{
  "product": "Atlas Cyber Protect",
  "version": "1.0.19",
  "updated": "2026-08-17",
  "summary": "Silent LAN side-box that watches your network, explains threats, and runs company People · Atlas Connect · Chat. Same email+password after manager Approve. FN.nology manages every customer site from the Cyber Protect room dashboard (/factory/guard): companies → sites → Connect PCs with unattended Atlas Connect, room notes & ideas, and pricing only set per quote in the Business room. Daily Protect backup at 02:00 for restore. Portal redesigned (modern AI-style UI, radar + live status strip, manager Business dashboard tab on the box). Factory Guard room rebuilt as a full management dashboard: Overview/Companies/Users/Support/Connect/Notes with company rename, ticket close, and per-room ideas. Every surface (Factory UI, box portal, Windows agent, Chat app) now reports errors automatically to an Atlas fix list (deduped, owner-only, in the Factory Guard room) so issues are tracked and fixed. Company chat redesigned: Atlas look with 6 user color themes, new-chat button, Help me tickets. People accept/assign now works from the Factory guard room (no box login needed): new signups auto-load, pick company → Accept → mark Manager/User.",
  "where": {
    "portal": "Customer Protect box UI — usually http://<box-lan-ip>:8787/ (also Tailscale to that box). Tabs below live here.",
    "funnel_howto": "https://atlas-server.taile9cc75.ts.net/cyber-protect/how-to",
    "funnel_chat": "https://atlas-server.taile9cc75.ts.net/cyber-protect/chat",
    "factory_guard": "https://atlas-server.taile9cc75.ts.net/factory/guard — FN.nology owner only",
    "agent_setup": "https://atlas-server.taile9cc75.ts.net/releases/public/windows/AtlasCyberProtectAgent-Setup-latest.exe",
    "atlas_connect_client": "Built into the Protect agent — no extra client to install. The agent streams the screen itself (in-house Atlas Remote); nothing else is ever shown on the PC.",
    "acp_funnel": "https://acp-atlas-cyber-protect.taile9cc75.ts.net/ — optional Funnel front for this Protect site",
    "chat_apk": "https://atlas-server.taile9cc75.ts.net/releases/public/android/AtlasCyberProtect-latest.apk",
    "brochure_pdf": "https://atlas-server.taile9cc75.ts.net/releases/public/marketing/Atlas-Cyber-Protect-Brochure.pdf",
    "links_txt": "https://atlas-server.taile9cc75.ts.net/releases/public/marketing/Atlas-Cyber-Protect-How-Everything-Links.txt",
    "connect_api": "https://atlas-server.taile9cc75.ts.net/api/cyber-protect/connect (relay status + key, signed-in users get full details)",
    "agent_manifest": "https://atlas-server.taile9cc75.ts.net/api/companion/agent/update",
    "pricing": "One flat price: R8 000/month per site — unlimited PCs, setup + support included. Single package: Atlas Cyber Protect Complete.",
    "brochure": "https://atlas-server.taile9cc75.ts.net/releases/public/marketing/Atlas-Cyber-Protect-Brochure.html"
  },
  "logins": [
    {
      "name": "Protect box login",
      "where": "Top of the portal (email + password / register)",
      "does": "Unlocks the local Protect dashboard on this box (Overview, Devices, Threats, Insights, Guardian, etc.).",
      "note": "First visit: register. Owner can also use fn.nology@gmail.com + Atlas master password (owner-login). Fail2Ban ignoreip is loopback-only — banned IPs can be unbanned in Factory Guard. Master account always authenticates against the live atlas_password secret."
    },
    {
      "name": "Atlas company sign-in (collab)",
      "where": "People tab → Atlas company sign-in",
      "does": "Unlocks People list, Manager/User buttons, Atlas Connect, and company Chat APIs (Funnel Bearer token).",
      "note": "Separate from Protect box login. Owner: fn.nology@gmail.com + Atlas password, leave company_id blank. Managers: company email + their password."
    }
  ],
  "sections": [
    {
      "id": "overview",
      "tab": "Home",
      "find": "First tab after sign-in",
      "what": "At-a-glance health of this Protect site.",
      "can_do": [
        "See live process / job status",
        "Read the Guardian feed (plain-language events)",
        "Scan recent activity on this box"
      ],
      "tip": "Start here when something feels wrong — then open Threats or Devices."
