> For the complete documentation index, see [llms.txt](https://docs.guardware.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.guardware.com/documentation/discover/about/introduction-to-discover.md).

# Introduction to DISCOVER

GuardWare DISCOVER is a cross-platform system designed to identify, classify, and manage sensitive data across enterprise environments. It operates across endpoints, file servers, email systems, and cloud services, helping organisations detect and reduce exposure of regulated and sensitive information like PCI, PII, PHI, as well as custom data types.

At its core, DISCOVER is built around a centralised model of control and distributed execution. This allows it to scale across diverse infrastructures, from closed-off, high-security networks to fully cloud-native environments, while maintaining a single point of visibility and administration.

## System Architecture

GuardWare DISCOVER uses a centralised management architecture with distributed scanning components. The Management Console coordinates scan activity, while Scanning Agents execute scan and remediation tasks on assigned systems and services assigned to them.

{% columns fullWidth="false" %}
{% column width="33.33333333333333%" %}
{% hint style="info" icon="1" %}
**Management Console**\
\
The central web application where scan jobs are scheduled, configurations are stored, and results are reviewed. It can be hosted on-premises or in the cloud.
{% endhint %}
{% endcolumn %}

{% column width="33.33333333333333%" %}
{% hint style="info" icon="2" %}
**Scanning Server**\
\
A Windows system running the Scanning Agent that has been assigned to perform remote scanning on behalf of other systems.
{% endhint %}
{% endcolumn %}

{% column %}
{% hint style="info" icon="3" %}
**Targets**\
\
The systems and services scanned by GuardWare DISCOVER. Targets can include endpoints, file servers, and cloud-based services such as Exchange Online, SharePoint Online, Gmail, and Google Drive.
{% endhint %}
{% endcolumn %}
{% endcolumns %}

## Deployment Models

GuardWare DISCOVER supports both on-premises and cloud deployments. Each deployment model supports Local Scanning, Remote Scanning, or a combination of both.

{% hint style="info" %}
[**On-Premises Deployment**](#on-premises-deployment)

[**Cloud Deployment**](#cloud-deployment)
{% endhint %}

### On-Premises Deployment

The Management Console is hosted on a Windows Server within the organisation's network. This deployment model is typically used when outbound communication is restricted or prohibited, or when organisational policies require management infrastructure to remain on-site.

Depending on the organisation's requirements, scanning can be performed using one of the following architectures.

#### Local Scanning

In a Local Scanning architecture, the Scanning Agent is installed directly on each device to be scanned. Each system scans its own local storage and securely communicates scan results to the on-premises Management Console over HTTPS.

<figure><img src="https://4044942488-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FPtAo3ilfcIjmOhwnXZVf%2Fuploads%2Fm2sMbrIcLBqoUrw9OwgO%2Fimage.png?alt=media&amp;token=3b27c9bb-aae7-4bd4-b668-84217778492b" alt=""><figcaption></figcaption></figure>

This architecture is suitable when the Scanning Agent can be installed on all target systems and no remote device scanning is required.

#### Remote Scanning

In a Remote Scanning architecture, one or more Windows systems are designated as Scanning Servers. Each Scanning Server runs the Scanning Agent and performs scans on behalf of target systems that do not have the Scanning Agent installed.

<figure><img src="https://4044942488-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FPtAo3ilfcIjmOhwnXZVf%2Fuploads%2FBBbKzgIRjKkJrpYLiPza%2Fimage.png?alt=media&amp;token=5055e8a6-958e-40d0-adfe-4a71bc5ac3b0" alt=""><figcaption></figcaption></figure>

Scanning Servers may be deployed on physical servers, virtual machines, or other Windows systems with network connectivity to the target environment. Scanning Servers connect to supported targets using the appropriate protocol or service interface:

* Windows devices and SMB file servers are scanned remotely using SMB or WinRM.
* Linux and macOS systems are scanned remotely using SSH.
* Microsoft 365 services, including Exchange Online and SharePoint Online, are accessed through the Microsoft Graph API.
* Google Workspace services, including Gmail and Google Drive, are accessed through the appropriate Google Workspace REST APIs.

Communication between the Management Console and Scanning Servers occurs over HTTPS. Scan assignments, credentials, and configuration settings are managed centrally through the Management Console.

Supported cloud services are scanned remotely through a Scanning Server. It connects through Microsoft Graph or the Google Workspace REST APIs. Remotely scanned targets can be reassigned to another Scanning Server at any time.

