started/console-tour

Find your way around the Foxborne console. Learn what the marking banner and status bar report, where each task lives and how to reach any incident, run or event from the keyboard.



By the end you will know what each part of the frame reports and which page holds each task. You will also move around the console with search and keyboard shortcuts.

## What you need [#what-you-need]

* A Foxborne account. Any of the five roles works for the tour, and what you can change depends on your role, as [Roles and permissions](/security/roles) sets out.
* The console open in a browser window at least 1,180 px wide. Narrower windows hide two status bar segments, and narrow screens open the sidebar from **Open navigation**.

## Take the tour [#take-the-tour]

<Steps>
  <Step title="Sign in">
    The sign-in page names your organization and shows the **System use notice** your administrator wrote. Tick **I understand and consent**, then select **Continue with** *your identity provider*. The button stays disabled until the box is ticked, and the audit log records the acknowledgment.

    Below a divider labeled **Break-glass access**, the break-glass account signs in with an email and **Use a hardware security key**. That path is for when the identity provider is down, and "Every use is audited and alerts your security team."

    Once you are signed in, the console opens on **Incidents**. Its home address, `/app`, opens **Range status**, the one-screen view of the range described below.
  </Step>

  <Step title="Read the frame">
    The marking banner frames every screen, across the top and again across the bottom. It carries the system-high marking, **CUI** or **UNCLASSIFIED**, in the standard classification colors. The status bar above the bottom banner repeats it and reports on the deployment:

    | Segment     | Example                                 | What it tells you                                                                                                     |
    | ----------- | --------------------------------------- | --------------------------------------------------------------------------------------------------------------------- |
    | Marking     | **CUI**                                 | The same marking as the banner, shown while the banner is on.                                                         |
    | Environment | **AWS GovCloud (US-West)**, CUI enclave | Where this deployment runs. Hover over it for the network note.                                                       |
    | Network     | **No outbound internet**                | States that the deployment has no outbound internet access.                                                           |
    | Collectors  | **13 of 15 collectors reporting**       | Enrolled collectors online now. The dot is green only when all of them are. Select it to open **Vehicle collectors**. |
    | Version     | **Foxborne 1.4.2**                      | The installed release.                                                                                                |
    | Clock       | Sat 26 Sep 2026 09:45:00Z               | The current time in UTC, updated every second.                                                                        |

    The values shown are examples. All times in the console are UTC, and clock readouts end in **Z**. [Markings and handling](/concepts/markings) explains the banner.
  </Step>

  <Step title="Walk the sidebar">
    The sidebar groups pages by what you do on them: **Operations**, **Investigate**, **Analyze**, **Data**, **Connect** and **Administration**.

    | Group          | Item             | What it holds                                                                                                                                                                                                                        |
    | -------------- | ---------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
    | Operations     | **Range status** | One screen for the range: today's and yesterday's sorties, every vehicle's link state, open incidents by evidence level, rule firings in the last 24 h and what waits on an approver. See [Range status](/investigate/range-status). |
    | Investigate    | **Incidents**    | Failures under investigation, on a site map and in a table. Its count shows incidents that are not closed.                                                                                                                           |
    |                | **Runs**         | Every imported flight and bench run, with its import status and clock. While runs parse, it shows a count such as **1 parsing**.                                                                                                     |
    |                | **Vehicles**     | Each platform, its configuration and its runs.                                                                                                                                                                                       |
    |                | **Import files** | Manual upload of the files for one run.                                                                                                                                                                                              |
    | Analyze        | **Reports**      | The fleet over 7, 30 or 90 days: sorties, flight hours, rule results, vehicles, investigations and data quality, and saved reports generated as marked documents. See [Read the fleet over time](/analyze/reports).                  |
    | Data           | **Sources**      | Storage connections and vehicle collectors. An amber count shows sources that need attention.                                                                                                                                        |
    |                | **Rules**        | The detection rules, with their thresholds and versions.                                                                                                                                                                             |
    | Connect        | **Integrations** | Destinations, ingest endpoints, exports and the delivery ledger. An amber count shows deliveries in the dead-letter queue.                                                                                                           |
    |                | **Alerts**       | The alert rules, six by default, who they notify and their recent firings.                                                                                                                                                           |
    |                | **Automations**  | The automations, four by default, and their run history. Its count shows runs held for approval.                                                                                                                                     |
    | Administration | **Hosting**      | Where Foxborne runs, the encryption key, updates and outbound connections.                                                                                                                                                           |
    |                | **Access**       | Members, roles and sign-in.                                                                                                                                                                                                          |
    |                | **Audit log**    | Every recorded action, on one hash chain.                                                                                                                                                                                            |
    |                | **Settings**     | Marking, retention, redaction, import limits and the ordering bound.                                                                                                                                                                 |

