Help Desk
You are trying to do a specific thing. Here is how.
This is not the Knowledge Base. The Knowledge Base explains how the method works and why. This page answers a narrower question: you are in the middle of something and it is not working. Short, numbered, and honest about what we cannot tell you without seeing your workspace.
There is no chatbot here — a person answers instead.
There is no chat widget on this site. A question sent through /contact reaches a person, who writes back in full sentences with the same evidence discipline as an exposure report. That takes longer than a simulated reply. It is also the only kind of answer we are willing to stand behind.
Where to go
Three different problems go to three different places.
Sending a security report to the general contact form, or a product question to the disclosure channel, slows both down. Pick the row that matches what you actually have.
A product or account question
Scoping, access, billing, or anything about how the platform behaves.
Go to /contactA security report
You found, or suspect, a vulnerability in the platform or this site.
Go to /securityA methodology disagreement
You disagree with how the Theos Method scores, weights or tiers something.
Go to /methodologyTopics
Find your task.
Grouped by what you are trying to accomplish, not by product area. Search narrows the list; each card opens to numbered steps and, where one exists, an escalation line.
Getting set up
4 topicsConnect a code repository for scanning
The repository is in scope, its credential is read-only, and detectors can see its source and build manifests.
- 1Confirm the repository falls inside the estate boundary you agreed at kickoff. If it does not yet, see "Set the estate boundary for your first assessment" first.
- 2Have your platform team provision a read-only credential scoped to the repository or the organisation — never a personal account.
- 3Add the credential inside the workspace at [PLACEHOLDER: exact console path/label, e.g. Settings > Integrations > Source repositories].
- 4Confirm the connection shows as read-only and reachable before the next scan is scheduled.
If this does not work
- If the connection will not authenticate, check the credential is not scoped to a single branch — detectors need the default branch and any release branches agreed at scoping.
- If a repository does not appear after connecting, confirm it sits inside the org or group your credential covers; a per-repository token will not surface sibling repositories.
Provide read-only access to configuration and endpoints
Discovery can read configuration exports and reach the agreed endpoints, without any credential that could change anything.
- 1List the configuration sources and endpoint ranges you agreed in scoping.
- 2Provision read-only exports or reachability from the agreed source range only — never an administrative credential.
- 3Record any access request that will not be approved; it becomes a documented blind spot in the final report rather than a silent gap.
- 4Confirm with your engagement contact once each source is reachable.
If this does not work
- If a security reviewer is holding an access request, tell them explicitly that the engagement reads metadata and configuration only, never key material or production credentials — that single line usually clears the queue.
- If an appliance exposes no read-only export at all, say so; it is recorded as a blind spot rather than escalated further.
Set the estate boundary for your first assessment
A written boundary exists — business units, environments, regions and systems in and out of scope — before discovery runs.
- 1Write the boundary down before kickoff: business units, environments, regions, repositories, endpoints and appliances in scope, and everything explicitly out of scope.
- 2Name an owner who can settle a scope dispute inside a single conversation.
- 3Enter the boundary in the workspace at [PLACEHOLDER: exact console path/label, e.g. Settings > Workspace > Scope].
- 4Leave open questions open rather than guessing — record each one with an owner and a date to close it by kickoff.
If this does not work
- If two people describe the boundary differently, that disagreement is the finding. Resolve it before discovery runs, not after.
- If scope changes mid-engagement, re-run discovery rather than editing the existing inventory in place — see "Re-run discovery after a scope change".
Set up single sign-on for your workspace
Your team signs in through your existing identity provider, and access follows your own joiner-mover-leaver process.
- 1Identify your identity provider and confirm it supports the protocol AutoPQC expects. [PLACEHOLDER: supported SSO protocols and identity providers]
- 2Have your identity administrator configure the connection using the details at [PLACEHOLDER: exact console path/label, e.g. Settings > Security > Single sign-on].
- 3Test with one account before requiring SSO workspace-wide, so a misconfiguration cannot lock everyone out at once.
- 4Once verified, require SSO for all workspace members and remove any standing local accounts.
If this does not work
- If sign-in loops back to the login page, check clock skew and certificate validity on your identity provider first — that is the most common cause.
- If you are locked out entirely, reach us through /contact from a verified company email so we can restore access.
Running an assessment
4 topicsStart a Baseline Assessment
Discovery runs against the agreed boundary and produces a first-pass inventory.
