Account security and two-factor authentication
Console accounts control backups and the storage behind them, so they deserve the same care as an admin account anywhere. Here is what the platform provides and what to switch on.
Two-factor authentication #
- Your name → Two-factor authentication → Set up. Scan the QR code with any authenticator app (Microsoft Authenticator, Google Authenticator, 1Password…) — it is standard TOTP.
- Enter the six-digit code to confirm. From then on sign-in asks for a code after the password.
- Save the recovery codes shown once at set-up. Each works one time when the phone is lost; regenerate them from the same screen if they run out.
An administrator can reset a user's two-factor from the Users page when both phone and codes are gone; the reset is written to the audit trail.
Signing in with Microsoft or Google #
The console accepts sign-in with a Microsoft work account or a Google account. Caryvane receives only the account's identifier and email; passwords stay with the provider, and that provider's own MFA applies. An account created this way has no Caryvane password.
The other credentials #
- Deployment tokens enrol machines: single-use and short-lived by default, revocable, and shown with their install command once. See Deployment tokens.
- Machine tokens are what an enrolled agent uses; they are bound to the machine's hardware fingerprint and useless on another machine.
- AI access keys are per user, tiered (read, control, edit, full), shown once, and act as their owner with their owner's visibility. See Keys.
- Storage credentials and connector tokens are encrypted at rest and never shown again after entry.
Who sees what #
Visibility follows the customer hierarchy and the user's role, enforced on the server for every request — console, API and MCP alike. An MSP admin cannot see another MSP's customers, or the distributor's rates; a customer user cannot see beyond their tenant; a job cannot read one customer's storage and write another's. See Roles.
What is logged #
Every sign-in, every change to a job, target, user, token or key, every archive rule and every AI-key action is written to the audit trail with who, when and from where.