Skip to content

First Access

When a resource is added and no people are linked yet, nobody can pass MFA on it — including the founder. This is intentional: access is explicit, never assumed. The panel calls this state First Access and guides you through it.

On the resource page, the First Access callout offers Connect myself:

  1. Pick the Windows account you sign in with on that machine (e.g. Administrator).
  2. If you haven’t enrolled an authenticator yet, scan the QR shown right there.
  3. Verify with a code — done. You are now linked, and once MFA is enforced you can sign in with your own factor.

The panel shows a clear badge on resources still waiting for their first person, so an accidentally enforced-but-empty machine can’t hide.

On a domain controller, Connect myself is intentionally unavailable. Add the Windows account manually and send yourself (or the responsible admin) a normal invitation instead.

Deriving access from existing Windows usernames would silently grant people you never chose. First Access keeps the rule consistent: a machine has zero relationships until someone explicitly creates them — safe for you on day one, and safe at fleet scale.