This guide walks you through setting up your Sudory account end to end: your organization, your team's sign-in security, who can see and change what, giving your auditor visibility, running your first scan, connecting your first integration, and reading the compliance baseline it produces. Each step is something you do yourself, in order, inside the product.
Time needed: about 25 minutes, plus the time it takes your invited teammates and auditor to accept their invitations, and whatever a connected provider's own setup screen asks of you.
Already have a login? If we've already created your organization and invited you as its Owner, your account exists: start at Step 2. If you're starting from a blank signup page, begin at Step 1.
Find it in your browser's address bar once you're signed in (/accounts/@your-handle/…), or leave this blank and follow the {your-org} links to your account list instead.
Sign up, then name your organization
/auth/signup → /accounts/create
@your-org) that you can adjust before continuing.
Why it matters
Every piece of data in Sudory, every integration, every finding, belongs to exactly one organization. This is the workspace the rest of this guide sets up.
Settings → Security
/enroll-mfa · /accounts/{your-org}/settings/security

Why it matters
MFA is one of the first things an auditor checks. Turning it on here, before you invite anyone else, means every teammate enrolls as part of accepting their invitation instead of as a separate ask later.
This setting governs browser sign-ins. Any long-lived API key your team creates for automation authenticates on its own and isn't affected by it.
Settings → Members
/accounts/{your-org}/settings/members
/accounts/{your-org}/settings/roles) with only the permissions it needs.
Why it matters
Getting roles right up front is what makes the next step, inviting an outside auditor, safe: they only ever see what their role allows.
Settings → Members
/accounts/{your-org}/settings/members

Why it matters
An external auditor needs to see your compliance posture, not operate your account. Viewer access gives them exactly that, without a separate role to configure.
Domains → Add a domain

Why it matters
The public scan is the fastest way to see Sudory working: no setup beyond a domain name, and results within moments.
Apps and integrations

Why it matters
The public scan from Step 5 is a snapshot of what's visible from outside. Connecting an integration is what turns that into ongoing, scheduled coverage of the systems you actually run.
Only an Owner or Manager can connect a new integration; a Viewer, including your auditor, can see what's connected but can't add one — the roles you set up in Step 3 already cover this.
Posture

Why it matters
You can't show improvement without a starting point. This is it — and it's also the first thing worth sharing with your auditor once they've accepted their invitation.
Choose a compliance framework to track against (ISO 27001, SOC 2, NIS2, GDPR, and others) and Sudory maps your findings to its controls automatically.
Each integration you connect under Integrations extends your deep scan coverage beyond the public scan from Step 5.
As scans and integrations run, Sudory populates your asset inventory automatically, ready for risk and vendor tracking.