> For the complete documentation index, see [llms.txt](https://docs.heeler.com/mrecEO40m5D6bt7Pq5pE/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.heeler.com/mrecEO40m5D6bt7Pq5pE/get-started.md).

# Get Started

Stand up Heeler and see your first findings — pick your path, work the checklist, and learn what each connection unlocks.

Heeler works by connecting to what you already have — your source code, cloud, registries, and tools — and building a live model of your software from it. There's nothing to deploy into your build: no sensors, no code tagging, no pipeline changes. **The more of your environment Heeler can see, the sharper its prioritization and remediation get.**

This section is the onboarding spine for administrators and DevSecOps. Each step delivers value on its own, and each connection you add sharpens everything before it.

{% hint style="info" %}
**Where this leads →** a program that runs without an operator: detect, prioritize by exposure, route, fix and confirm closure. [**Set Up Agentic Remediation**](/mrecEO40m5D6bt7Pq5pE/get-started/set-up-automated-remediation.md) is the setup; [**Run Unattended Dependency Remediation**](/mrecEO40m5D6bt7Pq5pE/solutions-and-use-cases/run-unattended-dependency-remediation.md) is a complete worked example.
{% endhint %}

## Choose your path

Not everyone onboards for the same reason. Start where your goal is:

<table><thead><tr><th width="300">Your goal</th><th>Start here</th></tr></thead><tbody><tr><td><strong>See findings fast</strong> (evaluation / POC)</td><td><a href="/mrecEO40m5D6bt7Pq5pE/get-started/quickstart.md">Quickstart</a> — connect one repository and read its findings.</td></tr><tr><td><strong>Stop risky code at the PR</strong></td><td><a href="/mrecEO40m5D6bt7Pq5pE/get-started/source-code-scm.md">Connect Your Code</a>, then turn on <a href="/mrecEO40m5D6bt7Pq5pE/prevent/pr-guardrails.md">Guardrails</a>.</td></tr><tr><td><strong>Fix findings without an operator</strong></td><td><a href="/mrecEO40m5D6bt7Pq5pE/get-started/source-code-scm.md">Connect Your Code</a> + <a href="/mrecEO40m5D6bt7Pq5pE/get-started/cloud-and-runtime.md">Cloud</a>, then set up a <a href="/mrecEO40m5D6bt7Pq5pE/operate/workflows.md">Workflow</a>.</td></tr><tr><td><strong>Roll Heeler out to the org</strong></td><td>Work the full checklist below, top to bottom.</td></tr></tbody></table>

## Your onboarding checklist

Work these in order. Each links to step-by-step instructions.

**Essential — get to first value**

* [ ] [Before You Begin](/mrecEO40m5D6bt7Pq5pE/get-started/before-you-begin.md) — line up the access you'll need.
* [ ] [Connect Your Code](/mrecEO40m5D6bt7Pq5pE/get-started/source-code-scm.md) — findings appear across your repos.
* [ ] Review your first findings — confirm the scan worked and read one (see [Quickstart](/mrecEO40m5D6bt7Pq5pE/get-started/quickstart.md)).

**Recommended — sharpen the signal**

* [ ] [Connect Your Cloud and Runtime](/mrecEO40m5D6bt7Pq5pE/get-started/cloud-and-runtime.md) — reachability and exposure make prioritization real.
* [ ] [Connect Registries and Artifacts](/mrecEO40m5D6bt7Pq5pE/get-started/registries-and-artifacts.md) — tie built artifacts back to source.
* [ ] [Map Your Organization](/mrecEO40m5D6bt7Pq5pE/get-started/map-your-organization.md) — teams, ownership, and tiers drive routing and priority.
* [ ] [Connect Ticketing](/mrecEO40m5D6bt7Pq5pE/get-started/ticketing.md), [Messaging](/mrecEO40m5D6bt7Pq5pE/get-started/messaging.md), and [Developer Platforms](/mrecEO40m5D6bt7Pq5pE/get-started/developer-platform.md) — the destinations findings ticket and notify.

**Scale & govern — bring in the team**

* [ ] [Users and Access](/mrecEO40m5D6bt7Pq5pE/get-started/users-and-access.md) — SSO, SCIM provisioning, and roles.
* [ ] Activate prevention — turn on your first [Guardrail](/mrecEO40m5D6bt7Pq5pE/prevent/pr-guardrails.md).
* [ ] Automate response — create your first [Workflow](/mrecEO40m5D6bt7Pq5pE/operate/workflows.md).
* [ ] *(Optional)* [Set Up Developer Tooling](/mrecEO40m5D6bt7Pq5pE/get-started/set-up-developer-tooling.md) — CLI, MCP, and Agent Skills.
* [ ] [Set Up Agentic Remediation](/mrecEO40m5D6bt7Pq5pE/get-started/set-up-automated-remediation.md) — connect your package registries and set the agent's policy, so Heeler can produce validated fixes.

## What each connection unlocks

<table><thead><tr><th width="260">Connect…</th><th>…and Heeler gains</th></tr></thead><tbody><tr><td><a href="/mrecEO40m5D6bt7Pq5pE/get-started/source-code-scm.md">Source code (SCM)</a></td><td>Dependency (SCA), code-security (SAST), and secret findings on every repository, plus PR guardrails.</td></tr><tr><td><a href="/mrecEO40m5D6bt7Pq5pE/get-started/cloud-and-runtime.md">Cloud &#x26; runtime</a></td><td>Code-to-cloud context — what's deployed, reachable, and internet-exposed — which drives accurate prioritization.</td></tr><tr><td><a href="/mrecEO40m5D6bt7Pq5pE/get-started/registries-and-artifacts.md">Registries &#x26; artifacts</a></td><td>The link from built images and artifacts back to the source that produced them.</td></tr><tr><td><a href="/mrecEO40m5D6bt7Pq5pE/get-started/ticketing.md">Ticketing</a>, <a href="/mrecEO40m5D6bt7Pq5pE/get-started/messaging.md">messaging</a> &#x26; <a href="/mrecEO40m5D6bt7Pq5pE/get-started/developer-platform.md">developer platforms</a></td><td>Ticketing (Jira, Linear, Shortcut, GitHub Issues), messaging (Slack, Teams, Google Chat), and the destinations workflows route to.</td></tr><tr><td><a href="/mrecEO40m5D6bt7Pq5pE/get-started/map-your-organization.md">Organization structure</a></td><td>Teams, ownership, and business tiers — so findings route to the right owner and prioritize by business impact.</td></tr><tr><td><a href="/mrecEO40m5D6bt7Pq5pE/get-started/users-and-access.md">Users &#x26; access</a></td><td>SSO (SAML 2.0), SCIM provisioning, and role-based permissions.</td></tr></tbody></table>

{% hint style="info" %}
In a hurry? The [Quickstart](/mrecEO40m5D6bt7Pq5pE/get-started/quickstart.md) is the fastest path from zero to first findings.
{% endhint %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.heeler.com/mrecEO40m5D6bt7Pq5pE/get-started.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