    },
    {
      "id": "tools",
      "tab": "Browser / Winbox",
      "find": "Tab: Browser / Winbox · also Factory Guard site Details",
      "what": "Open a browser (speed tests / web logins) or MikroTik Winbox on the customer office Protect PC.",
      "can_do": [
        "Open browser on the office Windows Protect agent (default speedtest.net, optional URL)",
        "Open Winbox on that same office PC to log into MikroTik routers on the LAN",
        "From Factory Guard: site Details → Browser (office PC) / Winbox (office PC)",
        "From overseas: click the tool, then Atlas Connect to see the office screen"
      ],
      "tip": "These programs run on the customer office PC, not in your browser. Funnel queues the command; the box heartbeat delivers it."
    },
    {
      "id": "devices",
      "tab": "Devices",
      "find": "Tab: Devices",
      "what": "Everything Protect can see on your LAN (phones, PCs, cameras, printers, IoT).",
      "can_do": [
        "List devices with IP, ping, type, ports, vendor",
        "Select Windows PCs and Install agent (popup on that PC, or invite link)",
        "Store remote-install Windows admin login for push installs",
        "See paired PC Agents for this site under the same tab"
      ],
      "tip": "Select PCs → Install agent. User confirms Install once with Windows admin if prompted."
    },
    {
      "id": "agents",
      "tab": "PC Agents",
      "find": "More ▾ → PC Agents (also listed under Devices and Insights)",
      "what": "Paired Windows agents on this customer site.",
      "can_do": [
        "See antivirus / security product status",
        "See installed programs and agent version",
        "Push / silent update when Atlas publishes a new agent",
        "Confirm which PCs are online to Atlas"
      ],
      "tip": "Install agents from Devices. Manual download is on Funnel releases (see Where)."
    },
    {
      "id": "people",
      "tab": "Team",
      "find": "Tab: Team (People)",
      "what": "Company staff accounts for this business (isolated per company on Atlas Funnel).",
      "can_do": [
        "Atlas company sign-in (required for People / Chat / Connect)",
        "From the Factory: Cyber Protect room → People auto-loads with your fn.nology session — no extra sign-in",
        "New signups show as pending → pick the company → ✓ Accept (approves + unlocks Chat/Connect)",
        "Mark Manager (everything) or User (chat + office PC only)",
        "Same buttons on a customer Protect box under its People/Team tab (Atlas company sign-in there, company blank)",
        "Assign office PC for user Connect / WFH",
        "Forgot password → email reset link"
      ],
      "tip": "Self-register stays pending until you Accept. The People table in the Factory guard room is the fastest place to approve — no need to log into each customer box.",
      "test": [
        "1. Customer installs the agent / registers with email — appears as pending.",
        "2. Factory → Cyber Protect room → People section loads automatically (owner session travels with the factory login).",
        "3. Choose the company from the dropdown → click ✓ Accept.",
        "4. Mark Manager or User. Same email + password now unlocks Chat and Atlas Connect.",
        "5. If a tab ever says 'sign in' while you are logged into the Factory, open the Factory map once to refresh the session, then reload the room."
      ]
    },
    {
      "id": "remote",
      "tab": "Remote help",
      "find": "Tab: Remote help (Atlas Connect)",
      "what": "Secure remote help for the business. Customer-facing name is Atlas Connect only (no relay jargon).",
      "can_do": [
        "Managers: Connect to company PCs, guest links, revoke all, Approve WFH",
        "Users: Connect only to assigned office PC (same login as Chat)",
        "End / Clock out sessions"
      ],
      "tip": "Office/company PCs: managers connect without a popup. Personal/home PCs: Accept on screen. Sign in under People first.",
      "how_it_works": [
        "Engine: the Protect agent's own in-house Atlas Remote (no third-party remote software, no extra client, nothing to install).",
        "Office PCs running the Windows Protect Agent stream their screen to the box and report ready (atlas_connect_id = atlas-remote).",
        "Manager clicks Connect: the collab API approves the session and the manager's Atlas Remote live view opens in the portal — fully embedded, only the Atlas Protect app is ever seen on the PC.",
        "Nothing pops up on the office PC: the remote engine runs invisibly inside the agent, never a RustDesk window."
