Documentation

Managed SOC · Getting Started

Onboarding checklist

A step-by-step checklist to bring an environment fully under Managed SOC coverage, from access and telemetry to escalation and sign-off.

Use this checklist to track a new environment from kickoff to full coverage. Working it end to end is what turns a signed order into live 24×7 monitoring with SLA-backed escalation. Your onboarding engineer works it alongside you and marks each item complete in the Network Portal.

1. Access and contacts

  • Portal access granted to your admins (see Roles & permissions).
  • Primary and after-hours escalation contacts recorded.
  • Response authorizations agreed — what the SOC may do without asking (for example, isolate an endpoint) versus what needs approval.
  • Maintenance windows and change-freeze periods documented.

2. Telemetry

  • Identity provider connected (Entra ID / Okta / Google Workspace).
  • Endpoint/EDR telemetry flowing from every managed device.
  • Firewall and DNS logs forwarded.
  • Cloud audit logs (AWS/Azure/GCP) forwarded.
  • Critical SaaS apps (email, file storage) connected.

3. Detection and tuning

  • Data health green for all connected sources.
  • Test detection verified end to end.
  • Baseline tuning window scheduled (first ~2 weeks).
  • Known-good behaviors allow-listed to reduce noise.

4. Response readiness

  • Containment method confirmed for endpoints and identities.
  • Incident communication plan agreed (who we call, in what order).
  • Runbook for your top three risk scenarios reviewed.

5. Sign-off

  • Coverage map reviewed and accepted.
  • First monthly review scheduled.
  • Onboarding marked complete in the Portal.

Tip

Keep escalation contacts current. The single most common cause of slow response is an out-of-date after-hours phone number. Review them each quarter.

Need a hand with Managed SOC?Talk to our team →