Onboarding

Getting Started with Sudory

This guide walks you through setting up your Sudory account end to end: your organization, your team's sign-in security, who can see and change what, giving your auditor visibility, running your first scan, connecting your first integration, and reading the compliance baseline it produces. Each step is something you do yourself, in order, inside the product.

  1. 1Organization
  2. 2MFA
  3. 3Roles
  4. 4Auditor
  5. 5Public scan
  6. 6Connector
  7. 7Baseline

Time needed: about 25 minutes, plus the time it takes your invited teammates and auditor to accept their invitations, and whatever a connected provider's own setup screen asks of you.

Already have a login? If we've already created your organization and invited you as its Owner, your account exists: start at Step 2. If you're starting from a blank signup page, begin at Step 1.

@

Find it in your browser's address bar once you're signed in (/accounts/@your-handle/…), or leave this blank and follow the {your-org} links to your account list instead.

1

Create your organization

Sign up, then name your organization

/auth/signup/accounts/create

  1. Go to the Sudory sign-up page and create your user with your work email.
  2. Choose a name for your organization. Sudory generates a short handle for it (like @your-org) that you can adjust before continuing.
  3. You land in your new account as its Owner — the role with full control, including billing and the ability to delete the account.
The Create organization form, with fields for organization name and handle.
Create organization — name it and choose its handle.

Why it matters

Every piece of data in Sudory, every integration, every finding, belongs to exactly one organization. This is the workspace the rest of this guide sets up.

2

Turn on multi-factor authentication

Settings → Security

/enroll-mfa · /accounts/{your-org}/settings/security

  1. Enroll your own account: open an authenticator app, scan the QR code Sudory shows you, and save the recovery codes it gives you somewhere safe.
  2. As Owner, turn on Require MFA in Settings → Security. Every member of your organization will need to enroll their own authenticator before they can sign back in.
Settings, Security page, with the Require MFA for all members toggle.
Settings → Security — Require MFA for all members.

Why it matters

MFA is one of the first things an auditor checks. Turning it on here, before you invite anyone else, means every teammate enrolls as part of accepting their invitation instead of as a separate ask later.

This setting governs browser sign-ins. Any long-lived API key your team creates for automation authenticates on its own and isn't affected by it.

3

Set up roles and invite your team

Settings → Members

/accounts/{your-org}/settings/members

  1. Decide who needs what: Owner (full control, billing included), Manager (day-to-day work, no billing or role changes), or Viewer (read-only, no billing).
  2. If none of those fit a team's responsibilities exactly, define a custom role under Settings → Roles (/accounts/{your-org}/settings/roles) with only the permissions it needs.
  3. Invite each teammate by email from Settings → Members. They receive a link to accept and, once MFA is required, to enroll.
Settings, Roles page, listing the Manager, Owner and Viewer system roles with their permission counts.
Settings → Roles — Manager, Owner and Viewer, with what each one grants.

Why it matters

Getting roles right up front is what makes the next step, inviting an outside auditor, safe: they only ever see what their role allows.

4

Invite your auditor, read-only

Settings → Members

/accounts/{your-org}/settings/members

  1. Invite your auditor the same way as any teammate, from Settings → Members.
  2. Every invitation is granted the Viewer role by default: full visibility into findings, controls, and evidence, with no ability to change anything and no access to billing.
  3. If their responsibilities ever grow beyond that, an Owner can upgrade their role later from the same screen.
Settings, Members page, with pending invitations and a members table showing name, email and role.
Settings → Members — the same screen you used in Step 3, once more for your auditor.

Why it matters

An external auditor needs to see your compliance posture, not operate your account. Viewer access gives them exactly that, without a separate role to configure.

5

Run your first public scan

Domains → Add a domain

/accounts/{your-org}/domains

  1. Add your primary domain under Domains. Sudory scans what's publicly visible about it — DNS records, email-security configuration, website headers — without needing any credentials from you.
  2. When you're ready to go further, connect an integration (your cloud provider, identity provider, and so on) under Integrations. Those run deeper, scheduled scans against systems that do require credentials.
The Domains page, listing an added domain marked Monitored.
Domains — your domain, added and monitored.

Why it matters

The public scan is the fastest way to see Sudory working: no setup beyond a domain name, and results within moments.

6

Connect an integration

Apps and integrations

/accounts/{your-org}/apps

  1. Open Apps and integrations and pick a provider: your cloud account, identity provider, or another system you run.
  2. Follow that provider's own setup. Most connect through a temporary, revocable access role you create yourself; others use that provider's own sign-in and consent screen. Either way, nothing long-lived is handed over up front.
  3. Once connected, Sudory runs a scheduled deep scan against it automatically, on top of the public scan from Step 5.
The Apps and integrations page, listing providers with their category and authentication method.
Apps and integrations — search or browse, then pick a provider.

Why it matters

The public scan from Step 5 is a snapshot of what's visible from outside. Connecting an integration is what turns that into ongoing, scheduled coverage of the systems you actually run.

Only an Owner or Manager can connect a new integration; a Viewer, including your auditor, can see what's connected but can't add one — the roles you set up in Step 3 already cover this.

7

Read your baseline

Posture

/accounts/{your-org}/posture

  1. Once your public scan and connected integration finish scanning, open Posture to see your findings grouped by family: Security, Privacy, Accessibility.
  2. This first result is your baseline — the starting picture of where things stand today.
  3. From here, every framework you adopt, every further integration you connect, and every finding you resolve moves you forward from this baseline, and you'll be able to see that progress over time.
The Posture page, findings grouped by family such as Identity and Access, each check marked pass or fail.
Posture — your findings, grouped by family. This is your baseline.

Why it matters

You can't show improvement without a starting point. This is it — and it's also the first thing worth sharing with your auditor once they've accepted their invitation.

What's next

Adopt a framework

Choose a compliance framework to track against (ISO 27001, SOC 2, NIS2, GDPR, and others) and Sudory maps your findings to its controls automatically.

Connect more integrations

Each integration you connect under Integrations extends your deep scan coverage beyond the public scan from Step 5.

Build your asset inventory

As scans and integrations run, Sudory populates your asset inventory automatically, ready for risk and vendor tracking.

Questions at any step? Reach out to your Sudory contact and we'll walk through it with you.