Sign in and start your workspace
Umbra has no password of its own. The console at umbra.wazuh.com offers one way in, a Wazuh ID account, and the first person from an organization to sign in creates the workspace the rest of that organization then joins.
Wazuh ID, the one account
Wazuh ID is the account every Wazuh service shares. It lives at id.wazuh.com, and it is where credentials are entered and where a new account is created. Umbra never sees a password.
- Open umbra.wazuh.com. The sign-in screen carries a single button, Sign in with Wazuh ID.
- Authenticate at Wazuh ID.
- The browser returns to the console, which opens on Overview.
A browser that still holds a live Wazuh ID session skips the second step entirely. Signing in to another Wazuh service earlier is enough, and the hop through Wazuh ID is then silent.
The first sign-in from an organization
A person who signs in with no Umbra workspace behind their address gets one card, Welcome to Umbra, which names the address and offers Start here. That button creates the workspace and loads the console on the Overview.
Umbra is in closed beta, so an organization has to be enabled for it before a workspace can be created. When it is not, Start here answers with a message saying Umbra is not enabled for that organization yet, and that a workspace can be started once the Wazuh team grants the organization access. The card stays as it is, and the button can be used again later.
One workspace for the whole organization
Every account belongs to exactly one organization, and an organization gets one Umbra workspace. Everyone in it sees the same monitored domains, the same exposures and the same alerts, so an investigation one person starts is visible to the next.
Roles follow from the order people arrive. The first person to sign in administers the workspace. Anyone from the same organization who signs in afterwards joins that workspace as a regular user, and a person who arrives through an invitation joins with the role the invitation gave them. Only an admin can change a role later. See Team and roles.
The work email domain is monitored from the start
The domain of the address used to sign in is authorized for the workspace with no setup step, and Umbra registers it for monitoring on its own. The first exposures therefore start loading without anyone adding a domain.
A mailbox at a consumer, ISP or throwaway email provider is the exception. Holding one proves nothing about who owns that provider's domain, so it authorizes no domain at all and an account in that position starts with nothing monitored. Every other domain has to be proven before it can be watched. See monitored domains.
The beta bar on every screen
A bar sits across the top of every screen inside the console. Its one line reads "Umbra is in beta. Nothing is billed without human review, and we ship updates every day." Hovering or focusing it opens the full notice, which commits to four things.
- Work in progress. Pricing, findings and monitoring coverage will change as the service is built, and feedback on what is missing or wrong is welcome.
- A person reviews every bill. Prices and usage metering are real, but someone at Wazuh reviews each invoice before any card is charged.
- Expect changes. Changes ship to production every day, so a screen or a workflow can differ between visits.
- Go easy on the load. Capacity is still being sized, so use the platform as much as needed but do not stress-test it.
The bar cannot be dismissed.
Moving between services
The icon bar down the left of the console is the rail. Each icon is a Wazuh service, in one order that never changes, with Umbra's own tile marked as the current one. The top button opens the Wazuh Hub, the front door to the ecosystem. A tile below the services opens this documentation. Every one of them navigates in the same tab and carries the Wazuh ID session along, so switching service is not a second sign-in. The rail is on the sign-in screen too, before any account is involved.
Signing out
Sign out sits in the profile menu at the top right. It ends the Umbra session and the Wazuh ID session behind it, so the next sign-in asks for credentials again instead of returning to the previous account.