Skip to main content

Quickstart Guide

Welcome to Bastion

This guide walks you through the essential setup steps. Your dedicated vCISO is available over Slack to help at every step.

Home
Compliance
SOC 2 Type II
92%
ISO 27001
78%
Monitoring
Devices
24
18 compliant
Employees
42
89% trained
Infrastructure
11
open issues
Code
12
repos scanned

Step 1: Access Your Workspace

  1. Sign In

    Navigate to app.bastion.tech and sign in with your credentials. If you don't have an account, contact your administrator or request a demo.

  2. Explore the Dashboard

    The home dashboard provides an overview of your compliance status and active security monitoring. Use the sidebar to navigate between modules.

Step 2: Set Up Integrations

Integrations are the foundation of Bastion's automation. Connect your existing tools to enable automatic data collection and policy enforcement.

Identity Provider

Connect your identity provider to automatically import and sync employees:

  • Azure Active Directory - Microsoft 365 environments
  • Google Workspace - Google-based organizations

For other identity providers, use the manual user import (CSV).

Navigate to Integrations → Select your provider → Follow the OAuth flow.

Cloud Services

Connect cloud providers for infrastructure monitoring and compliance evidence:

  • AWS - Deploy CloudFormation template for read-only access
  • Azure - Register app in Entra ID with Reader role
  • GCP - Set up Workload Identity Federation
  • OVH - Create API token with read-only permissions
  • Scaleway - Create application with AllProductsReadOnly policy
  • Digital Ocean - Authorize via OAuth with read-only scope

Navigate to IntegrationsCloud Services → Select your provider.

Version Control

Connect your code repositories for code security:

  • GitHub - Install the Bastion - Compliance GitHub App
  • GitLab - Authorize the Bastion Technologies OAuth app
  • Azure DevOps - Register Entra app with Project Reader role
  • Bitbucket - Authorize the Bastion Technologies OAuth app

Navigate to InfrastructureCode Security → Connect VCS.

Step 3: Manage Employees

Once your identity provider is connected, users are automatically imported. You can then activate or deactivate them:

  1. Navigate to EmployeesPeople
  2. Review the list of imported users
  3. Activate users who are employees in your organization
  4. Deactivate users who are not employees
tip

Create Compliance Groups to organize employees by department, location, or role. Groups make it easy to assign training and manage access reviews.

Step 4: Choose Your Modules

Every module is included in your subscription — enable only what you need:

ModuleUse Case
CompliancePursuing certifications (SOC 2, ISO 27001, etc.)
Customer TrustResponding to customer security questionnaires
Awareness TrainingSecurity education for employees
Phishing CampaignsTest employee phishing awareness
DevicesMDM and endpoint management
Web BrowsingDNS filtering and browser security
InfrastructureAttack surface monitoring
Code SecuritySBOM and dependency scanning

Step 5: Configure Your First Module

  1. Go to ComplianceFrameworks
  2. Select a framework (e.g., SOC 2 Type II)
  3. Review the controls and requirements
  4. Connect integrations to auto-collect evidence
  5. Start working through the control tests

Keyboard Shortcuts

Speed up your workflow with keyboard shortcuts:

ShortcutAction
HGo to Home
IGo to Integrations
CGo to Compliance
TGo to Customer Trust
EGo to Employees
AGo to SaaS
DGo to Devices
SGo to Infrastructure
KOpen Command Menu (search)

Next Steps