- 1Confirm the estate boundary and access are both complete — see the Getting set up topics above.
- 2Trigger the scan from [PLACEHOLDER: exact console path/label, e.g. Workspace > New assessment].
- 3Watch for confirmation that detectors have started against each connected source.
- 4Expect a first-pass inventory within the timeframe agreed at kickoff.
If this does not work
- If the scan will not start, check that every connected source shows as reachable — a single failed connection can hold the whole run.
- If you need to add a source after starting, let the current run finish and start a fresh one rather than editing scope mid-scan.
Check on a running scan's progress
You can see which sources have been read, which are pending, and roughly how far the run has to go.
- 1Open the assessment's status view at [PLACEHOLDER: exact console path/label].
- 2Check per-source status rather than a single overall percentage — one large repository can dominate an aggregate figure.
- 3Note any source marked failed or skipped; these become candidates for the blind-spot list in the final report.
If this does not work
- If progress stalls on one source for an unusually long time, that is more often a reachability problem than a large repository — check the connection first.
Re-run discovery after a scope change
The inventory reflects the current boundary, and the change in scope is recorded rather than silently absorbed into the numbers.
- 1Update the written estate boundary first, with the reason for the change.
- 2Start a fresh assessment rather than editing the previous one's results in place.
- 3Compare the new run's asset count against the old one with the scope change in hand — a count that moves is expected and should not be read as progress or regression on its own.
- 4Record the method version each run was scored under; a score that moved because the method changed is a different fact from one that moved because your estate did.
If this does not work
- If the asset count changes by more than the scope change explains, check the method version on both runs before assuming discovery missed something.
Pause or cancel a scan safely
A running scan stops without leaving the inventory in a half-written state.
- 1Use the cancel control at [PLACEHOLDER: exact console path/label] rather than revoking access mid-scan, which can leave partial findings without provenance.
- 2Confirm the assessment status changes to cancelled before revoking any credential provisioned for it.
- 3If you cancelled to change scope, follow "Re-run discovery after a scope change" rather than resuming the cancelled run.
If this does not work
- If a scan will not cancel, wait for the current source to finish reading before retrying — detectors do not stop mid-file.
Reading results
4 topicsRead a finding record
You can see which detector produced a finding, in which artefact and revision, and what evidence it matched.
- 1Open the finding from the inventory list.
- 2Check the provenance panel: the detector name, the artefact and revision, and the matched pattern or configuration value.
- 3Check the inputs that moved the score and the weight each carried, not just the final number.
- 4If something looks wrong, use the correction path in "Review disputed findings with your engineers" rather than dismissing it informally.
If this does not work
- If a finding shows no provenance at all, treat that as a defect and report it through /contact rather than trusting the score.
Interpret a tier that changed since last scan
You know whether a tier moved because the estate changed, the method changed, or a correction was applied — and which of those it was.
- 1Check the method version recorded on both runs first; a tier move across different method versions is not directly comparable.
- 2If the method version is unchanged, check whether the asset itself changed — a configuration update, a new endpoint, a certificate renewal.
- 3Check the correction history for the asset; an engineer confirming or overriding a finding during review also moves the tier.
- 4Read the tier definitions rather than assuming: Acute, Elevated, Watch and Contained are fixed bands on the exposure score, not relative labels.
If this does not work
- If a tier moved and none of the above explains it, raise it with your engagement contact directly.
Understand the aggregate exposure score
You can say what the estate's single number does and does not tell a reader, before it goes in a board pack.
- 1Read the exclusions list before the score — the score is only a score of what was in scope.
- 2Remember the aggregate is a weighted figure, not an average or a percentage of assets affected.
- 3Track the tier distribution alongside the aggregate; movement between tiers is often visible before the aggregate shifts.
- 4Cite the pilot figures only as an illustration of the method, never as a benchmark for your own estate.
Review disputed findings with your engineers
A finding your team disagrees with is corrected in the record, with a reason, rather than argued about informally.
- 1Open the finding and bring the evidence panel into the review session rather than describing it from memory.
- 2Let the engineer confirm, correct or annotate the finding directly against the evidence.
- 3Apply the correction to the asset record, not to the score in isolation, so the reasoning survives the next scan.
- 4Leave anything unresolved as an open item rather than dropping it quietly.
