TroutTrout

First 3 weeks

A realistic plan for what to get done in your first three weeks.

2 min read · Last updated 2026-06-22

This page describes the recommended onboarding path for an Access Gate over the first three weeks: asset discovery and inventory on Day 1, enclave-based access control in Week 1, then logging, monitoring, and incident response in Week 2.

TimingPhaseFocus
Day 1Discovery & VisibilityPassive network listening, active discovery, asset profiling, populate the asset inventory
Week 1Deploy Access Control with EnclavesCreate an enclave, add assets and principals, grant permissions, test access workflows, begin logging and alerting
Week 2Log, Monitor & RespondCollect audit logs, connect log collection to your SIEM, run a risk audit and generate compliance reports

What's a good goal for your first three weeks with an Access Gate

Phase 1: Discovery & Visibility (Day 1)

  1. Passive network listening
  2. Active discovery
  3. Asset profiling
  4. Populate the Asset inventory

Phase 2: Deploy Access Control with Enclaves (Week 1)

  1. Create an enclave
  2. Add assets and principals
  3. Grant permissions
  4. Test access workflows
  5. Begin logging and alerting

Phase 3: Log, Monitor & Respond (Week 2)

  1. Collect audit logs
  2. Connect your log collection to your SIEM
  3. Run a risk audit and generate compliance reports
At the end of three weeks, you should reach:
  • ✓ Complete asset inventory (AC.CM-1, AC.CM-2)
  • ✓ Identity-based access control (AC.L2-3.1.1, AC.L2-3.1.2)
  • ✓ Network segmentation (SC.L2-3.13.1)
  • ✓ Encrypted connections (SC.L2-3.13.11)
  • ✓ Audit logging (AU.L2-3.3.1 through AU.L2-3.3.9)
  • ✓ Incident response capability (IR.L2-3.6.1)