Run the first scan

Start the first authorized scanner run and understand queued, running, blocked and completed scan states.

First-time customers and technical reviewers

Feature availability

Product, package, provider and deployment boundaries for this page.

Available from
Current documentation
Deployment modes
cloud

Product screenshots

Current customer-safe screenshots are generated from the application so examples do not drift from the product.

Generated customer-safe screenshot of the WebRiskOps project scan start action.
Generated customer-safe screenshot of the WebRiskOps project scan start action.

Before you start

The first scan turns the reviewed project pages into evidence for reports and fixes. Use this page after the project exists, domain ownership is handled when required, Project Pages looks correct and Billing shows enough credits or an active plan. Do not start duplicate scans to speed up the result. A queued or running scan already owns the worker slot for that project.

Start the scan

Follow the path `Projects → Project detail → Actions → Run whole scan → Scan results`.

  1. Open `/projects` and choose the project. Result: the project detail page shows Project Pages, Scans and Actions.
  2. Confirm Project Pages looks right. Result: the scan starts from known public pages on the project domain.
  3. In Actions, click Run whole scan once. Result: WebRiskOps creates a queued scan run and sends scanner work to the queue.
  4. Open `/scans` or the project's Scan history. Result: Scan results shows queued, running, completed and failed runs.
  5. Open the newest scan with Open scan. Result: scan detail shows status, evidence boundary, findings and export actions.
  6. When status becomes Completed, open the report artifact from the scan or `/reports`. Result: the first report can use collected screenshots, HTML snapshots and issue evidence.

Watch scan state

Queued means the scan request was accepted and is waiting for the worker. Running means the browser worker is collecting page evidence. Completed means the run has terminal evidence for report generation. Blocked or Failed means the page-specific reason must be fixed before retrying. Partial evidence can still be useful. If one project page fails but other pages load, read the scan coverage notes and artifact summary before deciding whether to retry or continue to the report.

Continue to the first report

When the scan reaches Completed, continue to [Read your first report](/docs/getting-started/read-first-report). The next page explains how to open the private report, review issue evidence and choose the next action.

Blocked states

  • Scan run blocked means one of the required gates is missing, such as authorization, plan state, project page readiness or scanner safety.
  • Domain authorization required means ownership proof is missing. Complete the project page challenge before retrying the scan.
  • Scan run failed means the run could not collect enough evidence. Use the failure reason and retry only after the target is reachable and the project boundary is still correct.
  • Queued means the request is accepted but not running yet. Wait rather than starting duplicate scans.
  • Completed means evidence is ready for report generation or review.
  • Active scan means another queued or running scan already exists for this project. Open that scan instead of creating a duplicate run.

Related documentation

Was this page helpful?

Feedback goes into the product documentation review queue.