Witen

Fleet control plane

Customer website guide

The customer website is the account and fleet control plane. Use it to enroll assets, understand tenant-attributed evidence, verify synchronized enforcement, manage versioned configuration and policy, distribute trusted networks, download software, and control the subscription.

Create your fleet and add protection

  1. Register, verify your email address, and sign in.
  2. Choose a plan or begin with the available free fleet capacity.
  3. Open Add Protection and create the fleet when prompted. One fleet credential represents account ownership and limits.
  4. Choose Server or VPS, WordPress, or Matomo.
  5. Follow the product-specific guide to create and use a one-time enrollment token. The Matomo plugin supplies its installation ID automatically.
  6. Confirm the asset’s first report under Protected Assets before treating setup as complete.

Read the Operations dashboard

Operations is the fleet-status landing page. Its 24-hour summary shows accepted evidence, events reported with a local block reason, and unique source addresses. Use the Activity link for the full graph and rankings.

  • Fleet contact counts enrolled sensors that reported within the stated 24-hour window; it is not a five-minute uptime SLA.
  • Receipt API available means the Collector can serve receipts. It does not mean every actuator has synchronized decisions.
  • Synchronized enforcement counts actual decision lifecycle receipts separately from ordinary block telemetry.
  • Fleet health alerts are compromise and attack-surge observations, not a list of every routine block.
  • CVE exposure is derived from installed plugin inventory and should be verified against the affected software before remediation.

Investigate Activity

Activity offers only fixed 1h, 6h, 24h, 7d, and 30d windows. Every query includes the customer identity and a bounded time range, uses precomputed five-minute tenant buckets, returns limited top rankings, and is cached briefly. Completed five-minute atoms mean the newest data can take up to five minutes to appear.

Evidence events

Accepted security observations. Several events can belong to one source address or request sequence.

Reported blocked

Events carrying a local block reason. This is telemetry rather than receipt proof.

Unique attacker addresses

Distinct source addresses observed in hostile context; not a permanent declaration that every address is malicious.

  1. Start at 24h and compare each metric with the immediately preceding 24h period.
  2. Switch to 1h or 6h to localize a fresh spike; use 7d or 30d to distinguish recurring baseline traffic.
  3. Use Top categories to identify behavior, Most active assets to locate impact, and Top sources to separate SSH, web, and plugin perspectives.
  4. Return to Operations and recent tenant events for examples, then use local Warden evidence when deeper host analysis is required.

Manage Protected Assets

Protected Assets lists enrolled installations, source type, displayed name, tags, software version, configuration version, last report, and derived reporting status. Sort by hostname, source, software version, or configuration version to find drift.

  • Reporting: the installation reported within the current healthy window.
  • Delayed: reports are later than expected; inspect local service and network health.
  • Offline: the last report is old enough to require operator attention.
  • Awaiting first report: enrollment exists but no successful event report has established runtime contact.

Asset detail controls

Depending on tier and source, an asset can expose display-name and tag editing, reporting availability, blocklist profile selection, and supported .htaccess backup/restore history. A restore request is an operational action; review the selected backup and current web-server context before requesting it.

Verify decisions with receipts

Decision Receipts are stable customer-visible records of an actuator outcome. Each receipt identifies its subject, action, scope, explanation, confidence, evidence count, actuator, lifecycle state, start, and expiry.

  • Pending: issued but not confirmed as applied.
  • Applied: the named actuator reported successful application.
  • Failed: the actuator attempted and reported failure; investigate locally.
  • Rolled back: a formerly applied decision was reversed.
  • Expired: its enforcement interval ended.

Manage configurations and policy groups

Configurations

Configs shows each enrolled reporter’s configuration document and version history. Treat secrets separately; versioned control-plane configuration should not expose installation credentials. Review changes before applying them to a production host.

Policy groups

  1. Create a group with a clear operational purpose such as Production SSH or Public WordPress.
  2. Assign only customer-owned properties; one property belongs to one policy group.
  3. Enter bounded SSH/HTTP thresholds, windows, and ban duration.
  4. Save a new immutable draft version.
  5. Review near misses and the seven-day conservative recommendations.
  6. Explicitly apply the intended version. Saving a draft never activates it.

Distribute trusted networks safely

The account allowlist accepts one exact IPv4/IPv6 address or CIDR per entry and distributes it to your Warden and WordPress protections. These entries are excluded from customer correlation and enforcement paths.

  1. Record why the address or network is trusted in the label.
  2. Prefer one exact address over a broad CIDR whenever possible.
  3. Add recovery and administration sources before tightening enforcement.
  4. Verify client-IP extraction behind proxies so you do not allow the proxy address accidentally.
  5. Review and remove stale entries periodically.

Downloads, plans, and entitlement state

Downloads

The authenticated Downloads page shows products allowed by the account, exact version, platform/libc, file size, and SHA-256 checksum. Choose Warden glibc, musl, legacy 386, Alpine APK, or a WordPress or Matomo plugin ZIP according to the target.

Billing

Billing shows the active plan and protected-asset capacity. After a plan change, protection setup normally finishes within a few seconds. The page refreshes activation status automatically; contact support if setup remains incomplete for more than a few minutes.

  • Before a downgrade, remove or plan for assets beyond the target capacity.
  • Use the billing portal for payment-method and subscription management.
  • Verify entitlement convergence before assuming a newly purchased slot is available.
  • Contact support for capacity beyond the published plans.

Troubleshooting and recovery

Dashboard asks you to create a fleet

No usable fleet scope is associated with the account. Complete Add Protection. If you already created one, confirm you are signed into the same verified account and that entitlement synchronization succeeded.

An asset stops reporting

WordPress reports depend on site traffic and background jobs. Quiet sites show “No recent report”; a gap does not mean the site or local protection is offline. Continuously running agents such as Warden use tighter heartbeat checks.

  • Check the local service/plugin maintenance heartbeat and system clock.
  • Verify its installation credential is present and readable.
  • Check DNS, TLS, and outbound connectivity to the Collector.
  • Do not confuse a Collector outage with stopped local Warden enforcement.

Activity is empty

  • Try 7d or 30d; a genuinely quiet window is valid.
  • Check Protected Assets for recent reports.
  • Allow up to five minutes for the newest completed rollup.
  • If Recent Events has data but Activity does not, report the selected window and time to support.

Understand Outcomes

Outcomes ranks bad actor addresses from tenant-scoped hostile observations. “Active verified blocks” is narrower: it counts only applied, unexpired decision receipts synchronized by an actuator. The separation prevents ordinary event telemetry from being presented as proof of enforcement.

Contact support safely

  • Open Support in the customer navigation.
  • Include the protected asset name, UTC time, Warden version, and relevant receipt IDs.
  • Never send API keys, enrollment tokens, passwords, or private raw logs by email.

Customer activity is unavailable

The bounded analytics service could not answer. Local protection is not disabled. Operations, asset state, and local Warden tools may still be available while the analytics path recovers.