What do you need help with?

We are here and ready to help.
Email: servicedesk@socfortress.co

Creating Your Shuffle Account

Creating Your Shuffle Account (SOCFortress Hybrid SOAR Setup)

Category: SOAR / Shuffle / Onboarding Applies to: Customers using the SOCFortress SIEM stack with Shuffle automation Audience: Customer administrators setting up Shuffle for the first time


Overview

Shuffle is the open-source SOAR (Security Orchestration, Automation, and Response) platform that powers automation in your SOCFortress stack — things like alert enrichment, phishing analysis, notifications, and routine workflows.

SOCFortress uses a hybrid Shuffle architecture:

  • Shuffle Cloud (public) — the control plane where workflows are built, managed, and orchestrated, hosted and maintained by the Shuffle team at shuffler.io.
  • Local Shuffle runner (Orborus) — a lightweight component we deploy inside your environment. Think of Orborus like a worker container: it executes the workflows locally, which lets it securely reach your internal SIEM stack and any other on-prem technologies, while the cloud handles orchestration.

In short: the "brain" lives in Shuffle Cloud, and the local Orborus runner is the "hands" that reach into your environment to get work done.


Why this hybrid architecture

This model is a great fit for the SOCFortress stack for a few reasons:

  • Always up to date — the Shuffle team ships improvements and new integrations at a very high pace. Using the cloud control plane means you're always on the latest capabilities without you having to manage upgrades.
  • Lighter infrastructure footprint — the heavy orchestration layer runs in Shuffle Cloud, so the load on your own infrastructure stays light. The only local piece is the small Orborus runner.
  • Fully open source, multi-tenant — Shuffle remains fully open source, and the platform supports multi-tenancy, so it scales cleanly across clients and environments.

Prerequisites

  • A business email address to register the account.
  • Admin access to invite additional users to the organization once it's created.

Step 1 — Register your Shuffle account

  1. Go to https://shuffler.io/register.
  2. Register using your business email address and set a password.
  3. Verify your email if prompted, and log in to your new organization.

This creates your organization in Shuffle Cloud, which becomes the control plane for your automation.


Step 2 — Local Shuffle runner (Orborus) — handled by SOCFortress

You do not need to deploy anything for this step. As part of your stack deployment, SOCFortress installs and configures the local Shuffle runner (Orborus) inside your environment and connects it to your Shuffle Cloud organization. This is what allows workflows to securely reach your internal SIEM and other tools.


Step 3 — Invite the SOCFortress team as admins

So we can build and manage your automation, please invite the following SOCFortress team members to your Shuffle organization with the Admin role:

  • taylor.walton@socfortress.co
  • amine.moussa@socfortress.co
  • juan.romero@socfortress.co

How to invite users in Shuffle:

  1. Log in to your Shuffle organization at shuffler.io.
  2. Open the Admin / Organization settings (usually via the gear/organization menu).
  3. Go to the Users section.
  4. Add each email address above and assign the Admin role.
  5. Send the invites — the team will accept and confirm access.

What happens next

Once your account is created, Orborus is connected (by us), and the SOCFortress team has admin access, we'll begin building and wiring up your workflows — connecting your SIEM stack to the automations and integrations you need.


Notes & FAQ

  • Is my data safe with the cloud control plane? Workflow orchestration runs in Shuffle Cloud, but execution happens locally via Orborus inside your environment, so sensitive actions and connections to internal systems stay on your side.
  • Do I have to maintain Shuffle? No — the cloud platform is maintained by the Shuffle team, and SOCFortress manages the local Orborus runner and your workflows.
  • Why admin role for SOCFortress? Admin access is required for us to create, edit, and troubleshoot workflows and integrations on your behalf.

References

  • Shuffle registration — https://shuffler.io/register
  • Shuffle platform — https://shuffler.io/
  • Shuffle documentation — https://shuffler.io/docs
Facebook Share Tweet

Was this article helpfu?

Yes No

Thank you for voting

×
Select company

You are related to multiple companies. Please select the company you wish to login as.