Skip to main content

Account and Access designed

Use this path when the question starts with identity, sign-in, access, or account protection rather than with compute capacity.

Core Tasks

TaskExpected user actionOwning product surface
Sign inUse the standard browser sign-in path and land in the correct tenant/project contextapp shell and auth redirect flow
Review account postureCheck profile, sessions, API keys, SSH keys, and MFA postureAccount pages
Set up MFARegister or add an authenticator through the identity-provider-managed flowAccount security and IdP-managed MFA
Replace or remove MFAUse the managed MFA path or approved recovery flowAccount security and recovery workflow
Recover account accessStart account recovery before replacing a lost device or removing the final authenticatorRecovery workflow
Manage developer keysAdd or rotate SSH/API keys without exposing secrets in shared screenshots or docsAccount profile/security

Guided Walkthrough

Happy Path

  1. Sign in and confirm the correct tenant and project.
  2. Open Account -> Security.
  3. Review MFA status and session state.
  4. Open MFA management when adding or replacing an authenticator.
  5. Return to the account page and refresh status.
  6. Confirm the expected authenticator or recovery posture is visible.

Recovery And Edge Cases

  • Lost phone or upgraded device: start recovery before removing the existing authenticator.
  • Admin or privileged user: follow the stricter recovery/approval path defined by the platform policy for the environment.
  • MFA status stale: use the status refresh path before assuming the provider lost the factor.
  • Session posture unknown: treat it as a readback gap, not proof that MFA is disabled.

Documentation Rule

This page documents the user-safe flow. It does not expose internal IdP implementation details, raw provider URLs, or operator-only reset mechanics in the main path.