VectorVue Operator Manual
This manual is for delivery teams running security validation operations in VectorVue.
1. Operating Model
VectorVue workflow for operators:
- Prepare campaign scope and rules of engagement
- Execute and record activity evidence
- Track findings and remediation
- Validate defensive effectiveness through analytics
- Deliver auditor-ready evidence and reports
2. Access and Roles
Minimum role guidance:
- Viewer: read-only access
- Operator: create and update operational records
- Lead: approvals and team coordination
- Admin: platform administration and user management
2.1 Guided Onboarding Paths
Use guided workflows to reduce operator error during setup:
- CLI guided wizard:
make wizard
- TUI guided onboarding (admin):
make run-tui- open with
Ctrl+Shift+Wor sidebarONBOARD WIZARD
- Use the wizard to set:
- tenant id/name
- portal host and company branding
- tenant admin and client credentials
3. Daily Operator Procedure
3.1 Start-of-Day Checks
- Confirm platform health:
make api-smoke
- Confirm active campaign and tenant context.
- Confirm evidence and reporting storage are available.
3.2 Campaign Execution
- Open active campaign context.
- Register operational events and observations.
- Maintain finding records with severity and technical details.
- Attach supporting evidence for each significant finding.
3.3 Detection and Response Tracking
- Review detections and timeline indicators.
- Mark remediation progress where applicable.
- Escalate critical findings to lead for formal approval.
3.4 End-of-Day Closure
- Verify no orphan findings remain without severity.
- Verify critical findings have evidence and remediation owner.
- Review analytics summary for posture shifts.
- Prepare report artifacts for stakeholder review.
4. Quality Standards
Use these standards for commercial delivery:
- Every critical finding must include reproducible evidence.
- Every remediation task must have owner and status.
- Every report should map to current campaign window.
- All tenant data must remain isolated and scoped.
5. Multi-Tenant Safety Rules
- Never process or export data across tenants.
- Always confirm tenant identity before running bulk exports.
- Use tenant-scoped credentials and API tokens only.
6. Compliance-Aware Operations
Operator actions directly feed compliance evidence generation.
To maintain auditor-grade quality:
- Keep timestamps and object references accurate.
- Avoid manual edits to immutable evidence datasets.
- Ensure findings and remediation states are updated promptly.
7. Recommended Demo Walkthrough
- Overview: current campaign and risk posture
- Findings: focus critical/high severity
- Remediation: verify accountability and progress
- Reports: export executive artifacts
- Compliance APIs: show signed framework report response
8. Incident and Escalation Guidance
Escalate to lead/admin when:
- unauthorized access is suspected
- tenant data scope appears inconsistent
- evidence integrity checks fail
- API responses show signature or hash mismatch