Welcome to Navigator

Navigator is a Cyber Asset Attack Surface Management (CAASM) platform. It connects to the security and IT tools you already run, including vulnerability scanners, endpoint protection, mobile device management, identity providers, and CMDBs, and merges what they each report into one consolidated, deduplicated view of your devices, users, vulnerabilities, and software.

If you’ve used a CAASM platform before (Sevco, Axonius, or similar), the core idea will be familiar: no single tool in your environment has the complete picture. Your MDM knows about managed laptops but not what’s actually vulnerable on them. Your vulnerability scanner sees open ports but doesn’t know who’s logged into the machine. Navigator’s job is to reconcile all of that into one place, so “how many devices do we have, and how well are they covered?” has one clear, correct answer instead of five different partial ones.

Core concepts

Before diving into the Quick Start, it helps to understand three ideas that show up throughout Navigator:

Connectors

A connector is how Navigator talks to one of your existing tools, such as Tenable, Microsoft Defender, or Okta. Each connector knows how to fetch that tool’s own data (its devices, users, vulnerabilities, or software, depending on what the tool tracks) and hand it to Navigator in a common shape. Connecting a new tool never requires anything from the tool’s side beyond credentials you provide; Navigator does the polling.

See Connectors for the full list of what’s supported today and how to set each one up.

Consensus assets

Multiple connectors will often report on the same real-world device or person, such as a laptop that shows up in both your MDM and your EDR. Navigator automatically matches these records together into a single consensus asset, using strong identity signals (like a device’s directory ID) when available, and falling back to things like hostname, serial number, or MAC address when it isn’t.

Every consensus asset keeps track of exactly which of your connected tools reported it and what each one said. If two sources disagree about a field (say, the OS version), you can see both values and which source is currently “winning,” not just a silently merged answer.

Tenants

A tenant is your organization’s private workspace within Navigator: every connector, asset, and user you add belongs only to it. It’s a boundary Navigator enforces at the product level, not a specific database or server, so don’t read anything technical into the word beyond “this is where your data lives, and no one outside your organization can see into it.”

If you’re part of an MSSP or manage several distinct business units, each one gets its own separate tenant with its own separate sign-up. There’s no single login that spans more than one tenant today, so each is set up and accessed independently, just as separate from each other as from any unrelated Navigator customer.

What Navigator tracks today

Asset typeWhat it covers
DevicesLaptops, servers, and other endpoints: hardware specs, OS details, encryption status, agent/EDR coverage, IP addresses, and more
UsersDirectory accounts: MFA enrollment, admin status, and which devices they’re associated with
VulnerabilitiesFindings from your vulnerability scanners and EDR tools, enriched with CVSS, EPSS exploitation-probability scores, and CISA/VulnCheck Known Exploited Vulnerabilities (KEV) data
SoftwareInstalled software inventory per device

What’s next

  • New to Navigator? Start with the Quick Start. You’ll connect your first tool and see real data in a few minutes.
  • Wondering why you’d buy this instead of building it yourself? See Why Navigator.
  • Want a tour of what each page in the product does? See Using Navigator.
  • Ready to connect a specific tool? Jump straight to Connectors.

Getting help

If anything here doesn’t match what you’re seeing in the product, or you run into an issue setting up a connector, reach out to support@chartingcyber.com.

This documentation is a work in progress

Navigator is under active development. Some pages described in this guide are early/preview functionality; those are called out explicitly wherever that’s the case, matching the “Coming soon” notices you’ll see in the product itself. Nothing here should be read as a claim beyond what the product genuinely does today.