Skip to content

Your first 30 minutes

By the end of this tutorial you have a verified Sencai account protected by two-factor authentication, an organization you own, a working understanding of what each role grants, and - the part most people find out too late - the plan limits that decide whether you can invite anyone into that organization at all. Allow about 30 minutes, a chunk of it spent waiting for one verification email.

Everything here happens in the application at app.sencai.space. This documentation site is a separate, unauthenticated site.

  • An email address you can read right now. Sign-up sends a verification link to it - see Create your account.
  • An authenticator app on a phone you control, with its own backup or transfer path already set up. Sencai issues no recovery codes - see Account security.
  • A name for the organization you are about to own - see Organizations & teams.
  • Optionally, a teammate’s email address. Read step 4 before you promise anyone access - see Personal plans.

Register at app.sencai.space/auth/register with your first and last name, your email address, and a password of at least 10 characters. Sencai sends a verification link to that address, and you may be prompted to verify it before you can sign in for the first time. Then sign in at app.sencai.space/auth/login.

If you sign up through Google or Microsoft instead, that flow does not collect your name, so your first sign-in lands on a Complete your profile screen asking for it before you can continue.

Do this before there is anything worth protecting behind it. Go to User profile → Security (/gravity/userprofile), open the Security tab, and select Set up 2FA. Scan the QR code with your authenticator app, then enter the 6-digit code it generates. Two-factor authentication only turns on after that code is confirmed, so a mis-scanned QR code cannot lock you out. From then on, every sign-in asks for a code after your password.

The same tab holds your password change, your list of active sessions with a per-session Sign out, and your email address change. See Account security for all four.

Cloud instances, fleet agents, billing, and settings belong to an organization, never to an individual user - so you need one before anything else is useful. From the dashboard, choose to create a new organization and give it a name. A URL-friendly slug is generated from that name and you can edit it before submitting. You become the organization’s Owner automatically, and an organization always keeps at least one Owner.

Open it from your organization list to reach the detail screen, which is organized into Overview, Members, Invitations, Settings, Billing, and Cloud Accounts tabs. You will use Members and Invitations in step 6.

Every new organization starts on a full-featured 14-day trial with no credit card. When those 14 days are up, an Owner has to choose a plan: until one is chosen, creating or changing cloud instances, inviting members, and changing organization settings are blocked, while every read-only screen and the billing screens themselves stay reachable. See Organizations & teams and Billing overview.

4. Check your plan limits before you invite anyone

Section titled “4. Check your plan limits before you invite anyone”

How many people you can invite is set by the organization’s plan - Starter, Professional, Business or Enterprise - which caps users, cloud environments and managed resources. You change it at Settings → Subscription (/gravity/settings/subscription).

Your personal plan is a separate axis. It governs how many organizations you may own and which AI features you get. It does not cap how many members an organization can have, so a Free personal plan is no obstacle to building a team in an organization whose own plan has room.

New accounts start with a 14-day trial carrying full Unlimited-tier personal access. If it ends without an upgrade, your account converts to Free and anything now over Free’s limits gets a grace period rather than being cut off. Upgrade from your profile with Upgrade my plan (/gravity/profile/checkout/upgrade).

For the numbers, see sencai.space/pricing; for what each tier governs, see Personal plans and Organization plans.

Roles run, highest to lowest: Owner > Admin > Member > Auditor > Viewer. They are per-organization, so the same person can be an Admin in one organization and a Viewer in another.

The one that catches people is Auditor. It is a read-oriented role scoped toward audit and compliance visibility, and it sits below Member - the name suggests seniority that the role does not carry. Do not grant it expecting Admin-like reach.

Pick the role before you open the invite dialog, and when in doubt start narrower and raise it later; every role change is recorded in the organization’s audit trail either way. See Roles & permissions for exactly what each of the five grants and which one fits a given job.

If step 4 left you room, invite by email from your organization’s Members or Invitations tab, choosing the invitee’s role at the same time. An invitation grants nothing until it is accepted: until then it appears in the members list marked Pending invitation instead of with a join date. There is no resend action, so if one expires or the email is lost, revoke it and send a new invitation to the same address.

If you have no room on your plan, or nobody to invite yet, you are done anyway. The outcome of this tutorial - a verified, two-factor-protected account, an organization you own, roles understood, limits known - does not depend on this step.

From here, Your first hour with Sencai picks up with connecting a cloud account or enrolling a fleet agent. Read it with the correction from step 4 in mind.