Use this checklist to track a new environment from kickoff to full coverage. Working it end to end is what turns a signed order into live 24×7 monitoring with SLA-backed escalation. Your onboarding engineer works it alongside you and marks each item complete in the Network Portal.
1. Access and contacts
- Portal access granted to your admins (see Roles & permissions).
- Primary and after-hours escalation contacts recorded.
- Response authorizations agreed — what the SOC may do without asking (for example, isolate an endpoint) versus what needs approval.
- Maintenance windows and change-freeze periods documented.
2. Telemetry
- Identity provider connected (Entra ID / Okta / Google Workspace).
- Endpoint/EDR telemetry flowing from every managed device.
- Firewall and DNS logs forwarded.
- Cloud audit logs (AWS/Azure/GCP) forwarded.
- Critical SaaS apps (email, file storage) connected.
3. Detection and tuning
- Data health green for all connected sources.
- Test detection verified end to end.
- Baseline tuning window scheduled (first ~2 weeks).
- Known-good behaviors allow-listed to reduce noise.
4. Response readiness
- Containment method confirmed for endpoints and identities.
- Incident communication plan agreed (who we call, in what order).
- Runbook for your top three risk scenarios reviewed.
5. Sign-off
- Coverage map reviewed and accepted.
- First monthly review scheduled.
- Onboarding marked complete in the Portal.
Tip
Keep escalation contacts current. The single most common cause of slow response is an out-of-date after-hours phone number. Review them each quarter.
