docs: add UI Guide section mirroring CoPilot menu (#708)
Co-authored-by: Clawdbot <clawdbot@Clawdbots-Mac-mini.local>
taylorcopilot committed
Feb 14, 2026 at 21:26 UTC
2664506e132328828d00467c9a36dac9f23954fa
40 files changed
+387
docs/user/ui/README.md
new
+12
@@ -0,0 +1,12 @@
1
+# UI Guide (mirrors the CoPilot menu)
2
+
3
+This section is organized to match the left navigation in CoPilot.
4
+
5
+Use it when you know **where you are in the UI** and want to understand:
6
+- what the page is for
7
+- who it’s for (Operator vs Admin/Engineer)
8
+- common workflows and gotchas
9
+
10
+If you’re brand new, start with:
11
+- [Quickstart (Operators)](../operators-quickstart.md)
12
+- [Quickstart (Admins/Engineers)](../admins-quickstart.md)
docs/user/ui/agents-copilot-actions.md
new
+9
@@ -0,0 +1,9 @@
1
+# CoPilot Actions
2
+
3
+**Menu:** Agents → CoPilot Actions
4
+
5
+**Best for:** Admin/Engineer + Response engineering
6
+
7
+Configure or manage endpoint actions / response capabilities.
8
+
9
+
docs/user/ui/agents-detection-rules.md
new
+9
@@ -0,0 +1,9 @@
1
+# Detection Rules
2
+
3
+**Menu:** Agents → Detection Rules
4
+
5
+**Best for:** Detection engineering
6
+
7
+Edit and manage detection rules (Wazuh) through CoPilot.
8
+
9
+
docs/user/ui/agents-groups.md
new
+9
@@ -0,0 +1,9 @@
1
+# Agent Groups
2
+
3
+**Menu:** Agents → Groups
4
+
5
+**Best for:** Admin/Engineer
6
+
7
+Use groups to segment endpoints and attach customer labels used for routing.
8
+
9
+
docs/user/ui/agents-patch-tuesday.md
new
+9
@@ -0,0 +1,9 @@
1
+# Patch Tuesday
2
+
3
+**Menu:** Agents → Patch Tuesday
4
+
5
+**Best for:** Ops + reporting
6
+
7
+Patch-focused reporting/overview.
8
+
9
+
docs/user/ui/agents-sca-overview.md
new
+9
@@ -0,0 +1,9 @@
1
+# SCA Overview
2
+
3
+**Menu:** Agents → SCA Overview
4
+
5
+**Best for:** Ops + reporting
6
+
7
+Security Configuration Assessment overview.
8
+
9
+
docs/user/ui/agents-sysmon-config.md
new
+9
@@ -0,0 +1,9 @@
1
+# Sysmon Config
2
+
3
+**Menu:** Agents → Sysmon Config
4
+
5
+**Best for:** Admin/Engineer
6
+
7
+Manage Sysmon configuration in a repeatable way.
8
+
9
+
docs/user/ui/agents-vulnerability-overview.md
new
+9
@@ -0,0 +1,9 @@
1
+# Vulnerability Overview
2
+
3
+**Menu:** Agents → Vulnerability Overview
4
+
5
+**Best for:** Both (Ops + reporting)
6
+
7
+High-level view of vulnerabilities (often backed by Wazuh vulnerability detection data).
8
+
9
+
docs/user/ui/agents.md
new
+9
@@ -0,0 +1,9 @@
1
+# Agents
2
+
3
+**Menu:** Agents
4
+
5
+**Best for:** Admin/Engineer + Detection engineering
6
+
7
+Agent-related pages cover endpoint group configuration, Sysmon config, detection rules, and security posture views.
8
+
9
+
docs/user/ui/alerts-atomic-red-team.md
new
+9
@@ -0,0 +1,9 @@
1
+# Atomic Red Team
2
+
3
+**Menu:** Alerts → Atomic Red Team
4
+
5
+**Best for:** Detection engineering / validation
6
+
7
+Use Atomic Red Team workflows to test detections and confirm alert routing.
