Skip to main content

Sign in

Pharos has no accounts of its own. Sign-in is Wazuh ID, the identity service shared by every Wazuh Labs service: one account, one login, valid across the whole ecosystem. The console at pharos.wazuh.com hands the browser to Wazuh ID and receives it back signed in. There is no separate Pharos password to create or to forget, and account security, multi-factor authentication included, is managed in Wazuh ID rather than in Pharos.

One organisation, one workspace​

An organisation is the group of members a company shares in Wazuh ID. A workspace is that organisation's private slice of Pharos: its managers, its signals, its watchlists, its settings and its bill. Each organisation maps to exactly one workspace, and every member lands in the same workspace, whether they sign in at the console or arrive through the Hub.

The Hub at hub.wazuh.com is the front door of the Labs ecosystem, where an organisation activates services and manages its account. Activating Pharos there links the organisation to the same workspace that signing in directly would reach.

Who can get in​

A Wazuh ID account is necessary and not sufficient. Pharos is in closed beta, and the console lets a person in only when two things are true of them in the Hub:

  • the organisation has Pharos enabled. Until it does, signing in ends on a page that says Pharos is not enabled for the organisation yet.
  • the person has been given Pharos. An owner or a billing admin of the organisation grants it on the Hub's Members page. A member without the grant sees a page saying so and naming who can add them.

Neither refusal is an error, and neither creates anything: the console reports the reason and waits. Fixing it in the Hub and signing in again is the whole recovery.

The first sign-in​

The workspace is created at the first sign-in and never before. The first member into a workspace becomes its admin: the one who adds managers, sets the monthly limit and invites the team. Everyone after that joins the same workspace as a plain user, automatically. An admin can also invite people from the Team page, as a user or as another admin.

Activation from the Hub follows the same rule. Activating Pharos for a person who has never signed in creates nothing. The Hub asks that they sign in once with their Wazuh account first, then activate again.