Getting started · chapter 02 of 08

Set up the organisation, users, and access safely

Account setup is where ownership begins. Separate human access from device and integration credentials before the first production connection is created.

Practical guideOutcome: A verified organisation with named administrators, separated environments, and credentials stored by an accountable owner.
Chapter outcome

A verified organisation with named administrators, separated environments, and credentials stored by an accountable owner.

02.1

Create and verify the organisation

Use a work email address controlled by the organisation. Record the organisation name, the first product or project, and the person accountable for access decisions.

  1. 01Create the organisation account and verify the work email address.
  2. 02Confirm the organisation and project names used by the delivery team.
  3. 03Add a second administrator so access is not dependent on one person.
  4. 04Record the support and escalation contact for the project.
02.2

Assign access by responsibility

Give people only the access required for their work. Product, engineering, service, customer support, and external partners should not automatically receive the same permissions.

  • Organisation administrator: manages users, environments, and policy.
  • Device administrator: provisions devices and rotates device credentials.
  • Builder: configures variables, dashboards, events, and reports.
  • Operator or viewer: monitors assets and follows approved actions.
02.3

Protect tokens and environment boundaries

The authenticated portal or onboarding record provides the credential and base URL assigned to the deployment. Treat every token like a production password.

  1. 01Keep development and production credentials separate.
  2. 02Store server and device secrets in an approved secret manager or secure provisioning flow.
  3. 03Never paste credentials into source repositories, screenshots, or support tickets.
  4. 04Record the owner, purpose, issue date, and rotation trigger for each credential.

Rotate a credential immediately when its owner changes, a device is transferred, or exposure is suspected.

Connected-product assessment

Bring one product. Leave with a clear next step.

Use 30 minutes to test the fit around one product and one blocked decision. If there is a fit, we will outline the two-week Product Blueprint.

30-minute fit callOne productNo prepared deck