CaryvaneHelp
/

Account security and two-factor authentication

Console accounts control backups and the storage behind them, so they deserve the same care as an admin account anywhere. Here is what the platform provides and what to switch on.

Two-factor authentication #

  1. Your name → Two-factor authentication → Set up. Scan the QR code with any authenticator app (Microsoft Authenticator, Google Authenticator, 1Password…) — it is standard TOTP.
  2. Enter the six-digit code to confirm. From then on sign-in asks for a code after the password.
  3. Save the recovery codes shown once at set-up. Each works one time when the phone is lost; regenerate them from the same screen if they run out.

An administrator can reset a user's two-factor from the Users page when both phone and codes are gone; the reset is written to the audit trail.

Signing in with Microsoft or Google #

The console accepts sign-in with a Microsoft work account or a Google account. Caryvane receives only the account's identifier and email; passwords stay with the provider, and that provider's own MFA applies. An account created this way has no Caryvane password.

The other credentials #

Who sees what #

Visibility follows the customer hierarchy and the user's role, enforced on the server for every request — console, API and MCP alike. An MSP admin cannot see another MSP's customers, or the distributor's rates; a customer user cannot see beyond their tenant; a job cannot read one customer's storage and write another's. See Roles.

What is logged #

Every sign-in, every change to a job, target, user, token or key, every archive rule and every AI-key action is written to the audit trail with who, when and from where.