Skip to content

Onboarding

We prepare your deployment before you see it. You confirm what we prepared, and confirming is what starts it.

You are not asked questions we already know the answer to.

Open the link we email you. No account is needed. The link expires and works once.

Check the review page. It shows what we prepared. You can adjust:

  • Your organisation’s display name
  • Your address, either yourschool.plugboard.app or your own domain
  • The first administrator’s name and email
  • Time zone and locale

All of these are editable in the product afterwards. They are on this page so your first sign-in already looks right.

The one exception is the address. If you change it, it has to be an address no other Plugboard deployment is already using — confirming is refused if it is, and the message names the address. Changing it also means the DNS records you are given afterwards are for the new address, not the one in your invitation email.

Your region and hosting model are shown to confirm, not to choose. They follow from the agreement, and the region carries its data residency note. If you want either changed, reply to a human.

Press confirm. That starts the deployment. The page stays open and shows progress, which takes a few minutes.

If the email does not arrive, ask and we will send the link again.

A walkthrough matching your deployment, covering only what you have.

Managed: your address, first sign-in, inviting staff, connecting your identity provider, pointing your own domain at it, where backups go, and how to ask for a restore.

Self-hosted: the install method with your own values already filled in, your .env and licence key, TLS options, backup and update commands, and the installers themselves. The invitation link authorises those downloads, so you do not need a separate download centre link mid-setup.

Two things are yours alone and the walkthrough says so: keeping SECRETS_MASTER_KEY backed up somewhere other than the server, and running the update when a new version lands.

Follow the setup checklist. It front-loads the requests that have lead times. In outline:

  1. Branding, so it looks like yours.
  2. Turn off modules you will not use.
  3. Set the workflow before anyone lodges a real submission.
  4. Connect email first, then the directory or SIS, then the MDM.
  5. Build roles, then invite technicians.
  6. Turn on SSO and, if you can, SCIM.

A managed deployment cannot reach Active Directory, a Synergetic database, PaperCut, or a printer answering SNMP, because those are inside your network and we are not.

Install a connector agent. It dials out, collects queued work, and returns results. There is no inbound firewall rule to request, which is usually the difference between a two week change request and an afternoon.

The agent registers itself as a monitor at the same time, so one that is installed and then dies gets noticed by the alerting you already have.

Thing When
Confirmation of the review page To start
A DNS record Whenever you want your own domain. See your own domain
An OIDC application in your identity provider Before SSO works. We cannot create it in your tenant
A connector agent installed Before systems on your network connect
Credentials for each connector you want As you enable them. We never hold them; you paste them in

Moving between self-hosted and managed, or between regions, is supported. See support, restores and exits.