1. Your account

Accounts are provisioned to your organisation and tied to your work email. There is no

self-service signup; if you need access, ask your administrator to invite you.

  1. You receive an invitation email from no-reply@darkcoders.io.
  2. Click Accept invitation within 7 days (links expire).
  3. Set your display name and confirm your role.

2. Signing in (SSO)

The platform is federated with your organisation's identity provider (Okta, Azure AD / Entra ID,

Google, or Keycloak). Choose Sign in with SSO, enter your work email, and you are redirected to

your company login.

(and vice versa). Close your browser on shared devices.

3. Enrolling MFA (required)

  1. Go to Settings -> Security -> Multi-factor authentication.
  2. Add a passkey / WebAuthn factor first (fastest, phishing-resistant).
  3. Add a TOTP authenticator as a fallback.
  4. Generate backup codes and store them in your password manager.

See the MFA troubleshooting article if you hit problems.

4. Finding your way around

AreaWhat it isWhere
DashboardsPosture, risks, incidents, KPIsPortal home
Approval queueItems awaiting your decisionPortal -> Approvals
Your inboxPersona mail + notificationsPortal -> Inbox
DocumentsPolicies, procedures, attestationsPortal -> Documents
HelpThis guide + KB articlesdocs.darkcoders.io

5. Roles at a glance

Your role determines what you can see and do. Roles are assigned by your administrator.

RoleTypical userCan do
ViewerAny staffRead dashboards, policies, KB
AnalystSecurity teamTriage alerts, run lookups, file incidents
ApproverManagersApprove/reject gated actions, accept risks
AdministratorPlatform/ITFull configuration, users, integrations

administrator rather than sharing a colleague's account.

← End-User Guide  ·  All guidelines