Ship Safe field guide

From first scan to continuous protection.

Follow one practical workflow, then use the deeper guides when your team is ready for monitoring, PR checks, and AI agents.

Run your first scan →View the steps
Quick startAccountDashboardScanTake actionAutomationAgents
Six-step workflow

Your first secure baseline

Complete these in order. Each step leaves the workspace in a useful state, so you can stop and return later.

  1. 01

    Set up the account

    Choose an AI provider, connect GitHub, and select the alerts you need.

    Open workflow →
  2. 02

    Run the baseline

    Scan a repository with the recommended checks before changing advanced options.

    Open workflow →
  3. 03

    Triage the evidence

    Open critical and high findings, then acknowledge or dismiss each signal.

    Open workflow →
  4. 04

    Assign the work

    Copy the fix, create a GitHub issue, or send complex evidence to an agent.

    Open workflow →
  5. 05

    Verify the fix

    Rescan the same repository and only close findings after the evidence clears.

    Open workflow →
  6. 06

    Keep it protected

    Add monitoring, PR Guardian, and focused agents after the first baseline.

    Open workflow →
00 / Configure

Set up the account once.

Start with the integrations that unlock the workflow. You can add advanced alerts and CI access later.

  1. 01

    Confirm profile and plan

    Check the signed-in identity and which cloud features are available.

    Open setting →
  2. 02

    Choose an AI provider

    Select the model used for analysis and store its key securely.

    Open setting →
  3. 03

    Connect GitHub

    Add a token so Ship Safe can create issues from verified findings.

    Open setting →
  4. 04

    Set alerts and CI access

    Choose useful notifications and create an API key only when CI needs one.

    Open setting →
Profile, AI model, GitHub integration, and notification setup without exposing secret values.
Minimum useful setupAn AI provider is optional for core scanning. GitHub is only required for private repositories and issue creation.
01 / Orient

Read the workspace in under a minute.

The dashboard answers three questions first: what needs attention, whether risk is improving, and which repositories are protected.

  • Start with the recommended next step.
  • Use the severity chart to enter a focused findings queue.
  • Check repository posture before enabling automation.
Open dashboard →
Ship Safe dashboard showing priority findings and workspace posture
Security overview uses real scan, finding, repository, and agent data.
02 / Scan

Start with the recommended profile.

Choose the target and run the default checks before opening advanced settings. This gives you a consistent baseline that is easier to compare later.

Local-first optionnpx ship-safe audit .Use the CLI when source code must remain on the machine.
Create a scan →
Your browser does not support the Ship Safe repository scan walkthrough.
A real scan of OWASP NodeGoat, from GitHub URL to prioritized findings.
03 / Remediate

Move from signal to verified fix.

Filter first, inspect the evidence, apply the smallest safe change, and rescan before closing the finding.

PrioritizeInspect evidenceFixRescanClose
Open findings inbox →
04 / Act

Turn the finding into owned work.

Choose the lightest action that moves the risk forward. The scan remains the source of evidence; GitHub or an agent becomes the place where the work continues.

Expand a finding, preserve its triage state, and preview a GitHub issue before creating it.
01

Acknowledge

Use when the signal is valid and has been accepted into the team's work.

02

Copy the fix

Move the recommended remediation into the editor or the existing work item.

03

Create an issue

Send the evidence, location, rule, and fix to the repository with one confirmation.

04

Investigate

Use a deployed security agent when the evidence needs deeper analysis.

After the changeScan againCompare evidenceMark fixed
05 / Automate

Keep the baseline from drifting.

Repository monitoring watches the default branch. PR Guardian adds a security decision before risky code merges.

Move from a recurring repository schedule to controlled PR Guardian automation.
Manage repositories →Open PR Guardian →
06 / Extend

Add agent intelligence where it earns its place.

Use dedicated agents for recurring specialist work, then review their findings alongside repository scans instead of creating a separate security workflow.

Intelligence

Turn scan history into a security briefing.

Summarize patterns, changing risk, and the next actions worth taking.

Open intelligence →
Hermes agents

Deploy focused security roles.

Give each agent a clear objective, constrained tools, and a reviewable findings trail.

Set up Hermes →
Ready to begin

Run the baseline. Fix what matters. Keep it protected.

Start a scan →