    **Collapse the sidebar**, beside the Foxborne name, shrinks it to a rail of icons, and selecting the name expands it again. The browser remembers your choice.

    At the foot of the sidebar, the deployment button shows your organization and the mode, such as **Self-hosted, CUI enclave**, and opens **Hosting**. Your name, your job title and the **Account menu** button sit below it.
  </Step>

  <Step title="Use the top bar">
    Breadcrumbs on the left show where you are, such as **Incidents** / **INC-0142**, and each crumb links back. The browser tab takes the last crumb, as in **INC-0142 - Foxborne**.

    Each screen has its own address, down to the incident tab and the selected event, so a copied link opens the same view.

    In the top bar, a readout names the active range with its MGRS 100 km square and gives the date-time group in Zulu time, in the form `DDHHMMZ MON YY`, such as `260945Z SEP 26`. On the right sit the search field, the **Keyboard shortcuts** button and the theme button, which switches between the default dark theme and light.
  </Step>

  <Step title="Search from anywhere">
    Press <Kbd>⌘</Kbd> <Kbd>K</Kbd>, or <Kbd>Ctrl</Kbd> <Kbd>K</Kbd>, to jump to **Search incidents, runs, evidence**. Results appear from the second character, in up to five groups:

    | Group      | Matches                                                                                                                                                               | Up to |
    | ---------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----- |
    | Incidents  | Incident ID, title, vehicle and run ID                                                                                                                                | 5     |
    | Runs       | Run ID, label and vehicle                                                                                                                                             | 5     |
    | Evidence   | Event IDs that start with your text, or event titles once you type more than 3 characters                                                                             | 6     |
    | Vehicles   | Vehicle ID and frame name                                                                                                                                             | 4     |
    | By meaning | Events that say the same thing in other words, found by the [AI models](/concepts/ai-models). The group names what it matched, such as **By meaning: the radio link** | 6     |

    Use <Kbd>↓</Kbd> and <Kbd>↑</Kbd> to move through the results, <Kbd>Enter</Kbd> to open one and <Kbd>Esc</Kbd> to clear the field. Type `INC-0142` and press <Kbd>Enter</Kbd> to open the example incident. Type `radio` and **By meaning** adds the heartbeat losses, telemetry gaps and USB interface events whose titles never use the word. Search does not cover sources, collectors, rules, the **Connect** pages, people, the audit log or settings.
  </Step>

  <Step title="Learn the shortcuts">
    Press <Kbd>?</Kbd> anywhere outside a text field to open **Keyboard shortcuts**. The top bar button and the account menu open the same list:

    | Action                              | Keys                       |
    | ----------------------------------- | -------------------------- |
    | Search incidents, runs and evidence | <Kbd>⌘</Kbd> <Kbd>K</Kbd>  |
    | Previous or next event              | <Kbd>←</Kbd> <Kbd>→</Kbd>  |
    | Zoom in or out                      | <Kbd>\[</Kbd> <Kbd>]</Kbd> |
    | Fit the incident window             | <Kbd>F</Kbd>               |
    | Close the inspector or a dialog     | <Kbd>Esc</Kbd>             |
    | Show this list                      | <Kbd>?</Kbd>               |

    The event, zoom and fit keys act on an incident's timeline, and the arrow keys also step between events on an event page. [Keyboard shortcuts](/reference/keyboard-shortcuts) lists every key.
  </Step>

  <Step title="Open the account menu">
    Select **Account menu**, the button beside your name. It offers **Light theme** or **Dark theme**, whichever is not active, then **Keyboard shortcuts** and **Sign out**. Signing out returns you to the sign-in page.
  </Step>
</Steps>

