Documentation
Operate Watchpost deliberately
These guides explain the current development candidate through small operational examples—from compiling the binary and enrolling a post to evidence-grounded investigation, typed actions, SNMP devices, incidents, security, and recovery boundaries.
How to use these docs
Start with Getting started, Core concepts, and the Posts page. Collection explains checks, push observations, SNMP, and logs. The remaining guides follow the operational path from deterministic evidence to alerts, incidents, investigation, controlled actions, deployment, and retention.
Getting startedCompile and run Watchpost, create the administrator, and monitor a first endpoint.Core conceptsPosts, collectors, signals, evidence, alerts, incidents, fleets, and actions with examples.PostsThe central monitored object: what a post is, its kinds, monitoring methods, lifecycle, and health.Agent architectureInstalling and pairing the separate Watchpost Agent, outbound delivery, queueing, and local management.CollectionImmediate checks, push observations, guided SNMPv3 polling, logs, quality, and device scope.Rules and alertsThreshold examples, freshness, acknowledgement, notification routes, and incident escalation.IncidentsOpen and document durable episodes with evidence, useful notes, transitions, and resolution.InvestigationSelect exact evidence, ask bounded questions, navigate verified citations, and preserve uncertainty.DeploymentBare binary startup, loopback binding, service accounts, reverse proxies, backups, and upgrades.Security modelAuthentication, sessions, bootstrap tokens, proxy trust, audit ordering, and safe failures.Verification & hardeningWhat has been exercised and what has not been proven, with the boundary of every gate.Data and retentionStored records, provenance, bounds, example retention planning, SQLite recovery, and exports.
No public release or production-readiness claim is made yet. See the roadmap for implemented checkpoints and remaining release evidence.