Documentation

Website Watch

Set up always-on monitoring for one HTTPS origin: daily pulse, weekly Standard or Deep scan, and email when something new appears.

Who This Topic Is For

Site owners and agencies who need continuous visibility on a public HTTPS origin without spending scan credits on the included cadence.

Prerequisites

Before You Start

Use this checklist to make sure the workflow guidance applies cleanly to your current task.

  • You own the website or are authorized to monitor it.
  • The origin is reachable over HTTPS (example: https://shop.example.com).
  • You can complete Stripe checkout for each watched site if you do not already have an unused Watch seat.
Expectations

What To Expect

Use this section to set the right outcome before you start the workflow.

Standard or Deep at add-site, then locked

Pick Standard or Deep when you add the site. Daily pulse is the same on every seat. Quick and Comprehensive are not Watch tiers. Comprehensive, one-off dashboard scans, and add-ons stay on credits from the dashboard or Scheduled Scans.

Credits are not used for included runs

Paid active watches keep running at zero credits. The pulse and weekly Standard or Deep scan are part of the Watch seat. Manual dashboard scans still use credits as usual.

Alerts on change, not every run

The first successful runs establish a baseline and do not flood your inbox. Later runs email you when a new or worsened finding appears, the score drops past your threshold, or the certificate hits a 30, 14, 7, or expired window.

One seat per site

Standard is $29 per site per month ($290/year). Deep is $49 ($490/year). Quantity equals occupied seats of that depth. Unused Standard seats do not cover a Deep origin. Pause keeps the seat. Cancel drops the seat at period end. There is no volume discount and Watch is not gated on Pro.

Playbook

Step-By-Step Guidance

Follow these steps in order for a reliable and repeatable outcome.

  1. Open Watch from the dashboard.

    Sign in and go to /watch. The Watch item sits next to Scheduled in dashboard navigation.

    The dashboard also has a Watch card that shows how many sites you are watching.

  2. Add the HTTPS origin.

    Enter a short name such as Shop production, the HTTPS URL, monthly or yearly billing, and Standard or Deep.

    Click Watch website. If you already have an unused paid seat of that same depth, the site attaches to it.

    If not, Stripe Checkout opens so you can add a seat.

  3. Complete payment, then wait for the baseline.

    After checkout, the watch shows as pending_payment then active.

    The first pulse and first weekly Standard or Deep scan create a baseline. You should not expect an alert for every finding that already existed on day one.

    Open the watch detail to see last pulse time, last weekly scan, and certificate days remaining.

  4. Tune alerts before you treat Watch as production.

    On the watch detail page, set New findings, Resolved findings, Score drop, score-drop threshold, and minimum severity. Add quiet hours in 24-hour time such as 22:00 to 07:00, a timezone such as America/New_York, and up to five extra email recipients.

    Enable Weekly digest if you want a Monday 09:00 summary in that timezone.

  5. Mute known noise, then pause or cancel with intent.

    Mute an open issue when it is accepted risk or a staging quirk.

    Muted fingerprints stop repeating in delta alerts. Click Unmute on that open-issue row, or in Muted issues, when you want alerts again.

    Pause if you want monitoring off but the seat still occupied. Cancel if you want the seat to drop at period end.

    Run pulse now is limited to once per 15 minutes. Run weekly Standard now or Run weekly Deep now is limited to once per 6 hours.

  6. Keep Scheduled Scans for custom cadence.

    Watch is the change-detection SKU.

    Scheduled Scans remain the Pro-plus credit product when you need Comprehensive or a custom calendar. A pentest is a separate paid engagement.

    Use Watch between those deeper tests, not instead of them.

Examples

Worked Examples

These scenarios show how the workflow looks in practice, including the result you should see.

Agency watching five client shops

Northwind Security adds five HTTPS origins on monthly Standard. Stripe quantity becomes five. Occupied seats show as Watching 5 of 5 sites. Included pulses and weekly Standard runs do not consume the agency credit balance. A sixth origin at Deep starts a separate $49 checkout.

Five Standard seats: $145 per month. Mix in Deep at $49 each. Each client site has its own watch, alerts, and mutes.

Certificate entering the 14-day window

A pulse reports 12 days until notAfter. Watch records the tightest matching window (14 days, not 30) and sends a cert alert if that window has not already been sent. Quiet hours delay the email until 07:00 in the watch timezone.

You receive one cert-window alert for 14 days, then later 7 days, then expired if it is not renewed.

Mute a known header gap on staging

Staging is missing HSTS on purpose. The issue appears under Open issues. You click Mute. The row shows a Muted pill and Unmute. Later pulses still see the header gap, but that fingerprint is excluded from new-finding alerts. When staging should alert again, click Unmute.

Inbox stays quiet for the muted item. Unmute restores alerts for that fingerprint without changing other mutes.

Launch freeze without losing the seat

The shop pauses Watch during a holiday freeze. Status becomes paused. Occupied seats still count that site, so billing quantity does not drop. After the freeze, Resume starts pulses again from the last baseline.

No daily emails during pause. The seat is still paid until you cancel.
Validation

Validation Checklist

Use this checklist to confirm the workflow was completed correctly.

  • The watch URL is HTTPS and the status is active.
  • Last pulse and next pulse times appear on the watch card.
  • Alert checkboxes, timezone, and quiet hours match how the team works.
  • Known accepted findings are muted instead of generating repeat mail, and Unmute is available on the same watch page.
  • You can explain the difference between Watch, Scheduled Scans, and a pentest.
Troubleshooting

Common Problems And Fixes

If something does not match expectation, check these common failure modes first.

Using HTTP or a path that is not the origin

Watch monitors one HTTPS origin. Use https://shop.example.com rather than http:// or a deep path. If checkout is refused, confirm the URL is publicly reachable over TLS.

Common failure mode

Expecting Quick or Comprehensive inside Watch

Watch offers Standard or Deep for the weekly scan, chosen when you add the site. Quick and Comprehensive stay on the dashboard with credits. Scheduled Scans remain the custom-calendar credit path.

Common failure mode

Treating pause and cancel as the same action

Pause stops runs but keeps the paid seat. Cancel ends the watch and drops the seat at period end without a mid-cycle refund.

Common failure mode

Assuming zero credits will block Watch

Included Watch runs skip credit deduction. Zero credits still fire pulse and weekly Standard or Deep on a paid active watch.

Common failure mode
FAQ

Website Watch FAQs

Common questions for this topic.

No. Included daily pulse and weekly Standard or Deep runs always fire on a paid active watch, even at zero credits. Comprehensive, one-off dashboard scans, and add-ons stay on credits.

Next Recommended Action

Continue to the best next page based on where you are in your workflow.