Skip to content

Align CloudSec, CodeSec and MailSec onboarding, CLI and MCP guidance - #460

Open
maximelb wants to merge 5 commits into
masterfrom
audit/security-products-docs-20260930
Open

maximelb wants to merge 5 commits into
masterfrom
audit/security-products-docs-20260930

Conversation

@maximelb

@maximelb maximelb commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Cloud Security, Code Security and Email Security onboarding had examples and explanations that no longer matched their service contracts or the Python CLI. This gives new users an explicit installation and pilot path, correct policy records, and clear expectations for permissions, capabilities and rule updates across the CLI, SDK and MCP server.

  • Correct nested Code Security policy and registry credential examples, both enable switches, provider permissions, pagination examples, and Microsoft 365 certificate generation/rotation.
  • Use standard released SDK/CLI installation throughout, remove repeated version notices and source-revision pins, and document the available commands/selectors. Explain local scanner access, static-analysis rule options and gated backend capabilities.
  • Correct MailSec subscription defaults, vendor rule ownership and updates, shortest-horizon retention, trial reporting versus enforcement, and candidate backtests versus analysis with installed rules. Keep first connections scoped to pilot mailboxes and explain report-mailbox scope.
  • Document MailSec purpose independently of threat verdicts and reconcile all current rule-model fields and presence semantics (49 tables, 267 fields), including thread verification and incomplete link lookups.
  • Add a CloudSec SDK pagination snippet and verify its imports in snippet CI. Remove private contributor details from customer-facing guidance.
  • Add MailSec MCP onboarding and navigation; update CloudSec/CodeSec MCP setup with read-only profiles, default ai_agent.operate, exact product permissions and profile/version boundaries. Subscribe before fetching MailSec onboarding instructions; distinguish preview, accepted jobs, withheld actions and completed responses.
  • Correct MCP AutoFix to use cloudsec.respond and governed remediation runs. Document operator-selected local scanner/rules/extractor options, optional report uploads, network metadata activity, sanitized IaC maps and write-gated receipt status.

Validation: strict MkDocs build; all 215 documentation tests; 417-file Markdown lint; rendered internal links across 74 product/SDK/MCP pages (36,682 links, zero errors); numbering checks; tool names and JSON examples checked against MCP source; Python snippet compilation, imports and signature checks; git diff --check. No production changes or live customer-provider onboarding were performed.

Companion MCP changes and source onboarding guides are in lc-mcp-server #75. Links to the new source guides resolve on master after that companion is merged.

Product subscriptions, permissions and optional backend capabilities are configured separately from client installation. The CLI instructions assume the security-product release is available.

@maximelb

Copy link
Copy Markdown
Contributor Author

/lc-review

lcbill
lcbill previously approved these changes Sep 30, 2026
@limacharlie-refractionpoint

limacharlie-refractionpoint Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

LimaCharlie Cloud Security — code scan

No new code findings were introduced by this pull request.

This check reports and never fails: no gating.fail_on is set on the code_scanning policy.

Scanned refractionPOINT/documentation 0553d39…39f35d8 — only findings new in the head commit are listed; anything already on the base branch is the repository's own finding set, on the Cloud Security Code page.

This comment is updated in place on every push to this pull request.

@maximelb

Copy link
Copy Markdown
Contributor Author

/lc-review

lcbill
lcbill previously approved these changes Sep 30, 2026
@maximelb

Copy link
Copy Markdown
Contributor Author

Adversarial source and rendered-documentation review completed for this head:

  • Code Security examples use the actual nested policy and registry schemas, distinguish record enable from policy enable, and document provider permissions and conditional workflow availability.
  • Installation guidance distinguishes stable 5.6.2, existing development commands and the pending companion SDK additions. Local scanner access and certificate rotation limitations are explicit.
  • MailSec subscription, vendor rule reconciliation, minimum retention, pilot/report mailbox scope, and candidate-rule evaluation match the service contracts.
  • Every MDM object table and field in the collector's pinned model was reconciled: 49 tables / 267 fields. Purpose classification is separate from threat verdicts; omitted evidence is not treated as safety.
  • All 215 documentation tests, strict build, snippet imports/compilation, rendered links, numbering and Markdown lint passed locally. No open issues were found in this review.

/lc-review was requested again after the final schema update, with no substantive response in the ten-minute wait. Empty automatic approvals and Code Security scan results are separate from the requested written AI review. This PR remains open and unmerged.

@maximelb maximelb changed the title Correct CloudSec, Code Security and MailSec onboarding and reference Align CloudSec, CodeSec and MailSec onboarding, CLI and MCP guidance Sep 30, 2026
@maximelb

Copy link
Copy Markdown
Contributor Author

/lc-review

lcbill
lcbill previously approved these changes Sep 30, 2026
@maximelb

Copy link
Copy Markdown
Contributor Author

Final head 701a48b includes the CloudSec/CodeSec/MailSec CLI and MCP onboarding review, including the new MailSec MCP page and exact profile/permission/setup sequencing. All eight CI checks are green: rendered build, unit tests, Markdown, links, Python/Go snippet compilation, link comment and Code Security scan.

Independent source review and adversarial cross-review found no open issues. Local validation passed 215 tests, strict MkDocs, 417-file Markdown lint and 36,682 internal links across 74 reviewed product/SDK/MCP pages. The companion MCP implementation is #75 in refractionPOINT/lc-mcp-server; its new source-guide links should land with that PR.

/lc-review was requested for this final head at 02:00:21 UTC. The ten-minute wait ended without substantive written AI feedback. The automatic approval has an empty body, so it is not treated as a written /lc-review review. This PR remains open and unmerged.

@maximelb

Copy link
Copy Markdown
Contributor Author

/lc-review

@maximelb

Copy link
Copy Markdown
Contributor Author

Release guidance updated per the imminent-release assumption: removed development-only installs, source pins and repeated CLI-version notices. Customer docs and MCP errors now use the standard released limacharlie package.

All three updated PRs are green. Local checks passed: strict MkDocs, 215 documentation tests, Markdown lint, rendered numbering checks and the affected CloudSec MCP tests. Adversarial review found no open issues. The renewed /lc-review requests received no written feedback within ten minutes; empty automatic approvals are not counted as written reviews.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants