Skip to main content
A Target is a place you want looked at, and the unit findings group under.

Create a Target

The Console cannot create Targets yet. Use the vijil command line tool:
The Console calls this object a Target. The command line still calls it a deployment, so every command that acts on a Target uses the deployment-* name. They are the same object.
The response contains a live credential, an install_token in plaintext. Never pipe this command to a file or into a continuous integration log. Copy the id and let the rest scroll away.
The id in the response is the Target identifier. Every command that acts on this Target needs it.

The Targets Tab

Open Discover in the sidebar and choose the Targets tab. Filter chips across the top count Targets by kind: All, Endpoint, Browser, Network, Cloud, and Source code. A Kubernetes cluster counts under Network, because the in-cluster Collector and the network scanner report as the same scanner kind.
The Targets tab listing six Targets with columns for source, kind, last scan, and agents
A chevron at the start of each row expands it to show that Target’s findings, grouped into AI, Non-AI, and Uncertain.
The Agents column counts Collectors. A Target showing three agents has three scanners installed against it. This column is separate from the Agent Registry.

Inside a Target

Click a Target to open it. The identifier sits under the title with a copy button, and the top right shows connection state and a Scan now button.
A Target detail page on day zero showing zero in scope, zero external providers, and no scan history
Two counters sit across the top: After the first scan, a line beneath the counters summarizes the most recent scan: when it ran, which Collector kind reported it, and how many Collectors it covered. Below that sit two panels, Usage insights and Agent activity. Both fill only from Vijil Dome telemetry pointed at this Target, and both stay empty on a Target that only runs scans.
The word “Agent” carries two meanings on this screen. In the Agent activity panel it means an AI Agent. In the Agents column and the connection badge it means a Collector.
Below them, five sub-tabs: The header badge reads Agent online, Agent stale, No agent reporting, or No agent connected.

Run a Scan

Press Scan now on the Target, or:
You can also press + New Scan on Discover and stay on the Scan surfaces tab. The modal calls Targets “scan surfaces”. Pick one and press Scan. Collectors poll every 30 seconds by default, so expect a short delay before the scan starts. Scan now reaches only Collectors that checked in within the last 24 hours. If none have, the Console tells you that it queued nothing. If the Target has no Collector connected, the Console asks you to confirm first.

Schedule Recurring Scans

Open the Schedule sub-tab, or use the command line:
--body takes a JSON object inline, or @file to read one from a file. Schedule a recurring scan for any Target you intend to keep.

Delete a Target

Deleting a Target removes its scan history, Collectors, credentials, policies, and violations. You can skip revoking the credentials first. Any Collector still installed on a machine loses its ability to report, so uninstall those separately. The command asks for confirmation. Pass --yes in a script.

Next Steps

Install a Collector

Credentials and install steps for each kind.

Review Discovered Resources

Read what a scan returned.
Last modified on October 2, 2026