Skip to content

Signing in and roles

Signing in

Sign in with your work email and password. After five wrong passwords the account is locked for 15 minutes, and every sign-in, failure and lockout is recorded in the audit log.

Sessions end after 60 minutes of inactivity and after 12 hours at most. Owners and admins can change both limits in Settings → Organization. Changing your password signs out your other sessions.

Two-factor authentication

  1. Open Account (your name at the top right).
  2. Under Two-factor authentication, confirm your password and scan the QR code with an authenticator app (1Password, Microsoft Authenticator, Google Authenticator or similar).
  3. Enter the 6-digit code to enable it.

From then on, sign-in asks for a code after your password. Each code can be used only once.

TIP

Require two-factor authentication for everyone. In Settings → Organization → Console sessions, owners and admins can require it for all admins. You must have it enabled yourself first. Admins without it can then only set it up until they do.

Lost access

  • Forgot your password or lost your authenticator? Ask an owner or admin to reset it in Settings → Admins. You get a temporary password and must choose a new one at the next sign-in.
  • No owner can sign in? The server operator can run sentinel admin reset-password --email you@example.com on the server (see Command reference).

Roles

Give each person the least privileged role that fits their work. Invite colleagues in Settings → Admins. Sentinel shows a temporary password once, and the new admin must change it at first sign-in.

AreaOwnerAdminAnalystAuditor
View overview, alerts, findings, endpoints, policies, integrations, settings, audit log
Triage alerts (status, assignment, comments)
Request and open evidence
Manage rules and fingerprint documents
Manage people, devices, groups, enrollment codes
Manage integrations and organisation settings
Invite and manage admins, analysts, auditors
Manage owners, keys and license
View system status, verify and export the audit log
Reveal pseudonymised people

Sensitive actions ask for your password again: license upload, key operations, role changes, and password or two-factor resets for others.

NOTE

With Pseudonymise people for analysts enabled in Settings → Privacy, analysts see a pseudonym (for example P-7K2Q9M4A) instead of names and email addresses, including in the audit log. Owners and admins can reveal a person when an investigation requires it, and the reveal is audited.

Klipsu Sentinel is a product of Lygon Software · enterprise@klipsu.com