      ],
      "test": [
        "1. Install the Windows Protect Agent on an office PC and sign in (it reports ready within ~1 minute).",
        "2. From the portal People list, click Connect on that PC — the Atlas Remote live view opens in the portal.",
        "3. Drive the PC from the live view: click / drag / scroll / type. Nothing is shown on the office PC except the Atlas Protect agent.",
        "4. Old separately-installed RustDesk copies are removed automatically by the agent (purge on start + every 5 min)."
      ],
      "loose_ends": [
        "Remote view needs the Protect agent signed in and streaming on the target PC — if a PC shows 'waiting for first frame', open the agent on that PC and wait ~1 minute.",
        "Windows agent also opens Browser (speed tests / logins) and Winbox on this office PC when queued from Protect UI or Factory Guard."
      ]
    },
    {
      "id": "chat",
      "tab": "Chat",
      "find": "Tab: Chat · full UI on Funnel /cyber-protect/chat · embedded in Windows agent (Chat tab)",
      "what": "Modern company messenger (direct chats, groups, media, voice/video calls). Company-only — never shared across businesses.",
      "can_do": [
        "Direct chats + groups with avatars, online dots, unread badges, search",
        "Voice & video calls between contacts — recorded and saved (audio/video webm) to the company archive",
        "Attach images/files/voice — viewable inline by thread members (media is tenant-isolated)",
        "Contacts are automatic: approved people who registered with the Protect agent on a PC or phone appear in the Contacts tab — tap one to start a direct chat",
        "Managers create groups and pick members; announcements are manager-led; manager badge shows to everyone (role set by FN.nology)",
        "Block/Unblock on Protect People (or the box portal): a blocked person's phone/agent locks immediately and their email can be reused for a new employee",
        "Chat tab inside the Windows agent (email identity, same as phone APK), or Funnel /cyber-protect/chat",
        "Android APK AtlasCyberProtect-latest.apk — same email account as the PC agent",
        "Full archive (chats, pictures, files, call log + recordings) auto-copied to the office Protect PC — managers view it on the box (Archive tab)",
        "Help me — opens a support-style ticket / assist path"
      ],
      "tip": "Nobody adds contacts by hand — install the agent on a PC (or the Cyber Chat app on a phone) and register; after a manager Approves, the person appears for the whole company. Same login as People / Atlas Connect. Calls need mic/camera permission the first time."
    },
    {
      "id": "traffic",
      "tab": "Traffic",
      "find": "More ▾ → Traffic",
      "what": "Bandwidth pulse and services Protect can observe from this side-box.",
      "can_do": [
        "See top talkers (who is using bandwidth on the path Protect sees)",
        "List LAN services spotted during scans"
      ],
      "tip": "Honest limit: this is a side-box sample, not a full switch mirror of every packet."
    },
    {
      "id": "insights",
      "tab": "Insights",
      "find": "More ▾ → Insights",
      "what": "Deeper network and PC health from Protect’s point of view.",
      "can_do": [
        "Internet & DNS checks from the Protect box",
        "Network gear — discover gateways, switches, APs; save default or per-device admin login; scan + read info (read-only)",
        "Device timeline of changes Protect noticed",
        "PC Agents — antivirus, programs, updates",
        "Email / link warnings from PC agents (clipboard, Outlook, pasted links)"
      ],
      "tip": "Network gear never changes router/switch/AP settings unless authorized by fn.nology@gmail.com. Creds stay on the Protect box (0600)."
    },
    {
      "id": "threats",
      "tab": "Threats",
      "find": "Tab: Threats",
      "what": "Active hunt results on your LAN.",
      "can_do": [
        "See risky open services (e.g. Telnet, SMB, RDP, open databases)",
        "Spot brand-new unknown devices",
        "Notice gateway MAC changes (ARP spoof hint) and probes toward Protect",
        "Choose Fine (keep/allow) or Neutralize (contain MAC on Protect’s path)"
      ],
      "tip": "Protect never silent-blocks without your Fine / Neutralize choice."