8
+
9
+
docs/user/ui/alerts-mitre.md
new
+9
@@ -0,0 +1,9 @@
1
+# MITRE ATT&CK
2
+
3
+**Menu:** Alerts → MITRE ATT&CK
4
+
5
+**Best for:** Detection engineering + reporting
6
+
7
+Use this view for ATT&CK alignment, coverage discussions, and investigation context.
8
+
9
+
docs/user/ui/alerts-siem.md
new
+9
@@ -0,0 +1,9 @@
1
+# SIEM
2
+
3
+**Menu:** Alerts → SIEM
4
+
5
+**Best for:** Both
6
+
7
+Use the SIEM view to search/pivot into surrounding events. This is often where you use `index_name` + `index_id` references.
8
+
9
+
docs/user/ui/alerts.md
new
+15
@@ -0,0 +1,15 @@
1
+# Alerts
2
+
3
+**Menu:** Alerts
4
+
5
+**Best for:** Admin/Engineer + Detection engineering + SOC leadership
6
+
7
+This section is oriented around SIEM views and testing/coverage (not the day-to-day triage queue).
8
+
9
+## Sub-pages
10
+
11
+- SIEM
12
+- MITRE ATT&CK
13
+- Atomic Red Team
14
+
15
+
docs/user/ui/artifacts.md
new
+9
@@ -0,0 +1,9 @@
1
+# Artifacts
2
+
3
+**Menu:** Artifacts
4
+
5
+**Best for:** SOC operators / analysts
6
+
7
+Artifacts are where you manage investigation files and evidence.
8
+
9
+
docs/user/ui/connectors.md
new
+9
@@ -0,0 +1,9 @@
1
+# Connectors
2
+
3
+**Menu:** Connectors
4
+
5
+**Best for:** Admin/Engineer
6
+
7
+Connectors are where you configure and verify connectivity to underlying tools.
8
+
9
+
docs/user/ui/customer-portal.md
new
+7
@@ -0,0 +1,7 @@
1
+# Customer Portal
2
+
3
+**Menu:** Customer Portal
4
+
5
+**Best for:** Admin/Engineer + customer-facing workflows
6
+
7
+
docs/user/ui/customers.md
new
+17
@@ -0,0 +1,17 @@
1
+# Customers
2
+
3
+**Menu:** Customers
4
+
5
+**Best for:** Admin/Engineer
6
+
7
+Customers represent tenants in CoPilot.
8
+
9
+Deep link tips:
10
+- `/customers?code=<customer_code>`
11
+- `/customers?action=add-customer`
12
+
13
+
14
+
15
+## Related
16
+
17
+- [Customer Provisioning (Tenancy)](../customer-provisioning.md)
docs/user/ui/external-network-connectors.md
new
+5
@@ -0,0 +1,5 @@
1
+# Network Connectors
2
+
3
+**Menu:** External Services → Network Connectors
4
+
5
+
docs/user/ui/external-services.md
new
+9
@@ -0,0 +1,9 @@
1
+# External Services
2
+
3
+**Menu:** External Services
4
+
5
+**Best for:** Admin/Engineer
6
+
7
+External Services covers third-party integrations, network connectors, and auth helpers.
8
+
9
+
docs/user/ui/external-singul-app-auth.md
new
+5
@@ -0,0 +1,5 @@
1
+# Singul App Auth
2
+
3
+**Menu:** External Services → Singul App Auth
4
+
5
+
docs/user/ui/external-third-party-integrations.md
new
+5
@@ -0,0 +1,5 @@
1
+# 3rd Party Integrations
2
+
3
+**Menu:** External Services → 3rd Party Integrations
4
+
5
+
docs/user/ui/graylog-management.md
new
+5
@@ -0,0 +1,5 @@
1
+# Graylog Management
2
+
3
+**Menu:** Graylog → Management
4
+
5
+
docs/user/ui/graylog-metrics.md
new
+5
@@ -0,0 +1,5 @@
1
+# Graylog Metrics
2
+
3
+**Menu:** Graylog → Metrics
4
+
5
+
docs/user/ui/graylog-pipelines.md
new
+5
@@ -0,0 +1,5 @@
1
+# Graylog Pipelines
2
+
3
+**Menu:** Graylog → Pipelines
4
+
5
+
docs/user/ui/graylog.md
new
+9
@@ -0,0 +1,9 @@
1
+# Graylog
2
+
3
+**Menu:** Graylog
4
+
5
+**Best for:** Admin/Engineer
6
+
7
+Graylog pages help you manage pipelines, metrics, and management screens.
