Dashboard
The server serves the dashboard over HTTPS with sign-in; local mode serves the same dashboard on 127.0.0.1 without sign-in. The CLI and the dashboard share the same data.
Pages
- Hosts: every machine, its latest results per check and a severity overview. Hosts can be added, removed and scanned here.
- Host page: per-check results, full scan reports with search and filters, and the scan history.
- Vulnerabilities: each vulnerability and the hosts it affects.
- Agents (server only): enrolled agents, their status, and enrollment tokens.
- Audit log (server only): sign-ins, tokens, enrollments, scans and removals.
Live scans
While a scan runs, the host's page shows a live console: each step, every fixed command DeaconGuard runs (marked when it goes through sudo), how long each took, and findings as each check completes. It never shows command output or credentials.
Each scan's activity log is saved with its results, so View logs in the scan history replays it later.
History
Scan history keeps the 10 most recent scans per host, plus any older scan that still holds a check's latest result. Each scan can be deleted.
Sudo passwords
When a check needs sudo and sudo asks for a password, the scan pauses and the browser asks for it. The answer goes to that one scan, is kept in memory only, and is never saved or logged. A wrong password can be retried up to three times. Closing the dialog continues the scan without sudo; an unanswered question stops the scan after 10 minutes.