    },
    {
      "id": "guardian",
      "tab": "Ask guardian",
      "find": "More ▾ → Ask guardian",
      "what": "On-box helper that explains your network in plain language.",
      "can_do": [
        "Ask what threats were found",
        "Ask about devices, internet path, learning state",
        "Use preset questions or type your own"
      ],
      "tip": "Explains only — does not change policy without you."
    },
    {
      "id": "howto",
      "tab": "How to use",
      "find": "More ▾ → How to use · also Funnel /cyber-protect/how-to",
      "what": "This living guide — how each section works, what it can do, and where to find it.",
      "can_do": [
        "Read every portal section in one place",
        "Open the full Funnel how-to page",
        "See employee / manager / owner role tips"
      ],
      "tip": "When Atlas adds Protect features, this guide is updated in the same change (atlas-cyber-protect-guide.json)."
    },
    {
      "id": "how",
      "tab": "How it works",
      "find": "More ▾ → How it works",
      "what": "Short product truth: Protect is a silent LAN side-box.",
      "can_do": [
        "Understand plug-and-watch (same switch/router as your gear)",
        "See the continuous sweep, threat hunt, ping, identify, traffic sample, internet/DNS, learning %, Fine/Neutralize, guardian loop"
      ],
      "tip": "Not antivirus on every phone. Not your gateway. Neutralize only contains on the Protect path when you choose it."
    },
    {
      "id": "biz",
      "tab": "Business",
      "find": "Tab: Business (manager dashboard on the Protect box)",
      "what": "A manager dashboard right on the Protect box — approve users, manage office PCs, watch the support queue and run quick actions without the Funnel.",
      "can_do": [
        "Approve pending app signups (same Approve as Team tab)",
        "Mark Manager or User per person; assign office PC",
        "See office PCs + their Atlas Connect status, one-click Connect",
        "Support queue for this company (Help me tickets) with close",
        "Quick actions: refresh status, open How to use, Atlas Connect status"
      ],
      "tip": "Only managers see the Business tab — users keep Team/Chat/Connect. Company data never leaves this business.",
      "test": [
        "1. Manager signs in on the box portal (Atlas company sign-in).",
        "2. Open Business tab: pending approvals, office PCs, support queue load.",
        "3. Approve a pending signup; role shows Manager/User for everyone.",
        "4. Connect button dials the office PC via Atlas Connect (same login as Chat).",
        "5. User accounts never see the Business tab."
      ]
    }
  ],
  "roles": [
    {
      "id": "employee",
      "title": "Employees / Users",
      "bullets": [
        "Create account in app/chat → wait for manager Approve on Protect People",
        "Same email + password then works for Chat and Atlas Connect",
        "User access only: company Chat + Connect to your assigned office PC",
        "Accept/Decline remote on personal PCs; Clock out when WFH ends"
      ]
    },
    {
      "id": "manager",
      "title": "Managers",
      "bullets": [
        "Full company access: People, Approve users, Connect any company PC, Chat, guest links, overtime",
        "Approve pending signups so staff use one login everywhere",
        "Portal on site or agent worldwide via Funnel"
      ]
    },
    {
      "id": "owner",
      "title": "FN.nology owner",
      "bullets": [
        "fn.nology@gmail.com — Factory Guard for all Protect sites; unattended Atlas Connect to linked PCs",
        "Owner-login on any Protect UI with Atlas master password",
        "Company sign-in on People also accepts Atlas master password (same gate)",
        "Only owner-authorized path may change gateway/switch/AP settings later; Insights gear is read-only by default"
      ]
    }
  ],
  "find_map": [
    {
      "want": "Android Chat app",
      "go": "Funnel /releases/public/android/AtlasCyberProtect-latest.apk"
    },
    {
      "want": "How everything links (TXT)",
      "go": "Funnel /releases/public/marketing/Atlas-Cyber-Protect-How-Everything-Links.txt"
    },
    {
      "want": "Sales brochure PDF",
      "go": "Funnel /releases/public/marketing/Atlas-Cyber-Protect-Brochure.pdf"
