Frequently Asked Questions

Questions about THEWATCH

Straight answers about how connecting a tool works, pricing, and what's actually included.

Getting Started
A SOC automation and case-orchestration platform. THEWATCH doesn't compete with your SIEM or EDR for log collection. It sits downstream as the place every connected tool's alerts land, get triaged, and turn into a case, with SLA tracking, shift handoff, and automated response built in.
Request access and our team will follow up to get your organization set up. Every account then goes through mandatory two-factor enrollment on first login. See the Knowledge Base for the exact steps.
No. THEWATCH connects to the tools you already run: it's an intake and case-orchestration layer, not a replacement for detection tooling you've already invested in.
Connectors & Integrations
Connectors are unlimited on every PROVEiT! Flex subscription, there's no per-connector limit. Connect to anything with an API, plus the generic inbound webhook. See Integrations for what's already built.
THEWATCH connectors are a generic, authenticated webhook plus a field mapping you configure, not a per-vendor plugin. That means any tool that can send a JSON webhook can connect today, without waiting for a dedicated integration to be built. See the Knowledge Base for the exact setup steps.
Yes, a connector can mirror a ticketing system's own cases directly, keeping your ticket's status and assignee visible alongside THEWATCH's own case workflow. See Mirroring Cases & Tickets.
Yes, if the connector has an enrichment endpoint configured, an analyst can query the source tool directly from a case, without switching tabs. See Connector Enrichment.
Pricing & Billing
Annual billing is charged as 10 months up front and covers the full 12 months, effectively 2 months free compared to paying monthly. The per-month price shown on the pricing page updates depending on which billing option you select.
No. There is no startup, activation, or setup fee. Your bill is the recurring monthly platform fee plus the capacity, storage, and user accounts you select. The price you see is the price you pay.
You increase your selected Flex capacity, there are no overage packs to buy. Move up to the next capacity you need at any time and your monthly price updates to match. Automations are never stopped mid-incident over a capacity limit.
An Automation Action is one external operation THEWATCH performs on your behalf: querying a connected tool, enriching data, taking a response action, or sending a notification. Internal logic and correlation inside THEWATCH don't count against your limit, only the actual outside work.
How THEWATCH Works
A Watch (Monitoring Policy) is the detection logic: the condition THEWATCH is monitoring for. A Playbook is the automated response tied to that Watch. Every plan allows building as many Watches and Playbooks as you need within your plan's connector and action limits.
Yes, OIDC-based single sign-on, configured per organization. See Single Sign-On for setup steps.
Yes, on every account, with no way to skip it. A single account can see across every tool you've connected, so this isn't optional the way it is on some platforms.
Plans & Getting Started
There are no named plans to pick between. Configure PROVEiT! Flex to the automation-action capacity, storage, and user accounts your team actually needs, and increase it any time as you grow. Connectors, playbooks, and policies are unlimited on every subscription. Past the top self-serve capacity, or for MSSP terms, talk to us about Enterprise.

Still have a question?

We'd rather give you a straight answer than have you guess.

Get Support