Skip to main content
A workspace is your organisation’s space in Earnie. It holds your projects, your members and their roles, and the audit history of every decision made in it.

Before you begin

To complete the setup wizard you need two things.
  • A way to sign in. This is access through your organisation’s corporate SSO (single sign-on). If your administrator has enabled password sign-in, you can use your work email address instead, with a password you set from a link they send you.
  • Ownership or Maintainer access on the organisation, group, or project that holds the repository you want to scan. Connecting a repository requires an organisation owner. If you’re not one, Earnie gives you a link to send to one.

Signing in

The login page shows the sign-in methods your workspace uses. Each workspace runs one of three sign-in modes: Password sign-in is off unless your administrator has enabled it for your workspace. If you don’t see an email and password form, your workspace signs in through SSO. Signing In

Email and password

You can use this method only if your administrator has enabled password sign-in. Enter your work email address and password, then select Sign in.

Choosing your password

When an administrator adds you to a workspace that signs in with a password, they send you a link that opens Set your password. The link works once and expires after 72 hours. If it says it has expired or was already used, ask your administrator for a new one. The old link stops working as soon as the administrator creates a new one. If you forget your password later, ask an Admin for a reset link.

Changing your password

If you sign in with a password, open the User menu at the top right and select Change password. Enter your current password, then your new one twice, and select Change password. You stay signed in on the device you used. Earnie signs you out of every other device, so sign in again there with the new password.

Corporate SSO

Select Sign in with corporate SSO. Earnie redirects you to your organisation’s identity provider, the service your company uses to manage logins. After you authenticate there, the identity provider sends you back to Earnie and you’re signed in to your workspace. Both methods sign you in to the same workspace, with the same members, roles, permissions, and audit history.

After you sign in

Where you land depends on how you arrived:
  • On your first sign-in as an Admin, Earnie takes you straight into the setup wizard.
  • If you open a link to a specific Earnie page while signed out, for example from a pull request comment, Earnie takes you to that page after you sign in, whichever sign-in method you use.
  • When you return, Earnie opens the last project you were viewing, or All Projects if that’s where you were. If your organisation has only one project, you go straight into it.

The setup wizard

Welcome to Earnie Earnie takes the first person to sign in to a new workspace through a six-step setup wizard. When it ends, Earnie is connected to GitHub or GitLab, your first project exists, and its first scan is running. The rail on the left lists the steps and marks the ones you’ve completed. You can leave the wizard and come back later, and Earnie reopens it at the first step you haven’t completed. Skip setup, at the top right, leaves the wizard at any point. Skipping doesn’t dismiss the Finish setup card in the sidebar. The card stays until you finish the steps or dismiss it yourself.

1. Welcome

The first screen explains what the wizard builds: one governed inventory of all your code. The inventory covers the open-source components in your code, snippets copied from elsewhere, their licences, known vulnerabilities, and provenance, meaning where the code came from. Select GitHub or GitLab to begin.

2. Connect a provider

Install Github AppEarnie reads your code through a GitHub App. A GitHub organisation installs an app to give a service limited access to its repositories. Earnie’s access to your source code is read-only and covers only the repositories you choose. Earnie can also comment on pull requests and post checks, so it reports its results where your team reviews code.Before you grant anything, Earnie lists each permission it’s asking for. To connect:
  1. Authorise Earnie once, so it can see which GitHub organisations you belong to.
  2. Choose the organisation that will own the connection.
  3. Install the app.
After you install the app, the wizard moves to the next step. Connecting a repository explains each permission and each step.
With either provider, the next step is the same repository picker, which lists the repositories the connection can reach.

3. Select repository

In this step you create your first project, the codebase Earnie governs together with its scans, decisions, and rules.
  1. Pick the repository this project will govern.
  2. Name the project. Earnie fills this field with the repository’s name when you pick the repository. You can also add a description.
  3. Choose the scanners and intelligence layers for the first scan:
    • Scanners analyse the source code itself. Open-source matching always runs. If your workspace has Cryptography or AI enabled, Earnie selects each of them by default. See AI provenance for what the AI scanner identifies.
    • Download Git LFS models appears once AI provenance is on. It controls whether Earnie fetches model weights stored in Git LFS so it can identify them. Use the project preference, or download or skip for this scan only. Downloads use the repository owner’s Git LFS bandwidth quota.
    • Intelligence layers add data to what the scanners find, such as known vulnerabilities and licence data.
Turning off a layer makes the first scan finish sooner. You can re-run a scan with more layers at any time.

4. First scan

First Scan The first scan starts on its own as soon as Earnie imports the repository, so you have nothing to do in this step. You don’t need to wait for the scan to finish. It keeps running in the background while you complete the last two steps.

5. Add members (optional)

Add Members Add the people who will triage findings, meaning they review each finding and record a decision about it. For each person, enter their email address and choose a role: Admin, Operator, or Viewer. Team & roles explains what each role can do. Developers and automated agents don’t need seats. They use Earnie through CI, the CLI, and the API instead. You can skip this step and add members later from Settings → Members.

6. Starter policy (optional)

Starter Templates A policy is a rule that tells Earnie what to do when a scan finds something, for example to block a merge that introduces a banned licence. Earnie provides policy templates for common rules. Pick one or more templates to begin with. A template is the quickest way to watch the gate work from start to finish. The gate is Earnie’s pass or fail check on a change. Each template shows the action it applies, such as warn or block. Policies you turn on here are enabled immediately. Templates you add later from a project’s Policies page start as drafts instead. When you finish the wizard, Earnie opens the results of your first scan. If you skip this step, you can write policies later, as described in Setting policies.

What’s next

Your first scan is now running. Next, read Connecting a repository to see what access you granted, then Your first scan to follow the scan through to completion.