Skip to content

Get started with Sencai

This path is for someone who has just created a Sencai account and has nothing set up yet: no organization, no cloud provider connected, no servers enrolled.

Work through it and you will finish with an account protected by two-factor authentication, an organization you own whose shape you chose deliberately, the vocabulary every other page in this documentation assumes you already have, and a decision about which role each of your teammates should get.

It assumes only that you can sign in at app.sencai.space and read email at the address you signed up with. You need no cloud credentials and no server for any of it - connecting infrastructure comes after this path, not during it.

Have two things ready:

  • An email address you can read now. Sign-up sends a verification link, and changing your address later needs a second verification at the new one.
  • An authenticator app, and a backup of that app. The second step turns on TOTP two-factor authentication. Sencai issues no recovery codes, so the app’s own backup is your only fallback - arrange it before you scan the QR code, not after.

Two things may already be decided for you:

  • If a teammate invited you, you are already a member of their organization and your role there was chosen by whoever sent the invitation. Creating your own organization becomes optional; every other step still applies.
  • If your company uses Microsoft Entra ID or Google Workspace, sign-in may go through it. The Continue with Google and Continue with Microsoft buttons work for any account with no setup at all, but requiring SSO for a whole organization is a Business-tier feature that an Owner or Admin configures. See Single sign-on.

Security comes first, while the account is still empty: switching on two-factor authentication before anything exists to protect is cheap, and retrofitting it around live infrastructure and other people’s sessions is not. Vocabulary comes next, because the organization and role pages use “member”, “cloud account” and “managed resource” as settled terms rather than stopping to define them. Then structure before people - you cannot assign a role in an organization that does not exist. The end-to-end walk sits late on purpose, so it reads as confirmation of things you already understand instead of instructions you follow blindly. The map of the application comes last, once its screen names mean something to you.

0 of 7 read

  1. Open
  2. Open
  3. Open
  4. Open
  5. Open
  6. Open
  7. Open

Losing your authenticator locks you out of your own account. Disabling 2FA requires a currently valid code from the app, which is exactly the thing you no longer have after a lost or reset phone. There is no self-service recovery - getting back in needs your organization’s admin or Sencai support. This is the single most expensive mistake available on this path, and it costs nothing to avoid.

Decide the shape of your organization before you fill it. Merging one organization into another and splitting one in two both live under Settings → Org Operations (/gravity/settings/org-operations), and both move members and instances permanently. Treat them as one-way. Related, and smaller: there is no resend action for an invitation, so a lost or expired one has to be revoked and sent again.

Auditor is not a promotion. It sits below Member and above Viewer in the hierarchy - Owner > Admin > Member > Auditor > Viewer - and it is read-oriented, meant for someone who needs to see your audit trail without being able to change infrastructure. Granting it expecting Admin-like reach gives that person less access than Member, not more. You pick it in the Invite member dialog like any other role; if Auditor is not among the options in your organization, ask your account team to assign it. See Roles & permissions for what each of the five roles grants.

Do not design your access model around per-resource overrides yet. The roles page describes an overlay that narrows a member’s access to billing, AI features, instances, the audit log, or fleet management. Two limits matter: it can only subtract access within a role, never add capability the role lacks, and there is no self-service screen for it today - configuring it goes through your account team or the API. Pick the right role instead.

A trial that ends quietly changes what you can do. Every new organization starts on a 14-day trial. When it lapses, an Owner has to choose a plan before inviting members, changing organization settings, or creating instances works again. Nothing is deleted, and read-only screens plus checkout stay reachable throughout. See Billing overview.

Two sidebar groups use the same words for different things. The last step maps the whole application, and you will meet “Networks” and DNS twice. Live cloud → Networks (/gravity/live-cloud/networks), Live cloud → Firewalls (/gravity/live-cloud/firewalls) and Live cloud → DNS (/gravity/live-cloud/dns) change real infrastructure in your provider account. Their coverage differs: Networks is Hetzner Cloud only, Firewalls adds AWS, and DNS also covers Azure, Google Cloud and Cloudflare. Networking & Edge → Networks (/gravity/networks) writes a planning record in Sencai that touches nothing at your provider, and Networking & Edge → DNS Zones (/gravity/dns) is an explicit placeholder screen. Always read the group name, never the item name alone - see Networks & connectivity and DNS.

  • Connect a cloud provider - the usual next move once the organization exists and roles are settled
  • Fleet agent enrollment - the other first move, for a server you already have and no cloud account at all
  • Billing overview - choose the organization’s plan before its trial lapses, and see how it differs from your personal one
  • Learning paths - the other reading orders, once this one is done