Skip to main content
CloudThinker agents can read — and, with approval, change — your cloud infrastructure, so access to the platform itself is controlled with multi-factor authentication (MFA), single sign-on (SSO), and role-based permissions. Every agent action is logged with the user who initiated it and the approval it went through.

Authentication methods

Multi-factor authentication

Add a second factor to your own account:
1

Open your account settings

Open your account menu and go to Account Settings → 2FA.
2

Set up the authenticator

Start MFA setup and scan the QR code with an authenticator app (Google Authenticator, Authy, 1Password, and more).
3

Confirm with a code

Enter the 6-digit code from your authenticator to finish setup.
4

Save your backup codes

Download and store the one-time backup codes. At sign-in, you can enter an 8-character backup code instead of an authenticator code.
Each backup code works once. If you lose your authenticator and all backup codes, account recovery requires identity verification through support.

Single sign-on

SSO is available on Scale, Scale+, and Enterprise plans and is configured by the organization Owner in Admin Settings → Identity and access:
  • Domain verification — prove ownership of your email domain with a DNS TXT record before setting up SSO
  • SAML 2.0 or OIDC — choose the protocol your identity provider supports
  • Require SSO — optionally disable all other sign-in methods for your users
  • Provisioning — invite users manually, auto-create accounts on first SSO login (JIT), or sync your directory with SCIM

Roles and permissions

Access is controlled at two levels. An organization role applies across every workspace; a workspace role can grant a specific member a different level in one workspace.

Organization roles

Workspace roles

Permission matrix

Data security

BYOK is about model access, not encryption keys: workspaces on Scale, Scale+, and Enterprise plans can route LLM inference through their own AWS Bedrock credentials for cost control and data residency.

Audit logs

Organization activity — sign-ins, administrative changes, and agent actions — is recorded in Admin Settings → Audit Logs, available on Scale, Scale+, and Enterprise plans. Filter by user, action, and date, and export entries for compliance review.

Security best practices

  • Enable MFA for every member, especially Owners and Admins — or enforce SSO and let your identity provider require it.
  • Assign the minimum role each member needs, and review access quarterly.
  • Use read-only cloud credentials where possible, scoped to the services and regions agents need.
  • Rotate credentials — cloud keys, SCIM tokens, and webhook secrets — on a regular schedule.
  • Review audit logs for unexpected administrative changes or sign-ins.
For security questionnaires and compliance documentation, contact security@cloudthinker.io.

Custom Guardrails

Choose built-in protections and add patterns for your team’s identifier formats

Single Sign-On

Verify your domain, connect your identity provider, and enforce SSO

SCIM Provisioning

Automate user and group sync from your identity provider

Organization Management

Manage members, roles, and workspaces

Bring Your Own Key

Route LLM inference through your own AWS Bedrock account