Help & support
Everything you need to run your first tabletop exercise — from setting up a workspace to generating an after-action report. New here? Start at the top.
§01Getting started
From a standing start to your first after-action report in five steps:
- Create your account and confirm your email — or sign in with a FerrumSec ID.
- Create an organization (your workspace). MSPs and consultants can add client workspaces under their account.
- Pick a scenario template and schedule it as an exercise.
- Facilitate the exercise — release injects on the timeline and capture the team's decisions and observations as you go.
- Generate the after-action report to review performance, gaps, and the improvement actions your team agreed.
§02Key concepts
A quick glossary of the building blocks you'll see across ResponseLab:
- Organization
- Your workspace. All exercises, members, and data live inside an organization and are isolated from every other one.
- Scenario template
- A reusable incident exercise design — the storyline, timed injects, roles, and scoring guidance you run an exercise from.
- Exercise
- A scheduled tabletop run based on a scenario template, with its own participants, timeline, and captured results.
- Inject
- A timed event or update the facilitator releases during an exercise to drive the next decision.
- Role
- A participant function such as Incident Commander, IT Lead, Legal, Communications, or Executive Sponsor.
- Decision
- An action a participant or facilitator chooses in response to an inject — captured with its rationale.
- Observation
- A note, strength, gap, or facilitator comment recorded during or after the exercise.
- Action item
- An improvement task created from a gap — with an owner, priority, and due date.
- After-action report
- The PDF/HTML summary of an exercise: performance, readiness scores, gaps, and the improvements to make next.
§03Running an exercise
Open an exercise to reach the live room. As facilitator you release injects along the timeline; for each, capture the team's decision and the rationale behind it. Add observations whenever you spot a strength or gap. When the scenario is complete, mark the exercise Completed — this unlocks scoring and the after-action report.
Keep everything fictional. ResponseLab is a rehearsal tool: use invented organizations and artifacts, never a real, in-progress incident's confidential details.
§04Inviting your team
From your organization's page, invite teammates by email. Each invitee receives a branded email with a unique accept link; opening it and signing in adds them to the workspace with the role you chose. If an email doesn't arrive, an admin can copy the invite link straight from the pending-invitation list and share it directly.
§05Scores & reports
After an exercise, record readiness scores across the response categories (detection and escalation, containment, communications, recovery, governance, and more). ResponseLab combines them into an overall grade. Generate the after-action report to get a shareable summary — performance, captured decisions and observations, the readiness breakdown, and the action items your team will follow up on. Reports can be viewed in the browser or downloaded as a PDF.
§06Roles & access
What each organization role can do:
- Owner / Admin — manage the organization, members, and invitations; run exercises and generate reports.
- Facilitator — schedule and run exercises, capture decisions and observations, and generate reports.
- Participant — take part in exercises in their assigned role.
- Viewer — read-only access to exercises and reports.
- MSP admin — manage client workspaces under a parent (MSP) organization.
§07Troubleshooting
I didn't receive an invitation or verification email
Check spam, and confirm the address is correct. For invitations, an admin can copy the accept link from the pending-invitation list and send it to you directly.
I can't sign in
Use Forgot your password? on the sign-in page to reset it, or sign in with your FerrumSec ID. If your account was disabled by an admin, contact them to restore access.
The "Generate report" button isn't available
Reports are generated from a completed exercise — finish the live room first. After generating, the report may take a moment to render its PDF; the page updates when it's ready.
§08Contact support
Still stuck? Your workspace administrator can help with members and access. For anything else, email us at hello@ferrumsec.com — we read every message during the beta. See also the Terms of Use and Privacy Policy.