The Operator's Manual — C2 Command Layer
The capstone above all six pillars: one seat that conducts the whole department. Intake from four employee doorways, visible approval gates, one living risk register, and observability into every AI channel — with the agent layer and MCP wiring that runs it.
The capstone above all six pillars — not a seventh pillar, the seat that conducts them. The managed C2 command layer is the done-for-you version.
Six capabilities are only a department if one seat conducts them. Compliance, DevSecOps, PTaaS, AI-SOC, incident response and the fractional CISO each produce signal. Without a single place to see and direct them you have six tools and no department. The operator seat is what turns capability into coordination.
The C2 console — one pane, the whole department. An intake queue where reports from every doorway land, triaged and ready for action behind a gate. Approval gates, where every consequential action — a containment, an offensive re-test, a patch merge — waits for a human click that is visible and logged. The living risk register, where findings from every arm become tracked, closing, audit-ready entries. And AI-channel observability: volume and cost per channel, prompt-injection and jailbreak watch, and escalation flow, so the autonomy is never a black box.
Four doorways, one intake. Wherever an employee already works, the security department is one click away — an intranet portal, a browser companion, a desktop tray app and an Outlook add-in, all feeding the same queue and the same AI gateway. Reporting a phish, requesting access or asking a question all land in the operator seat. Because the doorways are first-party, you can swap your SIEM or MDR and the department keeps its visibility.
Grounded in one knowledge base. An Obsidian-git vault plus IaC JSON holding assets, topology, personas, runbooks, findings and history in one schema, version-controlled for a full audit trail. Every arm reads and writes it — a pentest finding, a triaged alert and a compliance gap all land in the same vault and update the same register. It learns by accretion rather than retraining: institutional memory that grows with every engagement. And zero-trust segmentation means the AI layer can be severed in one click with production untouched — the containment guarantee.
The agent layer. Run it on an agent framework — OpenClaw, Hermes, Grok- or Claude-based — held to three invariants: one vault, one gate, full observability. The guide covers wiring it to the CISO Marketplace MCP and API data feeds, where an agent can assess posture, write findings back to your reports, source remediation across 170+ services, and draft a proposal into a Finance pipeline it is never allowed to price.
Agent wallets, and why spend becomes a control. The 2026 shift is that agents hold wallets and spend autonomously, which turns budget into a gated security control rather than a finance concern. The guide treats it that way.
On a box, if you want sovereignty. The same pattern runs on hardware you hold — Qubes laptops and Linux NUCs with hardware tokens — the approach Pillar 04's SOC in a Box takes for the SOC, applied to the operator seat.
Honest limits, stated plainly. A console, not an autopilot: it conducts and surfaces, the operator directs, and the gates exist precisely so a human stays in command. It conducts your tools rather than replacing them — it orchestrates what you already run. It is built to run solo, with a contract analyst slotting into the triage tier as volume grows and no re-architecting required.
Includes the operator console reference layout, a fillable approval-gate policy for deciding in advance what needs a human click, the knowledge-base schema with the sever procedure, an MCP connection starter, and a full operator readiness checklist.
Buy it with the pillars it conducts — it is priced as part of a programme rather than sold as an island.
Also available in 2 bundles
This product is sold on its own and as part of a set. If you need more than this one, the set is cheaper than buying the parts.
Operator on a Box
The Operator's Manual plus SOC in a Box — the command layer and the hardened machine to run it on. Sovereign by construction: your vault, your gates, your hardware. 18% off buying separately.
Complete Security Program Pillars
The whole programme — the Phase 0 assessment that scopes it, all six pillars, and the C2 command layer that conducts them — the compliance operating system, the DevSecOps risk register, the Bug-Hunter discovery layer, the PTaaS proof lane, both halves of the AI-SOC pillar, and the Fractional CISO operating system they all report into. Discovery to detection to remediation as one program. 20% off buying separately.
What's included
- PDF — fully editable
- Instant download after purchase
- Free updates — re-download when we release new versions
- Practitioner License: unlimited client use (vCISO / MSP)
Complete your toolkit
More from the CISO Marketplace ecosystem
Choose your license:
- Secure checkout via Stripe
- All major cards accepted
- 30-day satisfaction guarantee