Stratforge One

Quickstart

This is the path most admins follow on their first day with Stratforge One: set up the organization, bring your people in, decide what they can do, connect the products they need, lock down sign-in, and check your spend. Work through the steps in order - each one builds on the last.

If any term below is unfamiliar, the Core concepts page explains the mental model in one short read.

1. Set up your organization

Start by giving your organization its identity. In Organization, set the name and label, upload a logo, and confirm your organization URL.

Your URL is the slug all your sign-in and product links are built from, so pick it carefully - changing it later signs everyone out and the old URL stops working immediately.

Deep dive: Organization.

2. Invite your members

Next, bring your people in. Open the Directory, choose Invite users, and send invitations by email. Invited people show up as pending until they accept, after which they become active members.

Decide each person's organization role as you go: Admin for the people who help you run the console, Member for everyone else. You can resend invitations and change roles at any time from a member's profile.

Deep dive: Directory users.

3. Create groups

Rather than manage access person by person, organize people into groups. In the Directory's Groups tab, create a group for each team or function and add the relevant members.

Groups are the unit you will grant access to in the next steps, so a little structure here saves a lot of repetition later.

Deep dive: Groups.

4. Assign roles and access

Now decide what people can do. In Access control, review the System roles that come with your apps and create Custom roles where you need something specific - you can clone an existing role to get a head start. Within each role, grant or revoke permissions per module.

Assign roles to your groups (or to individual members), and set up data policies to control which records each group can see. Remember the organization-wide default access mode: Restrictive denies access until a policy applies, Permissive grants it by default.

Deep dives: Access control overview and Data policies.

5. Connect an app

With access mapped out, connect the products your team needs. Browse the Apps catalog and subscribe to a Stratforge product to add it to your organization.

Once it is connected, open Manage for that app to configure its Data Policies, Access Controls, and Settings, then grant product access to the groups that should use it.

Deep dives: Apps catalog and Manage apps.

6. Configure sign-in and SSO

Before you go live, tighten how people sign in. In Security, enable the multi-factor authentication methods you want to allow - an authenticator app (TOTP) and email one-time codes - and turn on Force MFA if every member should complete a second step.

If you use an existing identity system, add an identity provider (SAML or LDAP) so your people can sign in with single sign-on.

If you force MFA, make sure at least one authentication method stays enabled - you can't disable the last remaining method while MFA is required.

Deep dives: Security overview and Authentication.

7. Review billing

Finally, get visibility into spend. Open Billing to see your dashboard - credits used, amount billed, and your current plan.

Set a budget with a limit so usage is restricted once you hit it, and check Bills to see spend broken down by service.

Deep dives: Billing overview, Budgets, and Bills.

That's the core setup. From here, manage your own profile and MFA in Account, and revisit Core concepts whenever you need to refresh the mental model.