Small status note from the build bench.
The current Guard constraint is simple: onboarding happens through the DigitalOcean Marketplace. Marketplace availability is not ready yet, so the site does not offer a separate signup flow. No queue, no fake “request access” button, no email-shaped backlog.
Initial contract
The first release is deliberately narrow:
- agentless;
- read-only;
- limited to permitted DigitalOcean inventory and its resource relationships;
- findings should include the observed context and a next step.
Things that are explicitly not part of that contract: host agents, malware scanning, scheduled monitoring, and automatic remediation. Keeping the first boundary small is much more useful than pretending it is a platform.
What changed
The product and documentation now describe the intended flow as:
- Marketplace installation, once available.
- Read-only authorization.
- Assessment and review of evidence-backed findings.
There is also an original visual mockup for that flow. It is labelled as illustrative because it is not a DigitalOcean screen and does not mean the listing is live. This is a boring detail. Boring details are where trust lives.
Next
Keep the assessment narrow, make the evidence legible, and only expand the scope after the basic loop is useful. The exciting part is a well-labelled permission boundary. Yes, really.