## Where each task lives [#where-each-task-lives]

| Task                                                                | Where in the console                                                               | Guide                                                                      |
| ------------------------------------------------------------------- | ---------------------------------------------------------------------------------- | -------------------------------------------------------------------------- |
| Import a flight log and its companion evidence                      | **Import files**                                                                   | [Import files in the console](/collect/import-files)                       |
| Check a run's sources, clocks and import job                        | **Runs**, then the run                                                             | [Check a run](/investigate/runs)                                           |
| Open a new incident on a run                                        | **Incidents**, then **New incident**                                               | [Work an incident](/investigate/incidents#open-a-new-incident)             |
| Work an incident from timeline to report                            | **Incidents**, then the incident                                                   | [Work an incident](/investigate/incidents)                                 |
| Inspect one event and its original record                           | The incident's **Reconstruction** tab, then **Open event**                         | [Inspect an event](/investigate/event)                                     |
| Write, review and export a report                                   | The incident's **Report** tab                                                      | [Write and review a report](/investigate/write-a-report)                   |
| Compare a vehicle's parameters across runs                          | **Vehicles**, then the vehicle                                                     | [Vehicles and parameter drift](/investigate/vehicle)                       |
| Chart the fleet over a period                                       | **Reports**                                                                        | [Read the fleet over time](/analyze/reports)                               |
| Save, schedule or download a report                                 | **Reports**, then **New report** or **Saved and generated**                        | [Save and schedule reports](/analyze/saved-reports)                        |
| Add a vehicle to the roster                                         | **Vehicles**, then **Add vehicle**                                                 | [Vehicles and parameter drift](/investigate/vehicle#add-a-vehicle)         |
| Connect storage or enroll a collector                               | **Sources**, on **Connections** or **Vehicle collectors**                          | [Connect a storage source](/collect/sources)                               |
| Create a detection rule                                             | **Rules**, then **New rule**                                                       | [Thresholds, scopes and overrides](/rules/configure#create-a-rule)         |
| Change a rule's threshold or scope                                  | **Rules**, then the rule, then **Edit**                                            | [Thresholds, scopes and overrides](/rules/configure)                       |
| Set up a destination and turn on its egress                         | **Integrations**, on **Destinations**, or **Add destination**                      | [Egress, data classes and the delivery ledger](/integrate/egress-controls) |
| Create an alert rule                                                | **Alerts**, then **New alert rule**                                                | [Alerts](/integrate/alerts#create-an-alert-rule)                           |
| Route an alert rule or switch it off                                | **Alerts**, then the rule's **Edit** or its switch                                 | [Alerts](/integrate/alerts)                                                |
| Create an automation                                                | **Automations**, then **New automation**                                           | [Automations](/integrate/automations#create-an-automation)                 |
| Switch an automation on or read its runs                            | **Automations**, on **Automations** or **Run history**                             | [Automations](/integrate/automations)                                      |
| Export evidence from an incident                                    | The incident's **Export** button, or **Integrations**, **Exports**, **New export** | [Export formats and evidence bundles](/integrate/exports)                  |
| Follow an export or replay a dead letter                            | **Integrations**, on **Exports** or **Delivery ledger**                            | [Export formats and evidence bundles](/integrate/exports)                  |
| Check which ingest endpoints listen                                 | **Integrations**, on **Ingest**                                                    | [Stream logs to Foxborne](/collect/streaming)                              |
| Install an update                                                   | **Hosting**, then **Install an update**                                            | [Install an update](/deploy/upgrades)                                      |
| Invite people and change roles                                      | **Access**, on **Members**                                                         | [Invite, change and remove access](/security/manage-access)                |
| Verify or export the audit chain                                    | **Audit log**, then **Verify chain** or **Export**                                 | [Audit log](/security/audit-log)                                           |
| Set the marking, retention, redaction, file limit or ordering bound | **Settings**                                                                       | [Markings and handling](/concepts/markings)                                |

## What you have now [#what-you-have-now]

You know what the banner and status bar report and which page holds each task. You can reach any incident, run, event or vehicle from search, and step through a timeline from the keyboard.

## Next [#next]

* [Quickstart: reconstruct your first incident](/get-started/quickstart) puts the tour to work on the example dataset.
* [Roles and permissions](/security/roles) lists what each role can change.
