1. Set up your organization
Create your organization, teams, and workspaces, then add members by invite, directory sync, or beacon. Onboarding walks through all of it. Workspaces group devices and their traces, and can receive targeted policies. Common workspaces include laptops, CI/CD, cloud agents, staging, and production, and they can just as easily follow teams, such as customer support and security. If organizing your devices that way would be useful, we suggest creating those workspaces up front, so guardrails and connectors can be scoped to a workspace when you reach step 3. If a single policy suits everything you run, one workspace is enough. Your organization starts with every built-in guardrail in Monitor mode, anomaly detection on a 24-hour cadence, and governance posture atdefault_allow. Nothing is blocked or redacted until you change it.
2. Install onto devices
Devices connect by browser sign-in, deploy key, or MDM. Onboarding covers each, and Install Ultra covers the installer itself. Install on one device first and check it there before going wider. Ask your agent “Call the Ultra Servers tool and show me my connected servers”, have it use one of those connectors, then confirm the call appears in Traces. Then roll out in cohorts: your security team first, then one more team, then wider. Ultra picks up the connectors already configured in each agent on first start, so nobody reconfigures anything by hand.3. Tailor your security controls
Your organization is already running every built-in guardrail in Monitor. This step is where you turn that up and decide what agents can reach in the first place. Two controls, and most organizations want both. Guardrails decide what an individual action is allowed to do. They inspect the action itself, so they work from the first call. Promote any guardrails as needed from Monitor to Block or Redact. Governance decides which connectors and tools are reachable at all. It works from your inventory, so it covers what Ultra has already seen and widens as your catalog fills in. Posture sets the baseline for actions that no rule matches:default_allow permits everything except what you block, default_deny permits only what you approve. Set the organization to the most permissive posture you want, then tighten individual workspaces according to desired policy.
Because governance depends on inventory, a connector nobody has used yet cannot be blocked by name, and default_deny usually lands later than your first guardrail promotions.
4. Monitor traffic
Your tool catalog fills in with the connectors and tools your agents actually reach for, and Traces shows what they did with them. Anomaly detection scans that traffic on a schedule, looking for suspicious patterns and recording each finding with a risk score. It starts on a 24-hour cadence, adjustable down to 15 minutes if you want issues surfaced sooner. A new organization raises no alerts until you switch sources on, so open Configuration in Alerts and enable the guardrail, governance, and anomaly sources you want. As the catalog settles, come back to step 3: extend governance to cover what has appeared, and move a workspace todefault_deny once its inventory looks stable.
What’s next
Onboarding
Create your organization and bring people and devices onto it
Guardrails
Enforcement modes, dry-run testing, and the built-in catalog
Governance
Posture, allow and deny rules, and drift enforcement
Quick Start for Users
The guide to hand to everyone you are onboarding