Get started with Sencai
This path is for someone who has just created a Sencai account and has nothing set up yet: no organization, no cloud provider connected, no servers enrolled.
Work through it and you will finish with an account protected by two-factor authentication, an organization you own whose shape you chose deliberately, the vocabulary every other page in this documentation assumes you already have, and a decision about which role each of your teammates should get.
It assumes only that you can sign in at app.sencai.space and read email at the address you signed up with. You need no cloud credentials and no server for any of it - connecting infrastructure comes after this path, not during it.
Before you start
Section titled “Before you start”Have two things ready:
- An email address you can read now. Sign-up sends a verification link, and changing your address later needs a second verification at the new one.
- An authenticator app, and a backup of that app. The second step turns on TOTP two-factor authentication. Sencai issues no recovery codes, so the app’s own backup is your only fallback - arrange it before you scan the QR code, not after.
Two things may already be decided for you:
- If a teammate invited you, you are already a member of their organization and your role there was chosen by whoever sent the invitation. Creating your own organization becomes optional; every other step still applies.
- If your company uses Microsoft Entra ID or Google Workspace, sign-in may go through it. The Continue with Google and Continue with Microsoft buttons work for any account with no setup at all, but requiring SSO for a whole organization is a Business-tier feature that an Owner or Admin configures. See Single sign-on.
The path
Section titled “The path”Security comes first, while the account is still empty: switching on two-factor authentication before anything exists to protect is cheap, and retrofitting it around live infrastructure and other people’s sessions is not. Vocabulary comes next, because the organization and role pages use “member”, “cloud account” and “managed resource” as settled terms rather than stopping to define them. Then structure before people - you cannot assign a role in an organization that does not exist. The end-to-end walk sits late on purpose, so it reads as confirmation of things you already understand instead of instructions you follow blindly. The map of the application comes last, once its screen names mean something to you.
What to watch out for
Section titled “What to watch out for”Losing your authenticator locks you out of your own account. Disabling 2FA requires a currently valid code from the app, which is exactly the thing you no longer have after a lost or reset phone. There is no self-service recovery - getting back in needs your organization’s admin or Sencai support. This is the single most expensive mistake available on this path, and it costs nothing to avoid.
Decide the shape of your organization before you fill it. Merging one
organization into another and splitting one in two both live under
Settings → Org Operations (/gravity/settings/org-operations), and both
move members and instances permanently. Treat them as one-way. Related, and
smaller: there is no resend action for an invitation, so a lost or expired one
has to be revoked and sent again.
Auditor is not a promotion. It sits below Member and above Viewer in the hierarchy - Owner > Admin > Member > Auditor > Viewer - and it is read-oriented, meant for someone who needs to see your audit trail without being able to change infrastructure. Granting it expecting Admin-like reach gives that person less access than Member, not more. You pick it in the Invite member dialog like any other role; if Auditor is not among the options in your organization, ask your account team to assign it. See Roles & permissions for what each of the five roles grants.
Do not design your access model around per-resource overrides yet. The roles page describes an overlay that narrows a member’s access to billing, AI features, instances, the audit log, or fleet management. Two limits matter: it can only subtract access within a role, never add capability the role lacks, and there is no self-service screen for it today - configuring it goes through your account team or the API. Pick the right role instead.
A trial that ends quietly changes what you can do. Every new organization starts on a 14-day trial. When it lapses, an Owner has to choose a plan before inviting members, changing organization settings, or creating instances works again. Nothing is deleted, and read-only screens plus checkout stay reachable throughout. See Billing overview.
Two sidebar groups use the same words for different things. The last step
maps the whole application, and you will meet “Networks” and DNS twice.
Live cloud → Networks (/gravity/live-cloud/networks),
Live cloud → Firewalls (/gravity/live-cloud/firewalls) and
Live cloud → DNS (/gravity/live-cloud/dns) change real infrastructure
in your provider account. Their coverage differs: Networks is Hetzner Cloud
only, Firewalls adds AWS, and DNS also covers Azure, Google Cloud and
Cloudflare.
Networking & Edge → Networks (/gravity/networks) writes a planning record
in Sencai that touches nothing at your provider, and
Networking & Edge → DNS Zones (/gravity/dns) is an explicit placeholder
screen. Always read the group name, never the item name alone - see
Networks & connectivity and DNS.
What’s next
Section titled “What’s next”- Connect a cloud provider - the usual next move once the organization exists and roles are settled
- Fleet agent enrollment - the other first move, for a server you already have and no cloud account at all
- Billing overview - choose the organization’s plan before its trial lapses, and see how it differs from your personal one
- Learning paths - the other reading orders, once this one is done