Interno: Frequently Asked Questions (FAQ)

Interno: Frequently Asked Questions (FAQ)

Overview

Answers to the questions we hear most often about Interno, the Zeron Command Center. Interno pulls data from your existing security and IT tools into one place, normalises it, and lets you build dashboards, queries, alerts and a risk register on top of it.


Prerequisites

  • An Interno account in your organisation
  • At least one integration connected, or data uploaded through Manual Ingestion, before most screens have anything to show

Getting Started

What is Interno? Interno is the Zeron Command Center. It brings the data from your connected security tools into a common set of tables, then gives you dashboards, an asset inventory, a query and widget library, and a risk register built on that data.

How is Interno laid out? The left sidebar has these entries:

Sidebar entryWhat is under it
ZIN AdvisorThe AI assistant chat. Shown on Zeron-hosted (SaaS) environments only.
DashboardYour dashboards and their widgets.
AssetsAsset Inventory, Manual Ingestion, Query Library.
Risk RegisterRisks and the risk workflow.
ReportsReporting.
AdminIntegrations, Management, Settings.

Do I need a special role? Interno does not use named job-title roles. Access is granted with permission scopes that begin with defence: (for example defence:dashboard:view). Your administrator groups those scopes into policies and groups. See *Interno: Roles & Permissions Reference*.


Integrations and Data

Which tools can I connect? Go to Admin > Integrations and use the Category dropdown to browse the catalogue. Categories include EDR, XDR, SIEM, SOAR, CSPM, VMDR, WAF, PAM, IDAM, DLP, NAC, ITSM and more. Each connector's setup form is defined by the connector itself, so the fields you are asked for differ from tool to tool.

Can I change the credentials of an integration I already added? Yes. Open the integration's card menu and choose Edit. The full credential form reopens with your saved values filled in, and you save with Update. You do not need to delete and recreate the integration.

Why are the password and token fields empty when I edit? Secret fields are never sent back to your browser. On edit they are shown blank and marked *(leave blank to keep current)*. Leave one blank and the stored secret is kept; type a new value and it is replaced.

Why can't I rename an integration? The Name is permanent. It becomes the integration's identifier and is recorded against every scan it produces, so it cannot be changed after creation. On the edit form the Name field is disabled and shows the tooltip *"This name can't be changed once the integration is added."*

What can I type in the Name when I create an integration? Letters, digits, and the characters . _ - only — no spaces and no other symbols. If you enter something else, saving is blocked with *"Name may contain only letters, digits, and . \_ - (no spaces)."*

What else can I do to an existing integration? The card menu also offers Start Scan, Deactivate / Activate, Edit and Delete.

What if my data isn't available through a connector? Use Assets > Manual Ingestion to upload it. The uploader accepts Excel workbooks only — .xlsx and .xls.

How is the data organised once it arrives? Records from every connector are normalised into shared tables named ZCN_<TYPE>ZCN_DEVICES, ZCN_USERS, ZCN_VULNERABILITIES, ZCN_INCIDENTS and so on. Many tools can feed the same table. See *Interno Data Sources & Fields (Data Dictionary)*.


Dashboards and Widgets

How do I create a dashboard? On the Dashboard page use the Create button. It offers Dashboard (build one from template or existing widgets), ZIN Dashboard (generated by AI from a prompt), Widget, Evidence and Alerts.

Can I build my own widgets? Yes. The widget builder has three tabs — Query (point-and-click), SQL (write it yourself) and AI (describe what you want). A Browse data dictionary drawer lets you search every available field and insert it into the query.

Can I filter a whole dashboard at once? Yes. With a dashboard open, use Global Filters in the header. Filters you add there apply to every widget on that dashboard. The button turns green while filters are applied, and hovering it lists them.

Can I move a dashboard between environments? Use Export Dashboard in the dashboard's menu to download a .json file, and Import Dashboard to load one back.


Queries, Alerts and Risks

What is the Query Library? Assets > Query Library holds your saved items under three tabs: Widget, Evidence and Alert.

How does the Risk Register work? Risks move through a four-step workflow: Risk Initiation, Risk Scoring & Prioritization, Risk Management and Risk Closure.


Permissions

Why do I see an "Unauthorized" screen on a page? Your account is missing the scope that page requires. An administrator can add it under Admin > Management. The *Interno: Roles & Permissions Reference* lists which scope each area needs.

Who can manage users and groups? Admin > Management is available only to users who hold the zitadel:iam permission. Its tabs cover Users, Groups and Departments, plus activity and authentication logs.


Troubleshooting

Most sidebar entries do not respond when I click them → Until your organisation has ingested any data, Interno keeps only Integrations, Management, Manual Ingestion and Settings clickable; Dashboard, Asset Inventory, Query Library, Risk Register and Reports stay disabled. Connect an integration or upload a workbook, then reload.

My Excel file is rejected on Manual Ingestion → Only .xlsx and .xls are accepted. Convert CSV or other formats to an Excel workbook first.

I cannot see the Create button on the Dashboard page → That button appears only if you hold at least one of defence:dashboard:create, defence:widget:create or defence:query:create.

Editing an integration says the name cannot be changed → That is expected — the name is fixed at creation. If you truly need a different name, create a new integration and delete the old one.

I do not see ZIN Advisor in the sidebar → ZIN Advisor is shown on Zeron-hosted (SaaS) environments only. It is not present in self-hosted deployments.


Need more help? Contact support@zeron.one

    • Related Articles

    • Getting Started with Interno

      Overview Interno is the Zeron Command Center. It pulls data out of the security and IT tools you already run, keeps it in one place, and lets you build dashboards, run queries and track risks against it. This guide takes you from first login to your ...
    • Interno: Roles & Permissions Reference

      Overview Access to each part of Interno is controlled by permission scopes. Interno's own scopes all begin with defence:. This article lists the scopes that Interno checks and what each one unlocks. This page covers Interno only. For every product's ...
    • Interno: Metrics & Glossary

      Overview A reference for the terms and the standard KPI widgets you will meet in Interno, the Zeron Command Center. Prerequisites Access to Interno At least one integration connected, so the terms below have data behind them Platform and Navigation ...
    • Troubleshooting Common Issues in Interno

      Overview This guide covers the issues Interno users hit most often, and how to resolve them. Most "I can't see it" and "I can't do it" problems come down to one of two things: a missing permission scope, or an organisation that has not ingested any ...
    • Interno Data Sources & Fields (Data Dictionary)

      Overview When you build a widget or a query in Interno you pick a table and its fields. This guide explains how Interno organises the data that arrives from your connected tools, what the shared system fields mean, and how to find the right field ...