LúminaKite

Getting started and navigation

Document: LK-MAN-EN-01 · Version: 0.1
Last updated: 2026-07-18 · Status: draft / requires product review
Audience: all users · Plan: all plans

Screenshots use a synthetic organization and identities. Actual availability depends on the active organization's plan, role, and configuration.

Contents

  1. Purpose and scope
  2. Accessing the platform
  3. Active organization
  4. Overview
  5. Main navigation
  6. Recommended workflow
  7. Personal preferences
  8. Good practices
  9. Related references

<a id="purpose-and-scope"></a>

1. Purpose and scope

This manual explains how to sign in, select the working context, read the initial summary, and navigate every LúminaKite area. Detailed monitoring and administration procedures are covered in manuals 02 and 03.

LúminaKite organizes information by organization. Domains, findings, evidence, cases, monitors, and integrations are associated with that context; always check the active organization before creating or changing information.

<a id="accessing-the-platform"></a>

2. Accessing the platform

2.1 Sign in

  1. Open the URL supplied by your organization.
  2. Enter your email and password.
  3. Complete the second factor when MFA is enabled.
  4. Confirm that the active organization name is correct.

The platform also supports account activation, recovery, and password reset. Never share passwords, MFA or backup codes, tokens, or API keys.

2.2 Access controls

  • Authentication protects private views and APIs.
  • Authorization combines the user's role and organization context.
  • Sessions and credentials are personal; do not use shared accounts.
  • If exposure is suspected, change the password, revoke affected credentials, and notify the internal owner.

<a id="active-organization"></a>

3. Active organization

The organization selector appears in the header when the account can access more than one. Changing it updates the data and permission context.

Before operating:

  1. Check the organization's name and plan.
  2. Confirm your role: Member, Admin, or Owner.
  3. Review limits and capabilities under Billing if a function is missing or locked.

Multi-organization support is included by default from Pro. An invitation must be accepted before access becomes available.

<a id="overview"></a>

4. Overview

Business organization overview with synthetic data

Figure 1. Posture, plan, and limit summary for the active organization. Captured: 2026-07-18.

Overview gathers indicators used to prioritize work:

  • posture or risk score and trends;
  • monitored assets and domains;
  • findings and alerts by severity or state;
  • open cases and recent activity;
  • DNS/email, ASM, and uptime status;
  • current plan, enabled capabilities, and limit consumption.

An aggregate indicator supports prioritization but does not replace evidence review. Open the associated domain, finding, or case before making a decision.

<a id="main-navigation"></a>

5. Main navigation

AreaPurposeDefault minimum plan
OverviewPosture and activity summaryAll
My domainsAdd, verify, inventory, and inspect domainsAll
AlertsUnified events requiring attentionAll
CasesRemediation trackingAll
BrandBrand protection and related findingsBusiness
FindingsNormalized risk and evidenceAll
DNS & EmailDNS, SPF, DKIM, and DMARC postureBasic: all; full: Pro; RUA: Business
UptimeMonitors, regions, maintenance, and public pagesBasic: all; advanced: Pro
ASMAttack surface discovery and assessmentNormal: all; Plus: Business
ReportsExecutive and technical reportsPro
Identity LeaksAssets, providers, and identity exposurePro
OrganizationMembers, invitations, roles, keys, and auditRole-based; multi-org from Pro
BillingPlan, capabilities, limits, payments, and invoicesOwner
ProfileAccount, security, preferences, and privacyAll

Depending on version and screen width, the header may also offer search, theme selection, full screen, notifications, or the account menu.

<a id="recommended-workflow"></a>

Select organization → review Overview → prioritize alert/finding
→ validate evidence → open or update case → remediate
→ request recheck → confirm closure → document or report
  1. Start with severity, exposure, and asset criticality.
  2. Validate evidence and scope before escalation.
  3. Use a case whenever the work needs an owner, state, or traceability.
  4. Record risk acceptance only with authorization and a review date.
  5. Run a recheck after applying the correction.
  6. Generate a report when the state must be communicated outside daily operations.

<a id="personal-preferences"></a>

7. Personal preferences

Under Profile, each user may manage, subject to availability:

  • name and profile image;
  • English or Spanish language;
  • time zone and date/time formats;
  • password and MFA;
  • optional consents kept separate from necessary service functions;
  • personal-data export, correction request, and account closure.

Language changes should be reflected across the interface. Report any text unavailable in both English and Spanish.

<a id="good-practices"></a>

8. Good practices

  • Monitor only assets that you own or are expressly authorized to assess.
  • Do not copy secrets, credentials, or sensitive evidence into comments or free-text fields.
  • Use cases and states to preserve decision traceability.
  • Apply least privilege to roles and API keys.
  • Periodically review members, pending invitations, integrations, and alert channels.
  • Treat links to unpublished status pages as internal information.
  • Sign out on shared devices and keep the browser current.

<a id="related-references"></a>


Change control: v0.1 — initial creation, 2026-07-18.