Troubleshooting
Diagnose common Orthalon sign-in, organization, sensor, policy, connector, and plan-access problems.
You do not have access to this organization
Confirm that the URL belongs to an organization of which the signed-in account
is a current member. Switch organizations from /app, accept any pending
invitation, or ask an administrator to restore membership. Signing in
successfully does not grant access to every organization.
If the error appears immediately after membership or organization changes, refresh the session and return through the organization selector instead of an old bookmarked slug.
Sensor policy refresh returns 401
The configured sensor credential is not valid for the ingest service.
- Sign in to the web app and create or select the organization.
- Provision a key under Sensors & keys.
- Copy the real one-time value into the agent or extension configuration.
- Confirm the installed browser/endpoint artifact was built for the same Orthalon environment. End users do not enter a service URL.
- Restart the sensor.
A random string is not a valid sensor key. Also check whether an administrator revoked or rotated the original.
A feature returns 403
A 403 normally means the account or organization is authenticated but lacks a role or plan entitlement. Verify:
- the selected organization;
- member versus administrator role;
- current plan under Organization billing;
- seat or subscription state;
- whether the capability is Enterprise-only.
Policy changes do not reach a sensor
Confirm the policy saved successfully, a newer bundle version exists, the sensor key is active, and the device can reach the policy endpoint. Check the sensor's reported policy version before reinstalling it.
A connector cannot sync
- 401: invalid or expired provider credential.
- 403: missing provider permission/admin consent or an Orthalon Enterprise gate.
- Orthalon decryption error: web and background worker encryption keys differ.
- No matched apps: provider records did not match catalog domains or unambiguous names.
Replace the complete connector configuration when rotating a secret because saved secrets are intentionally not returned to the browser.
Events are missing
Check the coverage layer first: active browser adapter, correct desktop/gateway base URL, healthy sensor check-in, and correct organization. A quiet dashboard can mean no events, but it can also mean the traffic never crossed an enrolled Orthalon surface.