### Cloud Deployment

The Management Console is hosted on a Windows Server running in a cloud environment. This deployment model provides centralised management without requiring the Management Console to reside within the organisation's internal network.

Depending on the organisation's requirements, scanning can be performed using Local Scanning, Remote Scanning, or a combination of both.

#### Local Scanning

In a Local Scanning architecture, the Scanning Agent is installed directly on each endpoint or file server to be scanned. Each system scans its own local storage and securely communicates scan results to the cloud-hosted Management Console over HTTPS.

<figure><img src="https://4044942488-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FPtAo3ilfcIjmOhwnXZVf%2Fuploads%2FXBrMv6og4VXQR4Ajg8O8%2Fimage.png?alt=media&amp;token=2bd88488-24d1-4432-bbcd-74dcf4e6c97b" alt=""><figcaption></figcaption></figure>

This architecture is suitable when the Scanning Agent can be installed on all target systems.

#### Remote Scanning

In a Remote Scanning architecture, one or more Windows systems are designated as Scanning Servers. Each Scanning Server runs the Scanning Agent and performs scans on behalf of target systems that do not have the Scanning Agent installed.

<figure><img src="https://4044942488-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FPtAo3ilfcIjmOhwnXZVf%2Fuploads%2FPW9xDJ9F83F66DNg8zcs%2Fimage.png?alt=media&amp;token=50110bed-5385-4ff9-92d0-4ee843c6013d" alt=""><figcaption></figcaption></figure>

Scanning Servers may be deployed on-premises, in the cloud, or in another suitable location with network connectivity to the target systems and services. They connect to supported targets using the appropriate protocol or service interface:

* Windows devices and SMB file servers are scanned remotely using SMB or WinRM.
* Linux and macOS systems are scanned remotely using SSH.
* Microsoft 365 services, including Exchange Online and SharePoint Online, are accessed through the Microsoft Graph API.
* Google Workspace services, including Gmail and Google Drive, are accessed through the appropriate Google Workspace REST APIs.

Communication between the Management Console and Scanning Servers occurs over HTTPS. Scan assignments, credentials, and configuration settings are managed centrally through the Management Console.

Supported cloud services are scanned remotely through a Scanning Server. It connects through Microsoft Graph or the Google Workspace REST APIs. Remotely scanned targets can be reassigned to another Scanning Server at any time.

## Deployment and Setup Flow

Deploying GuardWare DISCOVER involves installing the Management Console and then deploying one or more Scanning Agents to perform scan operations.

{% stepper %}
{% step %}

### Install the Management Console

The first step is installing the **Management Console** on a dedicated Windows server. This system becomes the central control point for all scanning activity, including configuration, scheduling, and reporting.
{% endstep %}

{% step %}

### Deploy the Scanning Agent

After the Management Console is operational, the next step is deploying the **Scanning Agent**. Depending on the chosen architecture, this may involve installing the Scanning Agent directly on endpoints for local scanning or installing the Scanning Agent on one or more Windows systems designated as Scanning Servers for Remote Scanning.

In both cases, the Scanning Agent acts as the execution layer that carries out scan tasks assigned by the Management Console.\
[**Scanning Agent Deployment Guide→**](/getting-started/install-discover-agent/install-discover-agent.md)
{% endstep %}

{% step %}

### Configure and Run Scans

This includes adding scan targets, configuring cloud service credentials where necessary, and assigning data owners where applicable. These configurations define what will be scanned and how they should be scanned.

Scan jobs can then be created and executed from the Management Console. Results are returned and displayed within the interface, allowing you to review findings, investigate files for sensitive data, and initiate remediation actions.\
[**DISCOVER Quick Start Guide →**](/documentation/discover/getting-started/discover-quick-start-guide.md)
{% endstep %}
{% endstepper %}

## Console Access and Operation

Familiarising administrators with the Management Console is essential, as all administrative and operational tasks are performed there. Access to the console requires valid administrator credentials. After authentication, users must complete a second layer of verification using a time-based authenticator application. This ensures that access to sensitive scan data and system controls is properly secured.

![](https://4044942488-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FPtAo3ilfcIjmOhwnXZVf%2Fuploads%2Fu87eUP3ufWB3Zpng2dd5%2FUnknown%20image?alt=media\&token=b2e5b965-ae9b-4d19-a236-c34443f08800)

Once logged in, the console provides a centralised view of all scan activity, including status, results, and historical reporting. From here, administrators can manage the full lifecycle of data discovery operations.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.guardware.com/documentation/discover/about/introduction-to-discover.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
