Skip to content

Secure access

This section is the administrator’s day-to-day: register targets, control who can reach them at what level, and review what happened. It all lives in the controller’s web console.

  1. Follow the initial setup walkthrough — first login, license, SSO, first target, first grant.
  2. Add targets, or import them in bulk from one YAML file.
  3. Arrange them into projects and groups.
  4. Connect OIDC so people sign in with your identity provider, and SCIM so leavers are deprovisioned automatically.
  5. Grant access — or grant nothing and let people request it just-in-time.
  6. Turn on recording and audit review, and SIEM export where compliance needs it.

Management is split into separate permissions — grant the narrowest one that fits the role:

  • manage targets — create and edit targets, projects, groups and SSH keys.
  • manage access — grant and revoke access, review audit, manage active sessions.
  • manage users — create users, enable and disable accounts.
  • administrator — everything, including settings (OIDC, SCIM, branding, policies).

A user can never change their own permissions, and only an administrator can create another administrator. See Administrators.