Skip to content

Onboarding

Onboarding is done through an online setup wizard. LAAVAT sends you a single-use link; you complete it with your identity provider credentials and group IDs. Nothing sensitive is exchanged by email.

Access to the platform is driven by your directory's groups, so the identity provider work comes first — the wizard validates your credentials and groups as you submit them, and can only succeed once they exist.

1. Prepare your identity provider

Create a service account in either Microsoft Entra ID or Google Cloud. Each page covers the application registration, the API permissions to grant, and the values you will need in the wizard.

2. Create the initial groups

Create the two groups the platform bootstraps from: an initial writer group, whose members may submit configuration requests, and an initial approver group, whose members approve them. See Initial groups — note that the group-type requirements differ between Entra ID and Google, and getting them wrong is the most common cause of approval notifications never arriving.

3. Request and complete the setup wizard

Request a setup link from support@laavat.io. LAAVAT provides the link, and you complete the wizard with your identity provider credentials and the two initial group IDs. See Identity provider setup for what the wizard asks for.

Each link is single-use and expires, and the platform picks up the new tenant configuration automatically within 15 minutes of submission.

4. Create the system configuration groups

With the tenant provisioned, define the groups that control day-to-day access — reader, writer and approver roles for products, CAs, revocation, and clients. See System configuration groups.

5. Apply the configuration

Submit the group configuration through the GUI or the API. A worked example using the reference client is in Example usage with reference client package.

Only one configuration group set is active at a time, and approving a new one replaces the current set.

Next steps

Track progress against the onboarding checklist, which marks who is responsible for each step, then follow the Quick start guide to create your first product.