Managing your organisation - Users & Sites
Customer administrators manage their own organisation under My Organisation (MSP / platform staff do the equivalent from Settings and Tenants). The page has four tabs: Overview, Users, Sites, and Branding.
Users
My Organisation → Users.
- Click Invite User, enter a name (optional), email, and a Role (Admin, Operator, or Viewer - see Roles & permissions).
- CloudImage creates the account (or adds a role to an existing user) and returns a temporary password. No email is sent - copy the temp password shown and pass it to the user securely.
- Other actions: Reset password (issues a fresh temp password), Reset 2FA (clears a user's authenticator so they re-enrol — see Two-Factor Authentication), and Remove (revokes access immediately).
Sites
My Organisation → Sites.
A Site represents a physical office / location, defined by a subnet (CIDR). Sites do two things:
- Group devices by location.
- Scope peer caching - devices on the same site subnet share downloaded content with each other.
Add a site with a Name (e.g. London Head Office), Location (e.g. London, UK), and Subnet (e.g. 10.1.0.0/24). Deleting a site only removes the definition; devices keep working.
Two-Factor Authentication (2FA)
Two-factor authentication is mandatory for every CloudImage account. It adds a one-time 6-digit code on top of your password, so a stolen password alone can't get into your account.
Enrolling (first login)
- Sign in with your email and password as normal.
- You'll be shown a QR code. Scan it with an authenticator app - Microsoft Authenticator, Google Authenticator, or any TOTP app.
- Enter the 6-digit code the app shows to confirm. You're enrolled.
From then on, every login asks for your password and the current 6-digit code from your authenticator.
Grace period: you have 7 days from your first login to enrol. During that window you can still sign in and use CloudImage normally while you set it up. After 7 days, enrolment is required before you can continue.
Set it up on a device you'll keep. Your authenticator app holds the key to your account - treat it like your password.
Lost your device, or locked out? - Log a support call
You cannot reset your own 2FA. This is deliberate: it's what stops an attacker who has your password from also removing your second factor.
If you lose your phone, get a new device, or are locked out for any reason:
- Log a support call.
- An administrator verifies your identity and resets your 2FA.
- On your next login you'll be prompted to enrol again (scan a fresh QR code) - exactly like the first time.
There is no self-service reset and no printable backup codes, so if you're the only person who can get into an account, raise a support call early rather than waiting until you're locked out.
For administrators - resetting a user
Admins can reset a user's 2FA from My Organisation → Users (MSP / platform staff: from the equivalent user-management panel), alongside Reset password. You can only reset users at or below your own role level - you can't reset an administrator who outranks you. After a reset, the user re-enrols on their next login.