Get started
Create a free account, verify your email, create a workspace and find your first report.
WitnessOps has a browser app and a Linux command-line client. Start in the browser; the CLI is optional. Creating an account is free and requires no card. Verify your email, then create your own workspace. An invitation is required to join someone else’s workspace.
1. Create your account
Open Sign up and complete the identity provider's signup flow. If you already have an account, use Sign in.
Complete email verification on the hosted sign-in screen. In the app, choose Create workspace and enter a name. This creates your workspace and its Owner membership; signup alone does not create a subscription or authorize checks. You can create up to three workspaces, counting archived workspaces. This is a per-creator limit, not a shared customer cap.
To join an existing workspace, ask its Owner for an invitation and accept it while signed in with the matching verified email. Existing Early Access invitations may instead show Activate workspace access. If access is paused, unavailable or unexpectedly requires an invitation, contact Support; do not create another account to bypass a restriction.
You can use the public free check without signing up. Only check a hostname you own or are authorized to check. Its public result and download do not require an account, and the snapshot is not automatically imported into a workspace.
2. Open the app
The browser app needs no installation. Open WitnessOps and sign in with your verified account. Select an existing workspace or create your own. Check the workspace and role before continuing.
Owners and Contributors can add assets and authorize supported checks. Viewers can read and export accessible results. Owners manage invitations, roles and members; signing in does not elevate a role.
3. Set up the optional CLI
Read CLI setup and authentication. The current CLI is a private package in the public source repository, not a published npm installer. The guide documents running that source with Node.js 22. Do not use an unverified installer or assume that the CLI is needed for browser access.
4. Make your first permitted observation
In an authorized workspace, an Owner or Contributor can open Assets, choose Add asset, and add a public hostname they are authorized to check. Open the asset and review the available check and authorization controls before starting. Account creation and CLI login do not start collection.
A saved observation is a new check; it is separate from a snapshot previously run on the public website. Linux server checks and signed Local Audit imports have separate requirements. Do not run privileged collection commands just to test login.
5. Find results and reports
Open Assets to inspect a system's observation history. Open Reports to find saved reports; a workspace with no saved observations has no reports yet. From an observation, use View report or inspect its supporting evidence and limitations. Undetermined results are unresolved, not a pass.
Use Settings for available workspace settings. A report describes the recorded scope and time; it does not certify the whole system as secure.
Need help?
Ask WitnessOps or contact support for signup, invitation, installation or authentication questions. AI chat is optional. To create a human support request, submit the form and verify your email. Never paste passwords, tokens or private evidence into chat or the form.
For paid expert work, read the separate review workflow or buyer path. Prices, agreed scope and permission to work remain separate from signup.