    },
    {
      "want": "Backup / restore after crash",
      "go": "Server daily 02:00 → /mnt/M.2pool/atlas-vault/07-SYSTEM/backups/cyber-protect/daily/LATEST.tgz (RESTORE.txt inside)"
    },
    {
      "want": "Open browser / Winbox on the office PC",
      "go": "Protect portal Browser / Winbox tab, or Factory Guard site Details"
    },
    {
      "want": "Ring room 3D city + bio disasters",
      "go": "Factory → The Ring — 3D city view; Nature panel has fire/drought/freeze/meteor and BIO plague/fever/pandemic/sickness"
    },
    {
      "want": "Same password for Chat and Connect",
      "go": "One company account after Approve — /cyber-protect/chat uses same login"
    },
    {
      "want": "See who is on the Wi‑Fi / LAN",
      "go": "Devices"
    },
    {
      "want": "Install protection on a Windows PC",
      "go": "Devices → select PC → Install agent"
    },
    {
      "want": "Antivirus / programs on PCs",
      "go": "PC Agents or Insights → PC Agents"
    },
    {
      "want": "Make someone a Manager",
      "go": "Team (People) → Atlas company sign-in → Manager button or Add person"
    },
    {
      "want": "Remote into a PC",
      "go": "Remote help (Atlas Connect — sign in under Team first; each PC shows ready once Atlas Connect is set up on it)"
    },
    {
      "want": "Work from home to office PC",
      "go": "Atlas Connect → Connect to my office PC"
    },
    {
      "want": "Company messages",
      "go": "Chat tab or Funnel /cyber-protect/chat"
    },
    {
      "want": "Router / switch / AP info",
      "go": "Insights → Network gear"
    },
    {
      "want": "Suspicious ports or new devices",
      "go": "Threats"
    },
    {
      "want": "Ask what Protect saw",
      "go": "Ask guardian"
    },
    {
      "want": "How this product works",
      "go": "How it works + How to use"
    },
    {
      "want": "Owner fleet of all customers",
      "go": "Factory Guard on Funnel"
    },
    {
      "find": "Where does FN.nology manage all customer Protect sites and connect to office PCs?",
      "tab": "Owner dashboard (Cyber Protect room)",
      "what": "/factory/guard — companies → sites → Atlas Connect PCs, room notes & ideas, no prices (set per quote in Business)"
    },
    {
      "want": "Manager Business dashboard on the box",
      "go": "Protect portal Business tab (http://<box-ip>:8787, manager sign-in)"
    },
    {
      "want": "Factory Guard room (owner dashboard)",
      "go": "/factory/guard — companies, users, support, Connect, room notes"
    },
    {
      "want": "Support ticket close API",
      "go": "POST /api/cyber-protect/support/tickets/{id}/status?status=closed"
    },
    {
      "want": "Fix list (error queue)",
      "go": "Factory Guard → Fixes (owner) / POST /api/client-log/fixlist"
    },
    {
      "want": "Chat themes",
      "go": "Atlas Chat settings gear (⚙) — 6 color themes, saved per device"
    },
    {
      "want": "Approve / assign users & managers to companies",
      "go": "Factory → Cyber Protect room → People section (auto-loads) → pick company → ✓ Accept → Manager or User"
    }
  ],
  "limits": [
    "Protect is a side-box on the LAN — not the customer router/gateway.",
    "It cannot scan every file on every phone/PC; PC Agents cover Windows endpoints you install.",
    "Traffic view is what this box can observe, not a full SPAN/mirror of the switch.",
    "Neutralize contains a MAC on Protect’s path — it is not a campus firewall rewrite.",
    "People / Connect / Chat need Atlas company sign-in; Protect top login alone is not enough.",
    "Daily Protect backup runs at 02:00 on NVMe; HDD hourly atlas-backup may fail if all412me is full — Protect daily still runs.",
    "Users never get manager People admin or Connect to arbitrary PCs — only assigned office PC."
  ],
  "maintainers": {
    "source_of_truth": "omni/atlas-cyber-protect-guide.json",
    "render_funnel": "omni/atlas-cyber-protect-howto.html + GET /api/cyber-protect/guide",
    "render_portal": "cyber-protect-usb/agent/portal.html → How to use tab (loads guide.json)",
    "rule": "When adding or changing a Protect portal tab or customer-facing feature, update this JSON in the same change (version + updated dates, section, find_map)."
  }
}