Signing in
The intranet uses single sign-on (OAuth2/OIDC) against any configured identity provider — Authentik, Keycloak, Google, Microsoft Entra, and so on. The rest of the app is provider-agnostic.
Sign in with SSO
- Open the intranet URL. If you are not signed in you land on the Sign in
screen (
/login). - Click Sign in with Your provider.
- You are redirected to the provider, authenticate, and are returned to the app.
- You land on your home screen.
If no provider is configured, the sign-in screen offers a dev sign-in link instead (see below).
Where you land
After signing in, the app sends you to a sensible starting point for your role:
You can always navigate elsewhere from the sidebar.
Dev sign-in (no provider required)
In a development or isolated environment the identity provider may not be reachable. Use the dev sign-in to mint a real session for an email and role directly:
/dev/login?email=you@cloud-exit.com&role=admin
emaildefaults to a demo account.roleis one ofengineer,reviewer,finance,admin.
Examples:
| Who | URL |
|---|---|
| Admin | /dev/login?email=abdul@cloud-exit.com&role=admin |
| Reviewer | /dev/login?email=reviewer@cloud-exit.com&role=reviewer |
| Engineer | /dev/login?email=engineer@cloud-exit.com&role=engineer |
The dev sign-in creates the user if needed and returns you to the app. It is the fastest way to explore a role you don't normally hold.
The dev sign-in bypasses the provider entirely. Use it to preview behaviour, not to test SSO itself.
Staging
When the app runs in staging, a Staging — synthetic data only banner shows under the top bar, and the sign-in screen notes that the environment is not production. Only identities on the staging allowlist can sign in; everyone else is refused until an operator adds them.
Signing out
Your name and role appear at the bottom of the sidebar, with a Log out button. Pressing it revokes the session and returns you to the sign-in screen.
Troubleshooting
| Symptom | Likely cause / fix |
|---|---|
| "No OAuth provider is configured" | Use the dev sign-in, or ask an operator to configure the provider. |
Sign-in loops back to /login | Provider misconfigured; check the callback URL with an operator. |
| Signed in but most sections 403 | Your role is engineer; that is expected for those sections. |
| "Staging has no allowed identities" | Ask an operator to add your email to the staging allowlist. |