Skip to main content
This page summarizes the main entities visible in the product and API flows.

Core entities


Search and module states

Typical status flow:
  • pending
  • running
  • finished
  • error

Visibility rules

A field, tab, or panel is displayed only when all required conditions are met:
  1. The search type supports that view
  2. The plan allows the underlying data source
  3. Matching data is present in returned payloads
  4. The user has not disabled the view in display settings
Missing panel usually means no applicable data was returned, not a rendering issue.

Relationships in practice

One search execution yields multiple module outputs (stream events and/or stored cards).
One search can include cards plus optional leaked, breached, and registered account datasets in its stored result payload.
Teams group projects, and projects can reference saved searches, notes, and attachments.
One monitor can generate many alert records over time, each with its own workflow status.