| Manage an OEM scan | Queue scan → poll scan status → query indexed results | Target, type, scan_id, latest state, completion time | OEM Scan Lifecycle |
| Onboard an Enterprise tenant | Create organization → register scope → collect baseline | Tenant mapping, organization ID, assets, initial counts | Enterprise and MSSP Onboarding |
| Send alerts to tickets | Enterprise alerts → normalize → deliver → checkpoint | Organization, alert ID, idempotency key, receiver outcome | Alert-to-Ticket Delivery |
| Respond to credential exposure | Compromised credentials → discovered emails → identity response | Reduced record ID, breach context, owner, action | Credential Response |
| Monitor certificates | Entities → assets → certificate objects | Fingerprint, issuer, names, expiry, last seen | Certificate Monitoring |
| Investigate past exposure | Current domain → historical hosts → passive DNS → certificates | Case ID, raw evidence, normalized timeline | Historical Exposure |
| Verify deployment exposure | OEM host scan → scan status → fresh host details | Completed scan, evidence time, expected and prohibited ports | Post-Deployment Verification |
| Monitor package advisories | OEM advisory feed → alias deduplication → version matching | Package, source ID, aliases, ranges, cutoff | Package Monitoring |
| Verify decommissioning | Before-state → OEM scan → current and historical evidence | Baseline, scan state, residuals, reviewer decision | Cloud Decommissioning |
| Assess M&A exposure | Organization search → domain collection → ownership review → passive enrichment | Candidate source, relationship state, verified evidence | M&A Assessment |