If this does not work
- If your engineer and the finding disagree and neither side can produce evidence, record it as an open item and escalate to your engagement contact rather than guessing.
Exporting and sharing
3 topicsExport a CBOM
A machine-readable cryptographic bill of materials for the scope you assessed, in a form your build or supply-chain tooling can ingest.
- 1Open the assessment you want to export from.
- 2Choose the CBOM export option at [PLACEHOLDER: exact console path/label and supported file format].
- 3Confirm the export scope matches what you intend to hand downstream — a CBOM inherits the same estate boundary as the assessment it came from.
- 4Store the export alongside your other supply-chain artefacts; it is a point-in-time record, not a live feed.
If this does not work
- If the export is missing an asset you expected, check whether it was in the exclusions list before assuming the export is wrong.
Export the exposure report for an audit
Internal audit or an external assessor receives the report, the standards mapping and the evidence trail in one package.
- 1Confirm with audit what format and level of detail they expect before exporting — worth a five-minute conversation, not a guess.
- 2Export from [PLACEHOLDER: exact console path/label].
- 3Include the Evidence Ledger reference for the run alongside the report — see the Signal Log's Evidence Ledger panel for what that reference does and does not prove.
- 4Record the method version on the export cover page so a reader in a year can tell which rules produced it.
If this does not work
- If your assessor asks for a certification the export does not contain, read "What to hand an auditor" first — a Posture Attestation records an observation. It is not accreditation.
Account and access
3 topicsInvite a colleague
A named person can sign in to your workspace with the access level appropriate to their role.
- 1Confirm your own role permits inviting others — see "Set roles and permissions for a new team member" if you are unsure.
- 2Send the invitation from [PLACEHOLDER: exact console path/label], using their company email address.
- 3Assign a role at the point of invitation rather than leaving it at a default.
- 4Ask them to confirm sign-in before you rely on them for a review session.
If this does not work
- If an invitation does not arrive, check the address for a typo before resending — resending to the same wrong address will not help.
Set roles and permissions for a new team member
A team member can see exactly the scope their job requires, no more.
- 1Decide before inviting whether the person needs the whole estate or a scoped subset of it.
- 2Choose the role at [PLACEHOLDER: exact console path/label and the exact role names available].
- 3Review role assignments periodically, particularly after a reorganisation — access tends to accumulate rather than shrink on its own.
- 4Remove access promptly when someone leaves the team or the company.
If this does not work
- If someone reports seeing more or less than expected, check their role assignment before assuming a platform fault.
Rotate or revoke a workspace credential
A credential you no longer trust stops working, without breaking scans that do not depend on it.
- 1Identify every connection that uses the credential before revoking it — a shared credential across several sources will break all of them at once.
- 2Issue a replacement credential first, then revoke the old one, to avoid a coverage gap.
- 3Update the connection at [PLACEHOLDER: exact console path/label] with the new credential.
- 4Confirm the affected sources show as reachable again before the next scheduled scan.
If this does not work
- If you must revoke immediately for security reasons, do so and expect the affected sources to show as unreachable until reconnected — that is the safe failure mode.
Billing and plan
3 topicsUnderstand what your current plan includes
You can say what your plan covers — assessment frequency, seats and support level — without guessing.
- 1Check the plan summary in the workspace at [PLACEHOLDER: exact console path/label, e.g. Settings > Billing > Plan].
- 2Compare it against the current published tiers at /pricing; a plan agreed before a pricing change keeps its original terms unless you have agreed otherwise.
- 3If a limit is unclear — seats, assessment frequency, data retention — ask through /contact rather than assuming the more generous reading.
If this does not work
- If the workspace shows a limit you do not recognise agreeing to, raise it through /contact before it affects a scan you are relying on.
Get a copy of an invoice or billing statement
You have the document your finance team needs, from a source you can point them back to.
- 1Open the billing history at [PLACEHOLDER: exact console path/label, e.g. Settings > Billing > Invoices].
- 2Download the invoice for the period you need.
- 3If a past invoice is missing or a charge looks wrong, raise it through /contact with the invoice number rather than the amount alone.
If this does not work
- If nobody on your team can see the billing area at all, check whether their role includes billing visibility — see "Set roles and permissions for a new team member".
Change or cancel your plan
Your plan changes, or your workspace winds down, on terms you agreed to in writing beforehand.
- 1Confirm what happens to in-progress assessments and stored reports on a downgrade or cancellation before you request it — ask through /contact if this is not already written into your agreement.
- 2Submit the change through [PLACEHOLDER: exact console path/label, or a named commercial contact if plan changes are handled outside the console].
- 3Confirm the effective date in writing, since a plan change rarely takes effect mid-billing-period.
If this does not work
- If cancellation and data deletion need to happen together, also follow "Request deletion of your workspace data" below — they are two separate requests.
When something looks wrong
3 topicsA scan found far less than expected
You can tell whether a low asset count reflects a small estate, a narrow scope, or a real gap in access.
- 1Check the exclusions list first — a narrow estate boundary produces a low count by design.
- 2Check every connected source shows as reachable; a failed connection produces silent under-counting rather than a visible error.
- 3Compare against the documented detector coverage — some cryptography, such as runtime-only algorithm selection or closed appliances with no exposed configuration, is a known blind spot rather than a defect.
- 4If none of the above explains it, raise it with your engagement contact with the assessment reference to hand.
If this does not work
- A count that looks too low compared with a previous run under a different scope is usually a scope difference, not a regression — check the boundary first.
A finding looks wrong to your engineers
The finding is either corrected with a reason recorded, or confirmed with the evidence that supports it — either way the record is accurate.
- 1Do not dismiss it informally — open the finding and read the evidence panel with the engineer who disagrees.
- 2Follow "Review disputed findings with your engineers" above to apply a recorded correction.
- 3If the evidence itself looks wrong rather than the conclusion drawn from it, report it through /contact so we can check the detector.
If this does not work
- Remember the published accuracy figure: on a 42-asset estate at 95.2% accuracy, expect roughly two labels to need correcting. One disputed finding is expected, not alarming.
You suspect a security issue with the platform itself
A genuine security concern reaches the right people quickly, through a channel built for exactly that.
- 1Stop, and do not attempt to test or exploit the issue further against our production systems.
- 2Go to /security for our disclosure policy and the current channel for reporting a vulnerability.
- 3Do not send us key material, credentials or customer data as part of a report, even as evidence — describe it instead.
- 4If it is an active incident rather than a research finding, say so explicitly in your report.
Privacy and data requests
2 topicsRequest a copy of the data we hold on your workspace
You receive an export of the workspace data covered by your request, or a clear written explanation of why a specific item is withheld.
- 1Read "What we hold, and what we never take" first, so your request names what actually exists rather than what you assume exists.
- 2Send the request through /contact from a verified account holder or workspace owner address, naming the workspace and the scope of data you want.
- 3Expect a written acknowledgement before the export itself. [PLACEHOLDER: turnaround time for a data-access request]
If this does not work
- If the request comes from someone other than a workspace owner, expect us to verify authority first — that step protects your organisation as much as it slows the request.
Request deletion of your workspace data
Your workspace data is deleted according to our published retention rules, and you know what that does and does not cover.
- 1Read "Retention and deletion" first for what is deleted, what a backup cycle can delay, and what a legal hold can override.
- 2Send the deletion request through /contact from a verified workspace owner address, stating whether you mean one assessment, one workspace, or the full account.
- 3Ask for written confirmation once deletion completes, and keep it — it is your own record, independent of anything on our side.
If this does not work
- If you need deletion tied to cancelling a plan, say so explicitly in the same request — see "Change or cancel your plan" — since the two are handled together but are still separate commitments.
Support commitments
What we actually commit to, stated plainly.
No invented response-time numbers. Where a figure is genuinely unset, it is marked as a placeholder rather than implied.
What we do
- Answer scoping, access and account questions from a named person, in writing, through /contact.
- Investigate genuine security reports through the channel described at /security.
- Point you to the exact Knowledge Base article or method section that answers a technical question, rather than re-explaining it inline.
What we do not commit to (yet)
- Commit to a response-time SLA on this page. [PLACEHOLDER: response-time targets, if any, to be confirmed by the product team]
- Offer 24/7 phone support today. [PLACEHOLDER: support hours and phone availability]
- Run a chat widget or an AI assistant on this site or in the product — see below.
- Make configuration changes inside your estate on your behalf; remediation stays with your teams under your own change control.
Still stuck?
If none of the topics above match what you are seeing, tell a person the whole story at /contact — the assessment reference, the source you are trying to reach, and what you expected instead.