8
+
9
+
docs/user/ui/healthcheck.md
new
+9
@@ -0,0 +1,9 @@
1
+# Healthcheck
2
+
3
+**Menu:** Healthcheck
4
+
5
+**Best for:** Both
6
+
7
+Healthcheck provides a high-level signal of platform/stack health.
8
+
9
+
docs/user/ui/incident-alerts.md
new
+11
@@ -0,0 +1,11 @@
1
+# Incident Alerts
2
+
3
+**Menu:** Incident Management → Alerts
4
+
5
+**Best for:** SOC operators / analysts
6
+
7
+This is your primary triage queue.
8
+
9
+Deep link tip: `/incident-management/alerts?alert_id=<id>`
10
+
11
+
docs/user/ui/incident-cases.md
new
+11
@@ -0,0 +1,11 @@
1
+# Incident Cases
2
+
3
+**Menu:** Incident Management → Cases
4
+
5
+**Best for:** SOC operators / analysts
6
+
7
+Cases track investigation lifecycle and allow you to link related alerts, comments, and artifacts.
8
+
9
+Deep link tip: `/incident-management/cases?case_id=<id>`
10
+
11
+
docs/user/ui/incident-management.md
new
+15
@@ -0,0 +1,15 @@
1
+# Incident Management
2
+
3
+**Menu:** Incident Management
4
+
5
+**Best for:** SOC operators / analysts
6
+
7
+Incident Management is where analysts spend most of their time.
8
+
9
+## Sub-pages
10
+
11
+- **Sources**: define/organize alert sources
12
+- **Alerts**: triage queue
13
+- **Cases**: investigation lifecycle
14
+
15
+
docs/user/ui/incident-sources.md
new
+9
@@ -0,0 +1,9 @@
1
+# Incident Sources
2
+
3
+**Menu:** Incident Management → Sources
4
+
5
+**Best for:** Admin/Engineer (setup) + Operator (awareness)
6
+
7
+Sources define how alerts are grouped and routed into Incident Management.
8
+
9
+
docs/user/ui/indices-management.md
new
+5
@@ -0,0 +1,5 @@
1
+# Index Management
2
+
3
+**Menu:** Indices → Index Management
4
+
5
+
docs/user/ui/indices-snapshots.md
new
+5
@@ -0,0 +1,5 @@
1
+# Snapshot & Restore
2
+
3
+**Menu:** Indices → Snapshot & Restore
4
+
5
+
docs/user/ui/indices.md
new
+9
@@ -0,0 +1,9 @@
1
+# Indices
2
+
3
+**Menu:** Indices
4
+
5
+**Best for:** Admin/Engineer
6
+
7
+Index Management is used to understand storage/retention, snapshots, and index health.
8
+
9
+
docs/user/ui/overview.md
new
+17
@@ -0,0 +1,17 @@
1
+# Overview
2
+
3
+**Menu:** Overview
4
+
5
+**Best for:** Both
6
+
7
+## What this page is
8
+
9
+The Overview dashboard is a high-level snapshot of your CoPilot environment: customers, alert/case counts, and key stack health signals.
10
+
11
+
12
+
13
+## Common workflows
14
+
15
+- Confirm the platform is healthy at a glance before starting triage.
16
+- Jump into Incident Management for alerts/cases.
17
+- Use health/usage widgets to spot issues (for example: storage pressure, connector errors).
docs/user/ui/report-creation.md
new
+9
@@ -0,0 +1,9 @@
1
+# Report Creation
2
+
3
+**Menu:** Report Creation
4
+
5
+**Best for:** Admin/Engineer + SOC leadership
6
+
7
+Report Creation is where you generate PDF/report outputs (Grafana dashboards and security reporting).
