Wegweiser
All notes

New scanner checks run on trial before you see them

Checks taken from the community rule sets now run on trial: what they find stays out of your Detections, health scores and bill until they have run clean for 14 days. You can ignore a single rule, for all your clients or one; a client's page lists the machines its VSA knows and no Wegweiser agent reports; and the Security briefing opens on what needs you now.

Every scanner check Wegweiser takes from a community rule set now starts on trial. It runs in the deep sweep on every machine, yours included, and what it finds is recorded for us to judge the check by. It stays out of your Detections, your health scores, your tickets and your bill.

A check comes off trial after 14 days with nothing against it, and only once a deep scan has finished on half the machines of its own platform, between 3 and 20 of them. At most 200 go live in a day. The checks we curate ourselves start live, as before.

What counts against a check: a match on a file NIST lists as ordinary software, matches on different files across three machines, 20 files on one machine, or a match on a file we ship, which fires on every machine that keeps a copy. Rules for remote access and hacking tools are exempt from the middle two, since finding the same tool on many machines is what they're for.

56 rules raised 99 percent of the warnings

We measured the daily sweep over 15 days: 4.1 million warnings, and 99 percent of them came from 56 generic community helpers.

A live rule matching a quarter of the machines of its own platform, at least five of them, now comes out of the daily scan. On a copy of production that's 57 rules.

A rule that matches a file we ship comes out too, whatever it looks for. Running production's pack over our own agent and the engines it carries matched 76 rules, 29 of them live.

Software Watch > What we look for says how many checks in each family are on trial. Its deep sweep line counts machines whose deep scan finished; it had counted the ones a scan was sent to.

Ignore a rule that finds your own tools

The remote access rules match your own RMM agent on every machine you manage. They're also what you want when you take over a client and go looking for the last provider's leftovers, so the decision is yours, one rule at a time.

Ignore this rule on a Detections entry opens the rule: its family, where it came from, what it looks for, and, for the public community sets, the rule text itself. It asks whether this is for all your clients or one, and for a reason. Masters and admins only.

Its matches are taken out as scans arrive, so Detections, health scores, tickets, the chat and your reports don't see them. The history from before leaves Detections, and the machines it scored are scored again.

Rules you ignore on What we look for lists each one with who ignored it, when, why, and how many matches it has held back, and Stop ignoring undoes it for new scans.

What you ignore is yours. It isn't a verdict that the rule is wrong, and it counts for nothing in the check across tenants that retires a rule for everybody.

Your client pages list what VSA knows and we don't

On a client linked to its VSA organisation, the Estate chapter gains Outside Wegweiser's view: the machines VSA knows there that no Wegweiser agent reports, most recently seen first, each with its VSA notifications of the last 30 days and a link into VSA. A record VSA hasn't seen for 90 days is marked as one to retire in VSA, and the records that look like machines we already monitor are counted apart.

Wegweiser also asks each connected VSA every hour what notifications are new, and keeps the Critical and Elevated ones. They show on the client's page and on a linked machine's own page. Nothing is written to VSA, and no webhook is made there.

Every call is a line in your own VSA audit log, so a poll spends at most six and a tenant at most 60 a day. The integration page sets how often, from 30 minutes to daily or off, each priced in lines a day.

The device chat can read what VSA says about a machine somebody linked: whether VSA's agent still reports, the antivirus, firewall and updates VSA sees, and its recent notifications. The chat sees it only where you have allowed VSA data to reach your AI provider.

The briefing opens on what it asks of you

The Security briefing opens on one sentence, "4 things need you now, and 6 to plan for", above a list in three tiers: Now, Plan for, and Worth knowing. Each line opens its card.

It used to open on its first chapter, whatever was in it. On 2026-10-04 that was a Chromium V8 flaw with twelve machine rows, for a hole Chrome and Edge had already fixed everywhere, while Office 2007, with no fix since 2017, sat collapsed below it.

More notes

  1. Agent release log

  2. An MSP can buy a new-client audit for £249

  3. The onboarding report costs 10 Wegcoins a copy