8
+
9
+
docs/user/ui/report-general.md
new
+5
@@ -0,0 +1,5 @@
1
+# General Reports
2
+
3
+**Menu:** Report Creation → General Reports
4
+
5
+
docs/user/ui/report-sca.md
new
+5
@@ -0,0 +1,5 @@
1
+# SCA Reports
2
+
3
+**Menu:** Report Creation → SCA Reports
4
+
5
+
docs/user/ui/report-vulnerability.md
new
+5
@@ -0,0 +1,5 @@
1
+# Vulnerability Reports
2
+
3
+**Menu:** Report Creation → Vulnerability Reports
4
+
5
+
docs/user/ui/scheduler.md
new
+9
@@ -0,0 +1,9 @@
1
+# Scheduler
2
+
3
+**Menu:** Scheduler
4
+
5
+**Best for:** Admin/Engineer
6
+
7
+Scheduler controls background jobs/collectors.
8
+
9
+
mkdocs.yml
+47
@@ -78,6 +78,53 @@ nav:
78
- Customer Provisioning (Tenancy): user/customer-provisioning.md
79
- Features by Area: user/features.md
80
- Navigation Guide (UI): user/navigation.md
81
+ - UI Guide (mirrors menu):
82
+ - Start here: user/ui/README.md
83
+ - Overview: user/ui/overview.md
84
+ - Incident Management:
85
+ - Incident Management: user/ui/incident-management.md
86
+ - Sources: user/ui/incident-sources.md
87
+ - Alerts: user/ui/incident-alerts.md
88
+ - Cases: user/ui/incident-cases.md
89
+ - Alerts:
90
+ - Alerts: user/ui/alerts.md
91
+ - SIEM: user/ui/alerts-siem.md
92
+ - MITRE ATT&CK: user/ui/alerts-mitre.md
93
+ - Atomic Red Team: user/ui/alerts-atomic-red-team.md
94
+ - Artifacts: user/ui/artifacts.md
95
+ - Customers: user/ui/customers.md
96
+ - Agents:
97
+ - Agents: user/ui/agents.md
98
+ - Groups: user/ui/agents-groups.md
99
+ - Sysmon Config: user/ui/agents-sysmon-config.md
100
+ - Detection Rules: user/ui/agents-detection-rules.md
101
+ - CoPilot Actions: user/ui/agents-copilot-actions.md
102
+ - Vulnerability Overview: user/ui/agents-vulnerability-overview.md
103
+ - Patch Tuesday: user/ui/agents-patch-tuesday.md
104
+ - SCA Overview: user/ui/agents-sca-overview.md
105
+ - Report Creation:
106
+ - Report Creation: user/ui/report-creation.md
107
+ - General Reports: user/ui/report-general.md
108
+ - Vulnerability Reports: user/ui/report-vulnerability.md
109
+ - SCA Reports: user/ui/report-sca.md
110
+ - Healthcheck: user/ui/healthcheck.md
111
+ - Indices:
112
+ - Indices: user/ui/indices.md
113
+ - Index Management: user/ui/indices-management.md
114
+ - Snapshot & Restore: user/ui/indices-snapshots.md
115
+ - Graylog:
116
+ - Graylog: user/ui/graylog.md
117
+ - Management: user/ui/graylog-management.md
118
+ - Metrics: user/ui/graylog-metrics.md
119
+ - Pipelines: user/ui/graylog-pipelines.md
120
+ - Connectors: user/ui/connectors.md
121
+ - External Services:
122
+ - External Services: user/ui/external-services.md
123
+ - 3rd Party Integrations: user/ui/external-third-party-integrations.md
124
+ - Network Connectors: user/ui/external-network-connectors.md
125
+ - Singul App Auth: user/ui/external-singul-app-auth.md
126
+ - Scheduler: user/ui/scheduler.md
127
+ - Customer Portal: user/ui/customer-portal.md
128
- Videos (Playlist): user/videos.md
129
- Developer / AI Agent Docs:
130
- Start Here: developer/start-here.md